Computer virus detection
First Claim
Patent Images
1. A computer program product embodied on a computer readable medium for detecting an outbreak of a computer virus on a computer apparatus, said computer program product comprising:
- (i) measurement computer code operable to measure one or more measurement parameters indicative of non virus specific activity of said computer apparatus over a respective measurement period;
(ii) comparison computer code operable to compare said one or more measurement parameters with respective predetermined threshold levels; and
(iii) signal generating computer code operable to generate a signal indicative of an outbreak of a computer virus if one or more of said one or more measurement parameters crosses a respective predetermined threshold level;
wherein one of said measurement parameters is e-mail throughput associated with said computer apparatus, where said e-mail throughput is measured in a form dependent upon at least one of a number of e-mails, and a total of size values for said e-mails within a predetermined time period.
10 Assignments
0 Petitions
Accused Products
Abstract
A computer virus outbreak is detected by comparing one or more measurement parameters determined over a measurement period against a threshold level. The measurement parameters can include a measurement of how many E-mail messages are sent having an identical file attachment, file type or simply in total. The threshold levels may be varied with the time of day and day of week as well as the tests applied.
-
Citations
36 Claims
-
1. A computer program product embodied on a computer readable medium for detecting an outbreak of a computer virus on a computer apparatus, said computer program product comprising:
-
(i) measurement computer code operable to measure one or more measurement parameters indicative of non virus specific activity of said computer apparatus over a respective measurement period; (ii) comparison computer code operable to compare said one or more measurement parameters with respective predetermined threshold levels; and (iii) signal generating computer code operable to generate a signal indicative of an outbreak of a computer virus if one or more of said one or more measurement parameters crosses a respective predetermined threshold level; wherein one of said measurement parameters is e-mail throughput associated with said computer apparatus, where said e-mail throughput is measured in a form dependent upon at least one of a number of e-mails, and a total of size values for said e-mails within a predetermined time period. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12)
-
-
13. A method of detecting an outbreak of a computer virus on a computer apparatus, said method comprising the steps of:
-
(i) measuring one or more measurement parameters indicative of non virus specific activity of said computer apparatus over a respective measurement period; (ii) comparing said one or more measurement parameters with respective predetermined threshold levels; and (iii) generating a signal indicative of an outbreak of a computer virus if one or more of said one or more measurement parameters crosses a respective predetermined threshold level; wherein one of said measurement parameters is e-mail throughput associated with said computer apparatus, where said e-mail throughput is measured in a form dependent upon at least one of a number of e-mails, and a total of size values for said e-mails within a predetermined time period. - View Dependent Claims (14, 15, 16, 17, 18, 19, 21, 22, 23, 24)
-
-
20. A method as claimed in claim a 13, wherein said respective predetermined threshold levels are varied in dependence upon time of day.
-
25. Apparatus for detecting an outbreak of a computer virus on a computer apparatus, said apparatus comprising:
-
(i) measuring logic operable to measure one or more measurement parameters indicative of non virus specific activity of said computer apparatus over a respective measurement period; (ii) comparing logic operable to compare said one or more measurement parameters with respective predetermined threshold levels; and (iii) signal generating logic operable to generate a signal indicative of an outbreak of a computer virus if one or more of said one or more measurement parameters crosses a respective predetermined threshold level; wherein one of said measurement parameters is e-mail throughput associated with said computer apparatus, where said e-mail throughput is measured in a form dependent upon at least one of a number of e-mails, and a total of size values for said e-mails within a predetermined time period. - View Dependent Claims (26, 27, 28, 29, 30, 31, 32, 33, 34, 36)
-
-
35. Apparatus as claimed in clam in 25, wherein said respective measurements periods are user selectable.
Specification