×

Heuristic based capture with replay to virtual machine

  • US 8,171,553 B2
  • Filed: 04/20/2006
  • Issued: 05/01/2012
  • Est. Priority Date: 04/01/2004
  • Status: Active Grant
First Claim
Patent Images

1. An unauthorized activity capture system comprising:

  • a tap configured to copy network data from a communication network; and

    a controller coupled to the tap and configured to receive the copy of the network data from the tap, analyze the copy of the network data with a heuristic to determine if the copy of the network data has one or more characteristics of a computer worm, flag at least a portion of the copy of the network data as suspicious by flagging the at least a portion of the copy of the network data for replay in an analysis environment based upon the heuristic determination that the at least a portion of the analyzed copy of the network data has one or more characteristics of a computer worm, and replay transmission of the suspicious, flagged network data copied from the communication network to a destination device.

View all claims
  • 7 Assignments
Timeline View
Assignment View
    ×
    ×