×

System and method of detecting computer worms

  • US 8,528,086 B1
  • Filed: 03/31/2005
  • Issued: 09/03/2013
  • Est. Priority Date: 04/01/2004
  • Status: Active Grant
First Claim
Patent Images

1. A system for detecting a computer worm, comprising:

  • a traffic analysis device configured to identify and copy network traffic traveling over a communication network, the network traffic having a characteristic associated with one or more computer worms;

    a computer network communicatively coupled with a memory, the computer network being configured to detect anomalies; and

    a controller communicatively coupled with the memory and in communication with the traffic analysis device, the controller being configured to (i) receive the copied network traffic, (ii) replay the copied network traffic and a plurality of network activities in the computer network, (iii) monitor a behavior of the computer network in response to the replay of the copied network traffic and the plurality of network activities, (iv) identify an anomalous behavior as an unexpected occurrence in the monitored behavior to detect a computer worm of the one or more computer worms, and (v) create an identifier associated with the anomalous behavior for subsequently detecting the computer worm in a second computer network different than the computer network,wherein the identifier comprises a signature that is associated with the anomalous behavior for detecting a presence of the computer worm in the second computer network.

View all claims
  • 7 Assignments
Timeline View
Assignment View
    ×
    ×