×

System and method of containing computer worms

  • US 8,549,638 B2
  • Filed: 06/13/2005
  • Issued: 10/01/2013
  • Est. Priority Date: 06/14/2004
  • Status: Active Grant
First Claim
Patent Images

1. A computer worm containment system in communication with a real communication network, the system comprising:

  • a computer worm detection system includinga traffic analysis device coupled in communication with the real communication network and configured to identify and copy network traffic having characteristics associated with a computer worm in the real communication network,a hidden computer network configured to detect anomalies, anda controller coupled to the hidden computer network, the controller being configured to (a) receive the copied network traffic, (b) replay the copied network traffic and a plurality of network activities generated within the hidden computer network in accordance with an identified pattern of activities, (c) monitor behavior of the hidden network in response to the replay of the copied network traffic and the plurality of network activities, and (d) determine an identifier of a computer worm based on anomalous behavior caused within the hidden computer network by the computer worm, the identifier associated with anomalous character of the computer worm and the anomalous character of the computer worm being determined by comparing the monitored behavior in the hidden computer network with behavior expected from the identified pattern of activities; and

    a computer worm blocking system configured to receive the identifier and use the identifier to block the computer worm from propagating within the real communication network.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×