×

Method and apparatus for detecting zombie-generated spam

  • US 8,775,521 B2
  • Filed: 06/30/2006
  • Issued: 07/08/2014
  • Est. Priority Date: 06/30/2006
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method for detecting a zombie attack in a network comprising a plurality of computers, the method comprising:

  • determining, for each particular computer in the plurality of computers, a working set associated with the particular computer, the working set comprising;

    a first list of email addresses including email addresses associated with emails sent by the particular computer and including email addresses associated with emails received by the particular computer;

    determining whether at least a first threshold number of computers in the plurality of computers are transmitting email messages to email addresses not included in their working set;

    determining whether at least a second threshold number of computers in the plurality of computers are transmitting at least a first threshold number of emails to a recipient computer;

    determining, for each computer in the plurality of computers, whether at least a second threshold number of emails are being transmitted to email addresses not included in its working set;

    storing, for each particular computer in the plurality of computers, data comprising;

    a second list comprising;

    an email address and a time associated with each sent email associated with the particular computer;

    a third list comprising an email address and a time associated with each received email associated with the particular computer; and

    a rate of emails sent by each particular computer in the plurality of computers;

    determining a change in the rate of emails sent based on the rate and the data;

    anddetecting a zombie attack based on;

    whether at least the first threshold number of computers in the plurality of computers are transmitting email messages to email addresses not included in their working set, andwhether at least the second threshold number of computers in the plurality of computers are transmitting at least the first threshold number of emails to a recipient computer; and

    whether the change in the rate of emails sent, associated with a particular computer is greater than a first threshold rate; and

    whether, for each computer in the plurality of computers, at least the second threshold number of emails are being transmitted to email addresses not included in its working set.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×