Invention Grant
- Patent Title: Worm detection by trending fan out
- Patent Title (中): 蠕虫检测通过风扇扇出
-
Application No.: US11785655Application Date: 2007-04-19
-
Publication No.: US08095981B2Publication Date: 2012-01-10
- Inventor: Peter Rabinovitch , Stanley TaiHai Chow , Bassem Abdel-Aziz
- Applicant: Peter Rabinovitch , Stanley TaiHai Chow , Bassem Abdel-Aziz
- Applicant Address: FR Paris
- Assignee: Alcatel Lucent
- Current Assignee: Alcatel Lucent
- Current Assignee Address: FR Paris
- Agency: Kramer & Amado P.C.
- Main IPC: G06F21/00
- IPC: G06F21/00

Abstract:
The invention detects stealth worm propagation by comparing the repeat elements in sets of destinations of a source in multiple time windows to a fitted distribution of same, stored as a benchmark plot. Measurements are performed over N time windows, wherein a representation of the set of destinations to which a respective source has sent packets is determined for each source, in each time window. The counting is performed using a hash table. Once N such sets of destinations have been obtained, the number Xk of destinations that are common to N, N−1, N−2, . . . , 2, 1 windows is determined. Thus Xk is the number of destinations that a particular source sent packets to in k time windows. Xk is then compared to the corresponding value on the plot; anomalies indicate an attack from the respective source.
Information query