Invention Grant
- Patent Title: Method and apparatus for detecting malware
- Patent Title (中): 用于检测恶意软件的方法和装置
-
Application No.: US12248537Application Date: 2008-10-09
-
Publication No.: US08112801B2Publication Date: 2012-02-07
- Inventor: Bassem Abdel-Aziz , Stanley Taihai Chow , Shu-Lin Chen
- Applicant: Bassem Abdel-Aziz , Stanley Taihai Chow , Shu-Lin Chen
- Applicant Address: FR Paris
- Assignee: Alcatel Lucent
- Current Assignee: Alcatel Lucent
- Current Assignee Address: FR Paris
- Agency: Fay Sharpe LLP
- Main IPC: G06F12/14
- IPC: G06F12/14 ; H04L9/32

Abstract:
A method of detecting malware may include: a) examining header data in each PDU transferred by a port of an access switch to identify PDUs transferred from a local network device, b) extracting a far-end device address for PDUs based at least in part on examination of an address portion of the corresponding header data, c) maintaining fan-out information indicative of a quantity of unique far-end device addresses extracted from the PDUs during consecutive time windows, d) determining a current trend based on the fan-out information for a current time window, e) comparing the current trend to an expected trend, and f) identifying a suspected malware infection in the local network device when the current trend exceeds the expected trend by a trend threshold. A network element that may implement the method may include a header data processing unit, data storage logic, data processing logic, and malware identification logic.
Public/Granted literature
- US20090044276A1 METHOD AND APPARATUS FOR DETECTING MALWARE Public/Granted day:2009-02-12
Information query