Invention Grant
- Patent Title: System and method of containing computer worms
- Patent Title (中): 包含电脑蠕虫的系统和方法
-
Application No.: US11151812Application Date: 2005-06-13
-
Publication No.: US08549638B2Publication Date: 2013-10-01
- Inventor: Ashar Aziz
- Applicant: Ashar Aziz
- Applicant Address: US CA Milpitas
- Assignee: FireEye, Inc.
- Current Assignee: FireEye, Inc.
- Current Assignee Address: US CA Milpitas
- Agency: Blakely, Sokoloff, Taylor & Zafman LLP
- Main IPC: G06F12/16
- IPC: G06F12/16 ; G08B23/00

Abstract:
A computer worm containment system comprises a detection system and a blocking system. The detection system orchestrates a sequence of network activities in a decoy computer network and monitors that network to identify anomalous behavior and determine whether the anomalous behavior is caused by a computer worm. The detection system can then determine an identifier of the computer worm based on the anomalous behavior. The detection system can also generate a recovery script for disabling the computer worm or repairing damage caused by the computer worm. The blocking system is configured to use the computer worm identifier to protect another computer network. The blocking system can also use the recovery script to disable a computer worm within the other network and to repair damage caused to the network by the worm.
Public/Granted literature
- US20110099633A1 System and method of containing computer worms Public/Granted day:2011-04-28
Information query