Invention Grant
- Patent Title: Proactive worm containment (PWC) for enterprise networks
- Patent Title (中): 企业网络的主动式遏制(PWC)
-
Application No.: US11961062Application Date: 2007-12-20
-
Publication No.: US08904535B2Publication Date: 2014-12-02
- Inventor: Peng Liu , Yoon-Chan Jhi , Lunquan Li
- Applicant: Peng Liu , Yoon-Chan Jhi , Lunquan Li
- Applicant Address: US PA University Park
- Assignee: The Penn State Research Foundation
- Current Assignee: The Penn State Research Foundation
- Current Assignee Address: US PA University Park
- Agency: Gifford, Krass, Sprinkle, Anderson & Citkowski, P.C.
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; H04L29/06

Abstract:
A proactive worm containment (PWC) solution for enterprises uses a sustained faster-than-normal outgoing connection rate to determine if a host is infected. Two novel white detection techniques are used to reduce false positives, including a vulnerability time window lemma to avoid false initial containment, and a relaxation analysis to uncontain (or unblock) those mistakenly contained (or blocked) hosts, if there are any. The system integrates seamlessly with existing signature-based or filter-based worm scan filtering solutions. Nevertheless, the invention is signature free and does not rely on worm signatures. Nor is it protocol specific, as the approach performs containment consistently over a large range of worm scan rates. It is not sensitive to worm scan rate and, being a network-level approach deployed on a host, the system requires no changes to the host's OS, applications, or hardware.
Public/Granted literature
- US20090031423A1 PROACTIVE WORM CONTAINMENT (PWC) FOR ENTERPRISE NETWORKS Public/Granted day:2009-01-29
Information query