Patent · US Active

Detecting public network attacks using signatures and fast content analysis

US8296842B2 · kind B2 · utility

48Cited by
16References
69Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 1, 2004
Grant dateOct 23, 2012
Priority date
Expiry dateMar 23, 2027

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2463/141
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Network worms or viruses are a growing threat to the security of public and private networks and the individual computers that make up those networks. A content sifting method if provided that automatically generates a precise signature for a worm or virus that can then be used to significantly reduce the propagation of the worm elsewhere in the network or eradicate the worm altogether. The content sifting method is complemented by a value sampling method that increases the throughput of network traffic that can be monitored. Together, the methods track the number of times invariant strings appear in packets and the network address dispersion of those packets including variant strings. When an invariant string reaches a particular threshold of appearances and address dispersion, the string is reported as a signature for suspected worm.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.