Original document(15 pages) Authorized document(15 pages) 中文版
    The detection system is composed of network flow acquisition unit distributed at each terminal in network system, and network worm analytic unit setup at server. The former collects information into and out of the terminal in real time. After snapshot and standardized processes, data are transferred to the analytic unit. Under request of analytic unit, the acquisition unit delivers suspicious attacking sample and basic status information of terminal. The analytic unit carries out statistics and analysis for flow data provided by the acquisition unit. Based on threshold value of flow, the analytic unit determines whether the terminal is possible to be suffered from worm attack or to become an attacking source. Based on determined result, and under interaction with the acquisition unit, the analytic unit requests the acquisition unit to deliver the said sample and information to carry out querying and matching operation in order to make determination, meanwhile alarming is sent out.
Application Number
申请号
200510075341 Application Date
申请日
2005.06.10
Title 名称 System and method for detecting network worm in interactive mode
Publication Number
公开号
1697404 Publication Date
公开日
2005.11.16
Approval Pub. Date 2007.08.01 Granted Pub. Date 2007.08.01
International Classification 分类号 H04L12/24
Applicant(s) Name
申请人
Guangdong Provincial Telecom Co., Ltd., Inst
Address 地址
Inventor(s) Name 发明人 Chen Xun;Jin Huamin;Zhuang Yirong
Attorney & Agent 代理人 xia xianfu

  
Automatic method for reporting MAC address from device of optical network unit at remote side to network management system
Method for transferring monitored information
Implementation method and system for testing consistency of border gateway protocol of supporting IPv6
Method for managing routes in virtual private network based on IPv6
Method for controlling user to access to network
Quick redialing method for user to log on broadband network
Virtual IP support method of device for built-in network service program
Method for sharing audio/video content over network, and structures of sink device, source device, and message
Frequency hopping piconets in an uncoordinated wireless multi-user system
Medium access control method in use for wireless network in short range
Google
Note:All patent data come from State Intellectual Property Office of the People's Republic of China. If there were discrepancies between here and the State Intellectual Property office, the later is more accurate. The patent data is only for public exchange and learning purposes. We are not responsible for the adverse consequences with unverified use of the data.