US2007234424A1PendingUtilityA1

Design and evaluation of a fast and robust worm detection algorithm

Assignee: LUCENT TECHNOLOGIES INCPriority: Mar 31, 2006Filed: Mar 31, 2006Published: Oct 4, 2007
Est. expiryMar 31, 2026(expired)· nominal 20-yr term from priority
H04L 63/1425H04L 63/145G06F 21/561
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method and computer product are presented for identifying Internet worm propagation based upon changes in packet arrival rates at a network connection. First, unsolicited (i.e., packets that were not requested by the receiver) traffic is separated from solicited traffic at the network connection. The unsolicited traffic arrival patterns are monitored and analyzed for any changes. Once changes in the unsolicited traffic arrival patterns are detected, the changes are mathematically analyzed to detect growth trends. The presence of growth trends that follow certain key characteristics indicate whether the changes are due to worm propagation.

Claims

exact text as granted — not AI-modified
1 . A method for detecting the propagation of a worm in a network, the method comprising the steps of: 
 (1) identifying and isolating unsolicited traffic from solicited traffic; and    (2) analyzing changes in unsolicited traffic patterns to identify a worm.    
   
   
       2 . The method of  claim 1 , wherein step (2) comprises the steps of: 
 detecting a change in arrival rates of said unsolicited traffic; and    determining whether said detected change is due to worm propagation.    
   
   
       3 . The method of  claim 2 , wherein said step of detecting a change in arrival rates of said unsolicited traffic comprises using a cumulative summing (CUSUM) statistical analysis for detecting a change in arrival rates of said unsolicited traffic.  
   
   
       4 . The method of  claim 3 , wherein said step of detecting a change in arrival rates of said unsolicited traffic further comprises issuing an indication of a change in said arrival rates when CUSUM detects a change in said arrival rates that exceeds a predetermined threshold.  
   
   
       5 . The method of  claim 4 , wherein said step of determining whether said detected change is due to worm propagation comprises using a non-stationary Poisson process to analyze said detected changes in arrival rates to determine if said changes are due to worm propagation.  
   
   
       6 . The method of  claim 5 , wherein said step of determining whether said detected change is due to worm propagation is performed responsive to said issuance of said indication.  
   
   
       7 . The method of  claim 6 , wherein said predetermined threshold is selected to provide a small detection delay before detecting a change in arrival rates.  
   
   
       8 . A computer program product embodied on a computer readable medium for detecting the propagation of a worm in a network, the product comprising: 
 first computer executable instructions for identifying and isolating unsolicited traffic from solicited traffic; and    second computer executable instructions for analyzing changes in unsolicited traffic patterns to identify a worm.    
   
   
       9 . The product of  claim 8 , wherein said second computer executable instructions comprises: 
 instructions for detecting a change in arrival rates of said unsolicited traffic; and    instructions for determining whether said detected change is due to worm propagation.    
   
   
       10 . The product of  claim 9 , wherein, in said second computer executable instructions, a cumulative summing (CUSUM) statistical analysis is used for detecting a change in arrival rates of said unsolicited traffic.  
   
   
       11 . The product of  claim 10 , wherein said second computer executable instructions further comprise instructions for issuing an indication of a change in said arrival rates when CUSUM detects a change in said arrival rates that exceeds a predetermined threshold.  
   
   
       12 . The product of  claim 11 , wherein, in said second computer executable instructions, a non-stationary Poisson process is used to analyze said detected changes in arrival rates to determine if said changes are due to worm propagation.  
   
   
       13 . The product of  claim 12 , wherein said instructions for determining whether said detected change is due to worm propagation are performed responsive to said issuance of said indication of change in said arrival rates.  
   
   
       14 . The product of  claim 13 , wherein said predetermined threshold is chosen such that it provides a small detection delay before detecting a change in arrival rate, said small detection delay resulting in fewer false detections.  
   
   
       15 . A method for detecting the propagation of a worm in a network, the method comprising the steps of: 
 (1) identifying and isolating unsolicited traffic from solicited traffic;    (2) detecting a change in arrival rates of said unsolicited traffic, wherein said detecting comprises using a cumulative summing (CUSUM) statistical analysis for detecting a change in arrival rates of said unsolicited traffic and issuing an indication of a change in said arrival rates when CUSUM detects a change in said arrival rates that exceeds a predetermined threshold; and    (3) determining whether said detected change is due to worm propagation, wherein said determining comprises using a non-stationary Poisson process to analyze said detected changes in arrival rates to determine if said changes are due to worm propagation.    
   
   
       16 . The method of  claim 15 , wherein said determining is performed responsive to said issuance of said indication of a change in said arrival rates.  
   
   
       17 . The method of  claim 16 , wherein said predetermined threshold is selected to provide a small detection delay before detecting a change in arrival rates.

Join the waitlist — get patent alerts

Track US2007234424A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.