EP1595193A2

Detecting and protecting against worm traffic on a network

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 5 February 2024, 2.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

102 claims: 31 independent, 71 dependent

  1. 1
    Claims of equivalent WO 2004070509 A2 CLAIMS 1. A method for processing commumcation traffic, comprising:monitoring the communication traffic that is directed to a group of addresses on a network;determining respective baseline characteristics of the communication traffic that is directed to each of the addresses in the group;detecting a deviation from the respective baseline characteristics of the communication traffic directed to at least one of the addresses in the group, such that the deviation is indicative that at least some of the communication traffic maybe of malicious origin;and responsively to detecting the deviation, filtering the communication traffic that is directed to all of the addresses in the group so as to remove at least some of the communication traffic that is of the malicious origin.
  2. 12
    The method according to any of the preceding claims, and comprising receiving packets that are indicative of a communication failure in the network that is characteristic of a worm infection, and wherein filtering the communication traffic comprises deciding to filter the communication traffic responsively to receiving the packets.
  3. 14
    The method according to any of claims 1-11, wherein monitoring the communication traffic comprises making a determination that one or more packets transmitted over the network are ill-formed, and wherein filtering the communication traffic comprises deciding to filter the communication traffic responsively to the ill-formed packets.
  4. 15
    The method according to any of claims 1-11, wherein detecting the deviation comprises incrementing a count of events that are indicative of the malicious origin of the communication traffic, and deciding whether to filter the communication traffic responsively to the count.
  5. 18
    The method according to any of claims 1-11, wherein detecting the deviation comprises detecting a type of the communication traffic that appears to be of the malicious origin, and wherein filtering the communication traffic comprises intercepting the communication traffic of the detected type.
  6. 21
    The method according to any of claims 1-11, wherein detecting the deviation comprises detecting a type of the communication traffic that appears to be of the malicious origin, and wherein monitoring the communication traffic comprises collecting specific information relating to the traffic of the detected type.
  7. 23
    The method according to any of claims 1-11, wherein monitoring and filtering the communication traffic comprise monitoring and filtering the communication traffic that is transmitted into a protected area of the network containing the group of the addresses so as to exclude the communication traffic from the area.
  8. 25
    A method for processing communication traffic, comprising:monitoring the communication traffic originating from a group of addresses and passing through a selected node on a network;detecting a pattern in the traffic originating from at least one of the addresses that is indicative of a malicious program running on a computer at the at least one of the addresses;and tracing a route of the traffic from the selected node back to the at least one of the addresses so as to identify a location of the computer on which the malicious program is running.
  9. 29
    A method for processing communication traffic, comprising:monitoring the communication fraffic on a network so as to detect packets that are indicative of a communication failure in the network that is characteristic of a worm infection;detecting an increase in a rate of arrival of the packets that are indicative of the communication failure;and responsively to the increase, filtering the communication traffic so as to remove at least some of the communication traffic that is generated by the worm infection.
  10. 32
    A method for processing communication traffic, comprising:monitoring the communication traffic on a network so as to detect ill-formed packets;making a determination, responsively to the ill-formed packets, that at least some of the communication traffic has been generated by a worm infection;and responsively to the determination, filtering the communication traffic so as to remove the at least some of the communication traffic that is generated by the worm infection.
  11. 35
    Apparatus for processing communication traffic, comprising a guard device, which is adapted to monitor the communication traffic that is directed to a group o f addresses on a network, to determine respective baseline characteristics of the communication traffic that is directed to each of the addresses in the group, to detect a deviation from the respective baseline characteristics of the communication traffic directed to at least one of the addresses in the group, such that the deviation is indicative that at least some of the communication traffic may be of malicious origin, and responsively to detecting the deviation, to filter the communication traffic that is directed to all of the addresses in the group so as to remove at least some of the communication traffic that is of the malicious origin.
  12. 43
    The apparatus according to c laim 42, wherein the guard device is adapted to read a Time-To-Live (TTL) field in headers of data packets sent to the addresses in the group, and to detect a change in values of the TTL field relative to the baseline characteristics due to the distribution of the operating systems.
  13. 46
    The apparatus according to any of claims 35-45, wherein the guard device is adapted to receive packets that are indicative of a communication failure in the network that is characteristic of a worm infection, and to decide to filter the communication traffic responsively to receiving the packets.
  14. 48
    The apparatus according to any of claims 35-45, wherein the guard device is adapted to make a determination that one or more packets transmitted over the network are ill-formed, and to decide to filter the communication traffic responsively to the ill-formed packets.
  15. 49
    The apparatus according to any of claims 35-45, wherein the guard device is adapted to increment a count of events that are indicative of the malicious origin of the communication traffic, and to decide whether to filter the communication traffic responsively to the count.
  16. 52
    The apparatus according to any of claims 35-45, wherein the guard device is adapted to detect a type of the communication traffic that appears to be of the malicious origin, and to filter the communication traffic by intercepting the communication fraffic of the detected type.
  17. 55
    The apparatus according to any of claims 35-45, wherein the guard device is adapted to detect a type of the communication traffic that appears to be of the malicious origin, and to monitor the communication traffic so as to collect specific information relating to the traffic of the detected type.
  18. 57
    The apparatus according to any of claims 35-45, wherein the guard device is adapted to monitor and filter the c ommunication traffic that i s transmitted into a protected area of the network containing the group of the addresses so as to exclude the communication traffic from the area.
  19. 59
    Apparatus for processing communication fraffic, comprising a guard device, which is adapted to monitor the communication traffic originating from a group of addresses and passing through a selected node on a network, to detect a pattern in the fraffic originating from at least one of the addresses that is indicative of a malicious program running on a computer at the at least one of the addresses, and to trace a route of the traffic from the selected node back to the at least one of the addresses so as to identify a location of the computer on which the malicious program is running.
  20. 63
    Apparatus for processing communication traffic, comprising a guard device, which is adapted to monitor the communication traffic on a network so as to detect packets that are indicative of a communication failure in the network that is characteristic of a worm infection, to detect an increase in a rate of arrival of the packets that are indicative of the communication failure, and responsively to the increase, to filter the communication traffic so as to remove at least some of the communication traffic that is generated by the worm infection.
  21. 66
    Apparatus for processing communication traffic, comprising a guard device, which is adapted to monitor the communication traffic on a network so as to detect ill-formed packets, to make a determination, responsively to the ill-formed packets, that at least some of the communication traffic has been generated by a worm infection, and responsively to the determination, to filter the communication traffic so as to remove the at least some of the communication traffic that is generated by the worm infection.
  22. 69
    A computer software product, comprising a computer-readable medium in which program instructions are stored, which instructions, when read by a computer, cause the computer to monitor commumcation traffic that is directed to a group of addresses on a network, to determine respective baseline characteristics of the communication traffic that is directed to each of the addresses in the group, to detect a deviation from the respective baseline characteristics of the communication traffic directed to at least one of the addresses in the group, such that the deviation is indicative that at least some of the communication traffic may be of malicious origin, and responsively to detecting the deviation, to filter the communication traffic that is directed to all of the addresses in the group so as to remove at least some of the communication traffic that is of the malicious origin.
  23. 80
    The product according to any of claims 69-79, wherein the instructions cause the computer to receive packets that are indicative of a communication failure in the network that is characteristic of a worm infection, and to decide to filter the communication traffic responsively to receiving the packets.
  24. 82
    The product according to any of claims 69-79, wherein the instructions cause the computer to make a determination that one or more packets transmitted over the network are ill-formed, and to decide to filter the communication traffic responsively to the ill-formed packets.
  25. 83
    The product according to any of claims 69-79, wherein the instructions cause the computer to increment a count of events that are indicative of the malicious origin of the communication traffic, and to decide whether to filter the commumcation traffic responsively to the count.
  26. 86
    The product according to any of claims 69-79, wherein the instructions cause the computer to detect a type of the communication traffic that appears to b e o f the malicious origin, and to filter the communication traffic by intercepting the communication traffic of the detected type.
  27. 89
    The product according to any of claims 69-79, wherein the instructions cause the computer to detect a type of the commumcation traffic that appears to b e o f the malicious origin, and to monitor the communication traffic so as to collect specific information relating to the traffic of the detected type.
  28. 91
    The product according to any of claims 69-79, wherein the instructions cause the computer to monitor and filter the communication traffic that is transmitted into a protected area of the network containing the group of the addresses so as to exclude the communication traffic from the area.
  29. 93
    A computer software product, comprising a computer-readable medium in which program instructions are stored, which instructions, when read by a computer, cause the computer to monitor the communication traffic originating from a group of addresses and passing through a selected node on a network, to detect a pattern in the traffic originating from at least one of the addresses that is indicative of a malicious program running on a computer at the at least one of the addresses, and to trace a route of the traffic from the selected node back to the at least one of the addresses so as to identify a location of the computer on which the malicious program is running.
  30. 97
    A computer software product, comprising a computer-readable medium in which program instructions are stored, which instructions, when read by a computer, cause the computer to monitor the communication traffic on a network so as to detect packets that are indicative of a communication failure in the network that is characteristic of a worm infection, to detect an increase in a rate of arrival of the packets that are indicative of the communication failure, and responsively to the increase, to filter the communication fraffic so as to remove at least some of the communication fraffic that is generated by the worm infection.
  31. 100
    A computer software product, comprising a computer-readable medium in which program instructions are stored, which instructions, when read by a computer, cause the computer to monitor the communication fraffic on a network so as to detect ill-formed packets, to make a determination, responsively to the ill-formed packets, that at least some of the communication traffic has been generated by a worm infection, and responsively to the determination, to filter the communication traffic so as to remove the at least some of the communication fraffic that is generated by the worm infection.
Independent claims31