EP1595193B1

Detecting and protecting against worm traffic on a network

Abstract

This record has no abstract on file.

EP1595193B1, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Expired 5 February 2024, 2.6 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

20 claims: 8 independent, 12 dependent

  1. 1
    A method performed by an apparatus for processing communication traffic that is directed to a group of addresses on a network, comprising:selecting (50) a subset of the group of the addresses such that the addresses in the subset are expected to receive smaller amounts of the communication traffic than other addresses in the group;monitoring (52) the communication traffic that is directed to the addresses in the subset;determining (58) respective baseline characteristics of the communication traffic that is directed to each of the addresses in the subset;detecting (66) a deviation from the respective baseline characteristics of the communication traffic directed to at least one of the addresses in the subset, wherein the deviation is indicative that at least a portion of the communication traffic is of potentially malicious origin;and responsively to detecting (66) the deviation, filtering (70) the communication traffic that is directed to all of the addresses in the group so as to remove at least some of the communication traffic that is of the malicious origin.
  2. 7
    The method according to any of the preceding claims, wherein monitoring the communication traffic comprises making a determination that one or more packets transmitted over the network are ill-formed, and wherein filtering the communication traffic comprises deciding to filter the communication traffic responsively to the ill-formed packets.
  3. 8
    The method according to any of the preceding claims, wherein detecting the deviation comprises incrementing a count of events that are indicative of the malicious origin of the communication traffic, and deciding whether to filter the communication traffic responsively to the count.
  4. 11
    The method according to any of the preceding claims, wherein detecting the deviation comprises detecting a type of the communication traffic that appears to be of the malicious origin, and wherein filtering the communication traffic comprises intercepting the communication traffic of the detected type.
  5. 13
    The method according to any of the preceding claims, further comprising receiving packets that are indicative of a communication failure in the network that is characteristic of a worm infection, and wherein filtering the communication traffic comprises deciding to filter the communication traffic responsively to receiving the packets.
  6. 15
    The method according to any of the preceding claims, wherein monitoring and filtering the communication traffic comprises monitoring and filtering the communication traffic that is transmitted into a protected area of the network containing the group of the addresses so as to exclude the communication traffic from the area.
  7. 19
    Apparatus for processing communication traffic, which is adapted carry out the method of any preceding claim.
  8. 20
    A computer-readable medium comprising instructions which, when executed in a processing system, cause the processing system to perform a method according to any of Claims 1 to 18.