HEURISTIC DETECTION AND TERMINATION OF FAST SPREADING NETWORK WORM ATTACKS

Patent №

US 7,159,149

Granted

2007-01-02

Filed 2002

Owner

SYMANTEC CORPORATION

Lab

AI components

1

hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

10280586

Methods, apparati, and computer program products for detecting and responding to fast-spreading network worm attacks include a network monitoring module (110), which observes (205) failed network connection attempts from multiple sources. A logging module (120) logs (220) the failed connection attempts. An analysis module (150) uses the logged data on the failed connection attempts to determine (225) whether a sources is infected with a worm using a set of threshold criteria. The threshold criteria indicate whether a source's failed connection attempts are non-normal. In one embodiment, a response module (160) responds (240) to the computer worm by, e.g., alerting a user or system administrator, terminating an infected process (20), or terminating the infected source's network access.

AI hardwareH04L 63/145G06F 21/566

AI classification

AI hardware0.92
Machine learning0.05
Planning0.03
Knowledge representation0.02
Natural language0.00
Evolutionary computation0.00
Vision0.00
Speech0.00

Ownership

SYMANTEC CORPORATION

assignment · 134320290

Assignors

SPIEGEL, MARK, MCCORKENDALE, BRUCE, SOBEL, WILLIAM

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC