IP Library Patent Application 10701353
Patent Application
App. No. 10/701,353

Detection of scanning attacks

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
10/701,353
Abstract

A system for detecting network intrusions and other conditions in a network is described. The system includes a plurality of collector devices that are disposed to collect data and statistical information on packets that are sent between nodes on a network. An aggregator device is disposed to receive data and statistical information from the plurality of collector devices. The aggregator device produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The aggregator runs processes that determine network events from aggregating of anomalies into network events.

Claims (42)

1 . A method comprising:

detecting scans emanating from hosts;

analyzing records of scans to determine receivers of a scan and determine which of those receivers of scans that later became sources for a subsequent scan; and

reconstructing the path by which a worm spread based on the analyzed records; and

sending notification of the reconstructed path to a console.

2 . The method of claim 1 further comprising:

examining ports used by the worm to determine which services were exploited by the scan.

3 . The method of claim 2 further comprises:

analyzing scan anomalies for the sets of hosts scanned.

4 . The method of claim 3 further comprising:

determining that a worm has passed from a first host to a second host over a time period.

5 . The method of claim 1 further comprising:

determining ports that a worm spread through to identify vulnerable services in the hosts.

6 . The method of claim 1 wherein detecting scans further comprises:

executing a scan detection process to determine hosts that were targets of scans.

7 . A computer program product residing on a computer readable medium for detecting worm propagating comprising instructions for causing a computer to:

detect scans emanating from hosts;

analyze records of scans to determine receivers of a scan and determine which of those receivers of scans that later became sources for a subsequent scan; and

reconstruct the path by which a worm spread based on the analyzed records.

8 . The computer program product of claim 7 further comprising instructions to:

examine ports used by the worm to determine which services were exploited by the scan.

9 . The computer program product of claim 7 further comprises instructions to:

analyze scan anomalies for the sets of hosts scanned.

10 . The computer program product of claim 9 further comprising instructions to:

determine that a worm has passed from a first host to a second host over a time period.

11 . The computer program product of claim 7 further comprising instructions to:

determine ports that a worm spread through to identify vulnerable services in the hosts.

12 . The computer program product of claim 7 wherein instructions to detect scans further comprises instructions to:

execute a scan detection process to determine hosts that were targets of scans.

13 . Apparatus comprising:

a processing device;

a memory;

a computer readable medium storing a computer program product for detecting worm propagating comprising instructions for causing the processor device to:

detect scans emanating from hosts;

analyze records of scans to determine receivers of a scan and determine which of those receivers of scans that later became sources for a subsequent scan; and

reconstruct the path by which a worm spread based on the analyzed records.

14 . The apparatus of claim 13 further comprising instructions to:

examine ports used by the worm to determine which services were exploited by the scan.

15 . The apparatus of claim 13 further comprises instructions to:

analyze scan anomalies for the sets of hosts scanned.

16 . The apparatus of claim 13 further comprising instructions to:

determine that a worm has passed from a first host to a second host over a time period.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2009
From: MAZU NETWORKS, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 022542/0800 →
CHANGE OF NAME Recorded Mar 30, 2009
From: MAZU NETWORKS, INC.
To: MAZU NETWORKS, LLC
Reel/Frame 022460/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 3, 2004
From: POLETTO, MASSIMILIANO ANTONIO; WILKEN, BENJAMIN
To: MAZU NETWORKS, INC.
Reel/Frame 015648/0266 →