IP Library Granted Patent US 8,578,479
Granted Patent B2
US 8,578,479 · App. 11/387,092 · Granted Nov 5, 2013

Worm propagation mitigation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,578,479
App. No.
11/387,092
Granted
Nov 5, 2013
Kind
B2
Abstract

A system, method, and computer program product for identifying a worm are disclosed. The system, method, and computer product are configured to generate a signature for a computer worm by identifying a set of bits representing the signature, generate a first worm signature based on the signature, and generate a second worm signature based on the signature. The first worm signature is formatted for a first device and the second worm signature is formatted for a second, different device. The first worm signature and the second worm signature are different.

Claims (50)

1. A computer program product residing on a non-transitory computer readable storage medium for intrusion detection in a network, the computer program product comprising instructions for causing a processor to:

generate an initial signature for a computer worm by identifying a set of bits representing the computer worm;

determine if devices in the network are capable of filtering traffic using the generated initial signature;

in response to determining that the devices in the network are not capable of filtering traffic using the generated initial signature, discard the generated initial signature; and

in response to determining that the devices in the network are capable of filtering traffic using the generated initial signature,

generate a first worm signature based on the generated initial signature, the first worm signature formatted for a first device; and

generate a second worm signature based on the generated initial signature, the second worm signature formatted for a second, different device, with the first worm signature and the second worm signature being different.

2. The computer program product of claim 1 further comprising instructions for causing a processor to:

communicate the first worm signature to the first device; and

communicate the second worm signature to the second device.

3. The computer program product of claim 1 further comprising instructions for causing a processor to log the identified set of bits in a database.

4. The computer program product of claim 1 wherein the first device is a device selected from the group consisting of a host based security device, an intrusion protection system, a firewall, a switch, and a router.

5. The computer program product of claim 1 wherein the second device is a device selected from the group consisting of a host based security device, an intrusion protection system, a firewall, a switch, and a router.

6. The computer program product of claim 1 wherein the instructions to generate the first worm signature and the instructions to generate the second worm signature comprise instructions to automatically generate the first and second worm signatures.

7. The computer program product of claim 1 wherein the instructions to generate the first worm signature and the instructions to generate the second worm signature comprise instructions to generate the first and second worm signatures without human intervention.

8. The computer program product of claim 1 wherein the first and second worm signatures comprise a set of instructions for causing the first and second device to mitigate worm propagation.

9. The computer program product of claim 1 wherein the instructions to identify the set of bits representing the signature for the computer worm comprise instructions to:

receive packet payload data; and

analyze the packet payload data to identify recurring sets of bits.

10. An intrusion detection system in a network, comprising:

a system configured to:

analyze packet payloads, by a computer processor, to generate an initial signature for a computer worm by identifying a set of bits representing the computer worm;

determine if devices in the network are capable of filtering traffic using the generated initial signature;

in response to determining that the devices in the network are not capable of filtering traffic using the generated initial signature, discard the generated initial signature; and

in response to determining that the devices in the network are capable of filtering traffic using the generated initial signature,

generate a first worm signature based on the generated initial signature, the first worm signature being formatted for a first device; and

generate a second worm signature based on the generated initial signature, the second worm signature being formatted for a second, different device, with the first worm signature and the second worm signature being different.

11. The intrusion detection system of claim 10 , wherein the system is further configured to:

communicate the first worm signature to the first device; and

communicate the second worm signature to the second device.

12. The intrusion detection system of claim 10 , further comprising:

a database; and

a processor configured to log the identified set of bits in a database.

13. The intrusion detection system of claim 10 wherein at least one of the first device and the second device comprises a device selected from the group consisting of a host based security device, an intrusion protection system, a firewall, a switch, and a router.

14. A method for intrusion detection in a network comprising:

generating, by a computer processor, an initial signature for a computer worm by identifying a set of bits representing the computer worm;

determining if devices in the network are capable of filtering traffic using the generated initial signature;

in response to determining that the devices in the network are not capable of filtering traffic using the generated initial signature, discarding the generated initial signature; and

in response to determining that the devices in the network are capable of filtering traffic using the generated initial signature,

generating a first worm signature based on the generated initial signature, the first worm signature being formatted for a first device; and

generating a second worm signature based on the generated initial signature, the second worm signature being formatted for a second, different device, with the first worm signature and the second worm signature being different.

15. The method of claim 14 further comprising:

communicating the first worm signature to the first device; and

communicating the second worm signature to the second device.

16. The method of claim 14 further comprising logging the identified set of bits in a database.

17. The method of claim 14 wherein at least one of the first device and the second device comprises a device selected from the group consisting of a host based security device, an intrusion protection system, a firewall, a switch, and a router.

18. The method of claim 14 wherein the first and second worm signatures comprise a set of instructions for causing the first and second device to mitigate worm propagation.

19. The method of claim 14 further comprising:

receiving packet payload data; and

analyzing the packet payload data to identify recurring sets of bits.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2009
From: MAZU NETWORKS, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 022542/0800 →
CHANGE OF NAME Recorded Mar 30, 2009
From: MAZU NETWORKS, INC.
To: MAZU NETWORKS, LLC
Reel/Frame 022460/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2006
From: GOPALAN, PREM; JAMIESON, KYLE; MAVROMMATIS, PANAYIOTIS
To: MAZU NETWORKS, INC.
Reel/Frame 018153/0102 →