IP Library Granted Patent US 8,341,740
Granted Patent B2
US 8,341,740 · App. 12/124,431 · Granted Dec 25, 2012

Method and system for identifying enterprise network hosts infected with slow and/or distributed scanning malware

Assignee: Alcatel Lucent
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,341,740
App. No.
12/124,431
Granted
Dec 25, 2012
Kind
B2
Abstract

Malware detection systems are presented in which a list is constructed of enterprise hosts to or from which each given enterprise network host sends or receives packets within a current measurement period and statistics are accumulated based on two or more measurement period lists, with a count value being derived from the statistics to indicate the number of other hosts to or from which each monitored host sent or received packets, and one or more monitored hosts may be identified as suspected of being infected with slow and/or distributed scanning malware for which the count value exceeds a threshold value.

Claims (25)

1. A method of identifying enterprise network hosts suspected of being infected with slow and/or distributed scanning malware, the method comprising:

constructing a current measurement period list of enterprise hosts to or from which each given host of an enterprise network sent or received packets within a current measurement period;

accumulating statistics based on two or more measurement period lists;

deriving a count value from the accumulated statistics for monitored hosts of the enterprise network, each count value being indicative of the number of other hosts of the enterprise network to or from which each given monitored host of the enterprise network sent or received packets;

selectively excluding one or more hosts that serve as email servers. web proxies, or NTP servers from the monitored hosts of the enterprise network; and

selectively identifying one or more monitored hosts of the enterprise network for which the count value exceeds a threshold value as suspected of being infected with slow and/or distributed scanning malware.

2. The method of claim 1 , wherein constructing the current measurement period list includes creating a fan-out list for each given host of the enterprise network indicating other hosts to which the given host of the enterprise network sent packets within the current measurement period.

3. The method of claim 1 , wherein constructing the current measurement period list includes creating a fan-in list for each given host of the enterprise network indicating other hosts from which each given host of the enterprise network received packets within the current measurement period.

4. The method of claim 1 , further comprising computing the threshold based at least in part on an average of the count values for the monitored hosts of the enterprise network.

5. A system for identifying enterprise network hosts suspected of being infected with slow and/or distributed scanning malware, comprising:

a network element including an electronic processor operatively coupled to an enterprise network and operative to construct a current measurement period list of enterprise hosts of the enterprise network to or from which each given host of the enterprise network sent or received packets within a current measurement period;

a malware detection component operative to accumulate statistics based on two or more measurement period lists from the network element, the malware detection component comprising:

an analysis component operative to derive a count value from the accumulated statistics for one or more monitored hosts of the enterprise network and to selectively exclude one or more hosts that serve as email servers, web proxies. or NTP servers from the monitored hosts of the enterprise network, each count value being indicative of the number of other hosts of the enterprise network to or from which each given monitored host of the enterprise network sent or received packets, and to selectively identify one or more monitored hosts of the enterprise network for which the count value exceeds a threshold value as suspected of being infected with slow and/or distributed scanning malware.

6. The system of claim 5 , wherein the network element is an enterprise switch.

7. The system of claim 6 , wherein the malware detection component is implemented in an enterprise management station operatively coupled with the enterprise switch.

8. The system of claim 5 , wherein the malware detection component is implemented in an enterprise management station operatively coupled with the network element.

9. The system of claim 5 , wherein the network element is operative to create the current measurement period list as a fan-out list for each given host of the enterprise network indicating other hosts of the enterprise network to which the given host of the enterprise network sent packets within the current measurement period.

10. The system of claim 5 , wherein the network element is operative to create the current measurement period list as a fan-in list for each given host of the enterprise network indicating other hosts of the enterprise network from which each given host of the enterprise network received packets within the current measurement period.

11. The system of claim 5 , wherein the analysis component is operative to compute the threshold based at least in part on an average of the count values for the monitored hosts of the enterprise network.

12. A method of identifying enterprise network hosts suspected of being infected with slow and/or distributed scanning malware, the method comprising:

constructing a current measurement period list of enterprise hosts of an enterprise network to or from which each given host of the enterprise network sent or received packets within a current measurement period;

accumulating statistics based on two or more measurement period lists;

deriving a count change value from the accumulated statistics for one or more monitored hosts of the enterprise network, each count change value being indicative of a change in the number of other hosts of the enterprise network to or form which each given monitored host of the enterprise network sent or received packets;

selectively excluding one or more hosts that serve as email servers, web proxies, or NTP servers from the monitored host of the enterprise network; and

selectively indentifying one or more monitored hosts of the enterprise network for which the count change value exceeds a change threshold value as suspected of being infected with slow and/or distributed scanning malware.

Assignments (3)
SECURITY INTEREST Recorded Jun 1, 2021
From: WSOU INVESTMENTS, LLC
To: OT WSOU TERRIER HOLDINGS, LLC
Reel/Frame 056990/0081 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2018
From: ALCATEL LUCENT
To: WSOU INVESTMENTS, LLC
Reel/Frame 045085/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 21, 2008
From: ABDEL-AZIZ, BASSEM; CHOW, STANELY; CHEN, SHU-LIN
To: ALCATEL-LUCENT
Reel/Frame 020979/0118 →
Continuity (1)
Related Publication 20090293122A1 · Nov 26, 2009