IP Library Granted Patent US 8,006,306
Granted Patent B2
US 8,006,306 · App. 11/387,114 · Granted Aug 23, 2011

Exploit-based worm propagation mitigation

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,006,306
App. No.
11/387,114
Granted
Aug 23, 2011
Kind
B2
Abstract

A system, method and computer program product for exploit-based worm detection and mitigation are disclosed. The system, method, and computer program product are configured to identify a signature representing content prevalent in network traffic, determine if the traffic including the signature exhibits propagation, determine if the traffic including the signature exhibits connectedness, and generate a worm signature based on the signature if the signature exhibits both connectedness and propagation.

Claims (80)

1. A computer program product residing on a non-transitory computer readable medium for intrusion detection, the computer program product comprising instructions for causing a processor to:

identify a signature representing content prevalent in network traffic;

determine if the network traffic that includes content associated with the signature exhibits propagation;

determine if the network traffic that includes content associated with the signature exhibits connectedness by:

comparing, to a first threshold, a number of destinations contacted by a host computer system with a packet that includes content associated with the signature;

determining that the host computer system exhibits connectedness if the number of destinations exceeds the first threshold; and

determining that the network traffic that includes content associated with the signature exhibits connectedness if a number of host computer systems that exhibit connectedness exceeds a second threshold; and

generate a worm signature based on the identified signature responsive to the network traffic that includes content associated with the signature exhibiting both connectedness and propagation.

2. The computer program product of claim 1 wherein the instructions to identify a signature representing content prevalent in network traffic comprise instructions to:

receive packet payload data; and

analyze the packet payload data to identify recurring sets of bits.

3. The computer program product of claim 2 wherein the instructions to analyze the packet payload data to identify recurring sets of bits comprises instructions to:

extract a plurality of sets of bits having a predetermined length;

compute a hash of each of the plurality of sets of bits; and

count the number of times a particular hash value occurs during a period of time.

4. The computer program product of claim 1 further comprising instructions to:

consolidate multiple signatures into a single signature.

5. The computer program product of claim 1 wherein the computer program product further comprises instructions for causing a processor to:

detect email-based worms.

6. The computer program product of claim 5 wherein the instructions for causing a processor to detect email-based worms comprise instructions for causing a processor to:

identify a second signature representing content prevalent in an email-based network traffic;

generate a client list for the second signature;

determine if a number of clients included in the client list exceeds a threshold;

generate a worm signature based on the second signature responsive to the number of clients included in the client list exceeding the threshold.

7. The computer program product of claim 1 wherein the instructions to determine if the traffic including the signature exhibits propagation comprise instructions to:

generate a table associated with the propagation of traffic including a particular signature in the network.

8. The computer program product of claim 7 , wherein the table comprises a tree with a number of levels, each of the levels including a number of hosts.

9. The computer program product of claim 8 wherein the instructions to determine if the traffic including the signature exhibits propagation comprise instructions to:

compare the number of levels to a first value;

compare the number of hosts in each of the levels to a second value; and

identify the signature as exhibiting propagation if the number of levels is greater than or equal to the first value and the number of hosts in each of the levels is greater than or equal to the second value.

10. A computer-implemented method, wherein the computer includes a processor, the method comprising:

identifying a signature representing content prevalent in network traffic;

determining, by the computer, if the network traffic that includes content associated with the signature exhibits propagation;

determining if the network traffic that includes content associated with the signature exhibits connectedness by:

comparing, to a first threshold, a number of destinations contacted by a host computer system with a packet that includes content associated with the signature;

determining that the host computer system exhibits connectedness if the number of destinations exceeds the first threshold; and

determining that the network traffic that includes content associated with the signature as exhibits connectedness if a number of host computer systems that exhibit connectedness exceeds a second threshold; and

generating a worm signature based on the identified signature responsive to the network traffic that includes content associated with the signature exhibiting both connectedness and propagation.

11. The method of claim 10 , further comprising:

receiving packet payload data; and

analyzing the packet payload data to identify recurring sets of bits.

12. The method of claim 11 , further comprising:

extracting a plurality of sets of bits having a predetermined length;

computing a hash of each of the plurality of sets of bits; and

counting the number of times a particular hash value occurs during a period of time.

13. The method of claim 10 , further comprising:

identifying multiple signatures; and

consolidating multiple, identified signatures into a single signature.

14. The method of claim 10 further comprising:

detecting email-based worms.

15. The method of claim 10 , further comprising:

generating a table associated with the propagation of traffic including a particular signature in the network, the table comprising a tree with a number of levels, each of the levels including a number of hosts.

16. The method of claim 15 , further comprising:

comparing the number of levels to a first value;

comparing the number of hosts in each of the levels to a second value; and

identifying the signature as exhibiting propagation if the number of levels is greater than or equal to the first value and the number of hosts in each of the levels is greater than or equal to the second value.

17. A computer-implemented instruction detection system, the system comprising:

a memory;

a processor; and

a system to profile network traffic configured to:

identify a signature representing content prevalent in network traffic;

determine if the network traffic that includes content associated with the signature exhibits propagation;

determine if the network traffic that includes content associated with the signature exhibits connectedness by:

comparing, to a first threshold, a number of destinations contacted by a host computer system with a packet that includes that includes content associated with the signature;

determining that the host computer system exhibits connectedness if the number of destinations exceeds the first threshold; and

determining that the network traffic that includes content associated with the signature exhibits connectedness if a number of host computer systems that exhibit connectedness exceeds a second threshold; and

generate a worm signature based on the identified signature responsive to the network traffic that includes content associated with the signature exhibiting both connectedness and propagation.

18. The system of claim 17 , wherein profiler is further configured to:

receive packet payload data; and

analyze the packet payload data to identify recurring sets of bits.

19. The system of claim 17 , wherein profiler is further configured to:

extract a plurality of sets of bits having a predetermined length;

compute a hash of each of the plurality of sets of bits; and

count the number of times a particular hash value occurs during a period of time.

20. The system of claim 17 , wherein the system is further configured to:

generate a table associated with the propagation of traffic including a particular signature in the network, the table comprising a tree with a number of levels, each of the levels including a number of hosts;

compare the number of levels to a first value;

compare the number of hosts in each of the levels to a second value; and

identify the signature as exhibiting propagation if the number of levels is greater than or equal to the first value and the number of hosts in each of the levels is greater than or equal to the second value.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2009
From: MAZU NETWORKS, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 022542/0800 →
CHANGE OF NAME Recorded Mar 30, 2009
From: MAZU NETWORKS, INC.
To: MAZU NETWORKS, LLC
Reel/Frame 022460/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2006
From: GOPALAN, PREM; JAMIESON, KYLE; MAVROMMATIS, PANAYIOTIS
To: MAZU NETWORKS, INC.
Reel/Frame 018153/0137 →