Invention Grant
- Patent Title: Universal worm catcher
- Patent Title (中): 万能虫捕手
-
Application No.: US10577860Application Date: 2004-11-18
-
Publication No.: US07950059B2Publication Date: 2011-05-24
- Inventor: Leeor Aharon , Cfir Cohen
- Applicant: Leeor Aharon , Cfir Cohen
- Applicant Address: IL Ramat Gan
- Assignee: Check-Point Software Technologies Ltd.
- Current Assignee: Check-Point Software Technologies Ltd.
- Current Assignee Address: IL Ramat Gan
- Agent Mark M. Friedman
- International Application: PCT/IL2004/001066 WO 20041118
- International Announcement: WO2005/062707 WO 20050714
- Main IPC: G08B23/00
- IPC: G08B23/00

Abstract:
A method for detecting malicious code in a stream of data traffic input (400) to a gateway in a data network by monitoring for suspicious data in the stream of data traffic (407). Upon detecting the suspicious data, an attempt is made to disassemble the suspicious data (403) and a treat weight is assigned for each instruction. The attempt to disassemble is initiated at initial instructions each with a different offset within the suspicious portion of data. The threat weights are accumulated respectively for each branch option in the disassembled code (403), producing respectively an accumulated threat weight for each branch option. When the accumulated threat weight exceeds a previously defined threshold level, an alert is generated and/or traffic is blocked from the source of the malicious code.
Public/Granted literature
- US20070089171A1 Universal worm catcher Public/Granted day:2007-04-19
Information query