One aspect of the invention is a vulnerability detection mechanism that can detect a large class of attacks through dynamic dataflow analysis. Another aspect of the invention includes self-certifying alerts as the basis for safely sharing knowledge about worms. Another aspect of the invention is a resilient and self-organizing protocol to propagate alerts to all non-infected nodes in a timely fashion, even when under active attack during a worm outbreak. Another aspect of the invention is a system architecture that enables a large number of mutually untrusting computers to collaborate in the task of stopping a previously unknown worm, even when the worm is spreading rapidly and exploiting unknown vulnerabilities in popular software packages.

 
Web www.patentalert.com

< Apparatus, method and program to detect and control deleterious code (virus) in computer network

< Storage conversion for anti-virus speed-up

> Key-based secure storage

> Method and system for building dynamic firewall rules, based on content of downloaded documents

~ 00232