Can Sax2 identify the worm infected machines in network?
Yes it can. There are two kinds worm. One is based on e-mail worm; the other one is based on operating system. The first worm’s the performance of the main characteristics is high frequency sending a message, similar content in the message headers, the same e-mail attachments. The second worm’s the performance of the main characteristics is trying to work with all host LAN connection, linking the port are consistent and link between the gap between short time, greater flow of occupation. Sax2’s email logs can capture analysis and reorganize sending and receiving mail in the network. According to e-mail log information and the features of e-mail worm, user can identify the worm infected machines in network. Through packet view and conversation view, you can easily identify infected machines within vulnerabilities worm.