The present invention provides a system and method of tracing the spread
of computer malware in a communication network. One aspect of the present
invention is a method that traces the spread of computer malware in a
communication network. When suspicious data characteristic of malware is
identified in a computing device connected to the communication network,
the method causes data that describes the state of the computing device
to be stored in a database. After a specific attack against the
communication network is confirmed, computing devices that are infected
with the malware are identified. Then, the spread of the malware between
computing devices in the communication network is traced back to a
source.