- 专利标题: Intrusion detection to prevent impersonation attacks in computer networks
-
申请号: US15616514申请日: 2017-06-07
-
公开(公告)号: US10193907B2公开(公告)日: 2019-01-29
- 发明人: David McGrew , Titouan Rigoudy
- 申请人: Cisco Technology, Inc.
- 申请人地址: US CA San Jose
- 专利权人: Cisco Technology, Inc.
- 当前专利权人: Cisco Technology, Inc.
- 当前专利权人地址: US CA San Jose
- 代理机构: Hickman Palermo Becker Bingham LLP
- 主分类号: G06F21/55
- IPC分类号: G06F21/55 ; H04L29/06
摘要:
In an embodiment, a central computer performs a data processing method. The central computer receives telemetry data from intrusion sensors. The central computer stores authentication records in a hosts database. Each authentication record is based on the telemetry data and comprises a thumbprint of a public key certificate and a host identifier of a sender computer. The central computer receives a suspect record that was sent by a first intrusion sensor. The suspect record has a first particular thumbprint of a first particular public key certificate and a first particular host identifier of a suspect sender. From the hosts database, the central computer searches for a matching record having a same host identifier as the first particular host identifier of the suspect record and a same thumbprint as the first particular thumbprint of the suspect record. The central computer generates an intrusion alert when no matching record is found.
公开/授权文献
信息查询