- 专利标题: Detecting attacks using passive network monitoring
-
申请号: US15694229申请日: 2017-09-01
-
公开(公告)号: US10243978B2公开(公告)日: 2019-03-26
- 发明人: Thomas Lawrence Roeh , Samuel Kanen Clement , John Augustus Kiefer
- 申请人: ExtraHop Networks, Inc.
- 申请人地址: US WA Seattle
- 专利权人: ExtraHop Networks, Inc.
- 当前专利权人: ExtraHop Networks, Inc.
- 当前专利权人地址: US WA Seattle
- 代理机构: Lowe Graham Jones PLLC
- 代理商 John W. Branch
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; H04L12/861 ; H04L12/26
摘要:
Embodiments are directed to detecting one or more attacks in a network. One or more network flows may be monitored using one or more network monitoring computers (NMCs). If one or more file write operations are detected based on information included in one or more packets of the one or more network flows, one or more detection rules may be executed to analyze one or more portions of the one or more packets to identify file information that is associated with the one or more file write operations. One or more metrics may be provided based on the one or more detection rules and one or more of the file information, the one or more file write operations, or the like. If one or more metrics exceed one or more threshold values, one or more reports of one or more attacks may be provided.
公开/授权文献
- US20180145995A1 DETECTING ATTACKS USING PASSIVE NETWORK MONITORING 公开/授权日:2018-05-24
信息查询