- 专利标题: Honeypot network services
-
申请号: US15010783申请日: 2016-01-29
-
公开(公告)号: US10284598B2公开(公告)日: 2019-05-07
- 发明人: Daniel Stutz
- 申请人: Sophos Limited
- 申请人地址: GB Abingdon
- 专利权人: Sophos Limited
- 当前专利权人: Sophos Limited
- 当前专利权人地址: GB Abingdon
- 代理机构: Strategic Patents, P.C.
- 主分类号: H04L9/00
- IPC分类号: H04L9/00 ; H04L29/06
摘要:
In general, in one aspect, a system for providing honeypot network services may monitor network activity, and detect network activity indicative of network service discovery by a first device, for example, port scanning. The system may present a temporarily available network service to the first device in response to detecting the activity indicative of port scanning, for example, by redirecting traffic at an unassigned network address to a honeypot network service. The system may monitor communication between the first device and the presented honeypot network service to determine whether the monitored communication is indicative of a threat, and determine that the first device is compromised based on the monitored communication between the first device and the presented honeypot network service. The system may initiate measures to protect the network from the compromised first device.
公开/授权文献
- US20170223052A1 HONEYPOT NETWORK SERVICES 公开/授权日:2017-08-03
信息查询