发明申请
US20120255019A1 METHOD AND SYSTEM FOR OPERATING SYSTEM IDENTIFICATION IN A NETWORK BASED SECURITY MONITORING SOLUTION
有权
基于网络的安全监控解决方案中的系统识别操作方法和系统
- 专利标题: METHOD AND SYSTEM FOR OPERATING SYSTEM IDENTIFICATION IN A NETWORK BASED SECURITY MONITORING SOLUTION
- 专利标题(中): 基于网络的安全监控解决方案中的系统识别操作方法和系统
-
申请号: US13083501申请日: 2011-04-08
-
公开(公告)号: US20120255019A1公开(公告)日: 2012-10-04
- 发明人: Kevin McNamee , Mike Pelley , Darren Deridder , Paul Edwards
- 申请人: Kevin McNamee , Mike Pelley , Darren Deridder , Paul Edwards
- 申请人地址: US CA Mountain View
- 专利权人: Kindsight, Inc.
- 当前专利权人: Kindsight, Inc.
- 当前专利权人地址: US CA Mountain View
- 主分类号: G06F21/00
- IPC分类号: G06F21/00
摘要:
A method and system for providing network based malware detection in a service provider network is disclosed. Transmission control protocol (TCP) packets defining originating from an access device coupled to the service provider network defining a TCP session between a computing device coupled to the access device, and a destination coupled to the service provider network are received. An operating system identifier (OS ID) associated with the TCP session and the computing device is determined. If malware is present in the TCP session and an associated malware ID is determined by comparing a malware signature to the one or more TCP packets. An alert identifying a network address associated with the access device, the malware ID and the OS ID associated with TCP session that generated the alert can then be generated.
公开/授权文献
信息查询