发明名称 System and method for tamper resistant reliable logging of network traffic
摘要 A network interface device includes a memory and a processor operable to receive a malicious packet marker, store the malicious packet marker to the memory, monitor network data packets flowing in the network interface device, determine that a packet matches the malicious packet marker, and store log information from the packet to the memory.
申请公布号 US9560062(B2) 申请公布日期 2017.01.31
申请号 US201314095783 申请日期 2013.12.03
申请人 SECUREWORKS CORP. 发明人 Khatri Mukund P.;Webb Theodore S.;Wilson Jacqueline H.;Ramsey Jon R.
分类号 H04L29/06 主分类号 H04L29/06
代理机构 Larson Newman, LLP 代理人 Larson Newman, LLP
主权项 1. A network interface device comprising: a first communication interface coupled to an information handling system; a second communication interface coupled to a management controller; a network port coupled to a network; a memory including first code and second code; and a processor operable to execute the first code to communicate network data packets between the first communication interface and the network port, and to execute the second code to: launch a log module in response to a command from the management controller;receive, by the log module, a malicious packet marker from the information handling system;store, by the log module, the malicious packet marker to the memory;receive, by the log module, a job entry from a management system separate from the management controller, wherein the job entry is received via the management controller via the second communication interface; andin response to receiving the job entry, to: monitor, by the log module, the network data packets flowing between the first communication interface and the network port;determine, by the log module, that a packet matches the malicious packet marker;store, by the log module, log information from the packet to the memory in response to determining that the packet matches the malicious packet marker; andsend, by the log module, the log information to the management controller via the second communication interface.
地址 Wilmington DE US