发明名称 SYSTEM AND METHOD FOR ANALYZING UNATHORIZED INTRUSION INTO A COMPUTER NETWORK
摘要 The method analyzes unauthorized intrusion into a computer network. Access is allowed through one or more open ports to one or more virtualized decoy operating systems running on a hypervisor operating system hosted on a decoy network device. This may be done by opening a port on one of the virtualized decoy operating systems. A network attack on the virtualized operating system is then intercepted by an introspection module running on the hypervisor operating system. The attack-identifying information is communicated through a private network interface channel and stored on a database server as forensic data. A signature-generation engine uses this forensic data to generate a signature of the attack. An intrusion prevention system then uses the attack signature to identify and prevent subsequent attacks. A web-based visualization interface facilitates configuration of the system and analysis of (and response to) forensic data generated by the introspection module and the signature generation engine, as well as that stored in the processing module's relational databases.
申请公布号 EP2953049(A1) 申请公布日期 2015.12.09
申请号 EP20150174670 申请日期 2008.04.15
申请人 COUNTERTACK INC. 发明人 CAPALIK, ALAN
分类号 G06F21/55;G06F9/455;G06F21/56;H04L29/06 主分类号 G06F21/55
代理机构 代理人
主权项
地址