发明名称 Network infrastructure obfuscation
摘要 A shadow network, which can be a virtual reproduction of a real, physical, base computer network, is described. Shadow networks duplicate the topology, services, host, and network traffic of the base network using shadow hosts, which are low interaction, minimal-resource-using host emulators. The shadow networks are connected to the base network through virtual switches, etc. in order to form a large obfuscated network. When a hacker probes into a host emulator, a more resource-intensive virtual machine can be swapped in to take its place. When a connection is attempted from a host emulator to a physical computer, the a host emulator can step in to take the place of the physical computer, and software defined networking (SDN) can prevent collisions between the duplicated IP addresses. Replicating the shadow networks within the network introduces problems for hackers and allows a system administrator easier ways to identify intrusions.
申请公布号 US9021092(B2) 申请公布日期 2015.04.28
申请号 US201314058034 申请日期 2013.10.18
申请人 Shadow Networks, Inc. 发明人 Silva Steven M.;Zhang Yadong;Winsborrow Eric;Wu Johnson L.;Schultz Craig A.
分类号 G06F15/173;H04L29/06;H04L12/24 主分类号 G06F15/173
代理机构 Kilpatrick Townsend & Stockton LLP 代理人 Kilpatrick Townsend & Stockton LLP
主权项 1. A method of obfuscating physical computers on a computer network from hackers, the method comprising: capturing packets on a computer network of physical computers; monitoring the captured packets to ascertain a schedule of a plurality of connection activations and deactivations of the physical computers on the network; surveying a logical topology of the computer network; instantiating and initializing a plurality of software-based host emulators, each host emulator configured to respond to an Internet control message protocol (ICMP) echo request packet; obtaining an Internet protocol (IP) address for each host emulator based on the surveyed topology; and connecting the host emulators to the base computer network over time based on the ascertained schedule and a random number generator, the connecting substantially interleaving the connecting of the host emulators with the plurality of connection activations of the physical computers.
地址 Santa Clara CA US