发明名称 Decoy Network Technology With Automatic Signature Generation for Intrusion Detection and Intrusion Prevention Systems
摘要 Improved methods and systems for decoy networks with automatic signature generation for intrusion detection and intrusion prevention systems. A modular decoy network with front-end monitor/intercept module(s) with a processing back-end that is separate from the protected network. The front-end presents a standard fully functional operating system that is a decoy so that the instigator of an attack is lead to believe a connection has been made to the protected network. The front-end includes a hidden sentinel kernal driver that monitors connections to the system and captures attack-identifying information. The captured information is sent to the processing module for report generation, data analysis and generation of an attack signature. The generated attack signature can then be applied to the library of signatures of the intrusion detection system or intrusion prevention system of the protected network to defend against network based attacks including zero-day attacks.
申请公布号 US2013152199(A1) 申请公布日期 2013.06.13
申请号 US201313759335 申请日期 2013.02.05
申请人 CAPALIK ALEN 发明人 CAPALIK ALEN
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址