Invention Grant
- Patent Title: Method, system, and apparatus to identify and study advanced threat tactics, techniques and procedures
-
Application No.: US15590540Application Date: 2017-05-09
-
Publication No.: US10462181B2Publication Date: 2019-10-29
- Inventor: Champ Clark, III , Robert Alvin Nunley
- Applicant: QUADRANT INFORMATION SECURITY
- Applicant Address: US FL Jacksonville
- Assignee: QUADRANT INFORMATION SECURITY
- Current Assignee: QUADRANT INFORMATION SECURITY
- Current Assignee Address: US FL Jacksonville
- Agency: Seyfarth Shaw LLP
- Agent Brian Michaelis
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/55

Abstract:
The present disclosure provides an information technology security system, method and apparatus that differentiates advanced attackers from unsophisticated attackers by querying a proprietary Threat Intelligence database that houses known attack and attacker information. Advanced attackers are proxied, or filtered, into a virtual honeypot where their tools, methods, and attack procedures can be recorded and studied. Context and back story are implemented into the honeypot to make it appear as real as possible by using a hardware “host” device located at the customer site that transparently forwards all traffic it receives into the virtual honeypot where the customer's network environment is re-created. Advanced attackers are filtered into this virtual honeypot where the tools and attack strategies that they otherwise would keep secret can be logged, examined, and researched.
Public/Granted literature
- US20170331858A1 METHOD, SYSTEM, AND APPARATUS TO IDENTIFY AND STUDY ADVANCED THREAT TACTICS, TECHNIQUES AND PROCEDURES Public/Granted day:2017-11-16
Information query