- Patent Title: Enhanced security techniques for remote reverse shell prevention
-
Application No.: US15267037Application Date: 2016-09-15
-
Publication No.: US10666618B2Publication Date: 2020-05-26
- Inventor: Shlomi Boutnaru
- Applicant: PAYPAL, INC.
- Applicant Address: US CA San Jose
- Assignee: PAYPAL, INC.
- Current Assignee: PAYPAL, INC.
- Current Assignee Address: US CA San Jose
- Agency: Haynes and Boone, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
When a computer system is compromised by a malicious user, detecting or preventing the malicious user can improve the security and efficiency of the computer system, as well as prevent data from being deleted or corrupted and/or stolen. An attacker who compromises a computer system is likely to take certain actions to exert control over the computer or avoid detection. When a compromised system is behind a network firewall, the attacker may seek to open a remote reverse shell on the compromised system to more easily issue commands, as the firewall may block direct attempts from outside the network to contact the compromised system. Detecting a reverse shell can be difficult, slow, and unreliable, however. The present disclosure discusses methods for detecting reverse shells based on analyzing redirection of data streams such as STDIN, STDOUT, and STDERR.
Public/Granted literature
- US20180077201A1 Enhanced Security Techniques for Remote Reverse Shell Prevention Public/Granted day:2018-03-15
Information query