Invention Grant
- Patent Title: Identifying malware-infected network devices through traffic monitoring
-
Application No.: US16872302Application Date: 2020-05-11
-
Publication No.: US11277428B2Publication Date: 2022-03-15
- Inventor: David Paul Heilig
- Applicant: David Paul Heilig
- Applicant Address: US PA Lancaster
- Assignee: David Paul Heilig
- Current Assignee: David Paul Heilig
- Current Assignee Address: US PA Lancaster
- Agency: Ellenoff Grossman & Schole LLP
- Agent James M. Smedley; Alex Korona
- Main IPC: H04L45/00
- IPC: H04L45/00 ; H04L29/06

Abstract:
The present invention generally relates to detecting malicious network activity coming from network devices such as routers and firewalls. Specifically, embodiments of the present invention provide for detecting stealth malware on a network device by comparing inbound and outbound network traffic to discover packets originating from the network device and packets that violate configuration rules. When combined with a network traffic monitor server configured to monitor actual network traffic reports and to receive known network traffic reports from host computers, the system can detect stealth network traffic originating from both network devices and host computer systems.
Public/Granted literature
- US20200274893A1 IDENTIFYING MALWARE-INFECTED NETWORK DEVICES THROUGH TRAFFIC MONITORING Public/Granted day:2020-08-27
Information query