Invention Grant
- Patent Title: Apparatus and method for conducting endpoint-network-monitoring
-
Application No.: US17839372Application Date: 2022-06-13
-
Publication No.: US11698963B2Publication Date: 2023-07-11
- Inventor: Robert Julian Noeth , Earnest Gregory Ake
- Applicant: Huntress Labs Incorporated
- Applicant Address: US MD Elicott City
- Assignee: HUNTRESS LABS INCORPORATED
- Current Assignee: HUNTRESS LABS INCORPORATED
- Current Assignee Address: US MD Ellicott City
- Agency: Cooley LLP
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F21/56 ; H04L9/40 ; H04L43/028 ; H04L43/062 ; H04L47/10 ; H04L69/22 ; H04L43/0876

Abstract:
Provided is an intrusion detection technique configured to: obtain kernel-filter criteria indicative of which network traffic is to be deemed potentially malicious, determine that a network packet is resident in a networking stack, access at least part of the network packet, apply the kernel-filter criteria to the at least part of the network packet and, based on applying the kernel-filter criteria, determining that the network packet is potentially malicious, associate the network packet with an identifier of an application executing in userspace of the operating system and to which or from which the network packet is sent, and report the network packet in association with the identifier of the application to an intrusion-detection agent executing in userspace of the operating system of the host computing device, the intrusion-detection agent being different from the application to which or from which the network packet is sent.
Public/Granted literature
- US20230004640A1 APPARATUS AND METHOD FOR CONDUCTING ENDPOINT-NETWORK-MONITORING Public/Granted day:2023-01-05
Information query