Invention Grant
- Patent Title: Detecting malicious behaviour on a network
- Patent Title (中): 检测网络上的恶意行为
-
Application No.: US13510545Application Date: 2010-11-19
-
Publication No.: US09003526B2Publication Date: 2015-04-07
- Inventor: Fadi J El-Moussa
- Applicant: Fadi J El-Moussa
- Applicant Address: GB London
- Assignee: British Telecommunications public limited company
- Current Assignee: British Telecommunications public limited company
- Current Assignee Address: GB London
- Agency: Nixon & Vanderhye P.C.
- Priority: EP09252660 20091120
- International Application: PCT/GB2010/002146 WO 20101119
- International Announcement: WO2011/061509 WO 20110526
- Main IPC: H04L29/08
- IPC: H04L29/08 ; H04L29/06 ; G06F11/30 ; H04L29/12

Abstract:
An intrusion detection device (61) for monitoring one or more target devices and detecting malicious software operating on one of the one or more target devices. The intrusion detection device has an interface arrangement (61, 10) comprising one or more interfaces (6110) for receiving inward bound traffic destined for the one or more target devices and outward bound traffic originating from the one or more target devices. The intrusion detection device (61) also includes categorization means (6140) for categorizing incoming service requests destined for one of the one or more target devices as either harmless or potentially suspicious; monitoring means (6150) operable, in respect of each incoming service request identified as being potentially suspicious, to monitor the behavior of the associated target device for behavior indicative of the target device operating as a proxy server; and a notifier (6160) for generating a notification in the event that the monitored behavior is indicative of the device acting as a proxy server.
Public/Granted literature
- US20120278889A1 DETECTING MALICIOUS BEHAVIOUR ON A NETWORK Public/Granted day:2012-11-01
Information query