Invention Grant
US09407647B2 Method and system for detecting external control of compromised hosts
有权
用于检测受损主机的外部控制的方法和系统
- Patent Title: Method and system for detecting external control of compromised hosts
- Patent Title (中): 用于检测受损主机的外部控制的方法和系统
-
Application No.: US14644177Application Date: 2015-03-10
-
Publication No.: US09407647B2Publication Date: 2016-08-02
- Inventor: Nicolas Beauchesne , Ryan James Prenger
- Applicant: Vectra Networks, Inc.
- Applicant Address: US CA San Jose
- Assignee: Vectra Networks, Inc.
- Current Assignee: Vectra Networks, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Vista IP Law Group, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/24

Abstract:
A detection engine may be implemented by receiving network traffic and processing the traffic into one or more session datasets. Sessions not initiated by an internal host may be discarded. The frequency between the communication packets from the internal host to external host may be grouped or processed into rapid-exchange instances. The number of rapid-exchange instances, the time intervals between them, and/or the rhythm and directions of the initiation of the instances may be analyzed to determine that a human actor is manually controlling the external host. In some embodiments, when it is determined that only one human actor is involved, alarm data may be generated that indicates that a network intrusion involving manual remote control has occurred or is underway.
Public/Granted literature
- US20150264069A1 METHOD AND SYSTEM FOR DETECTING EXTERNAL CONTROL OF COMPROMISED HOSTS Public/Granted day:2015-09-17
Information query