Invention Grant
- Patent Title: Detecting network reconnaissance by tracking intranet dark-net communications
-
Application No.: US14644182Application Date: 2015-03-10
-
Publication No.: US09602533B2Publication Date: 2017-03-21
- Inventor: Nicolas Beauchesne , Sungwook Yoon
- Applicant: Vectra Networks, Inc.
- Applicant Address: US CA San Jose
- Assignee: Vectra Networks, Inc.
- Current Assignee: Vectra Networks, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Vista IP Law Group, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/08

Abstract:
A method and system for detecting network reconnaissance is disclosed wherein network traffic can be parsed into unidirectional flows that correspond to sessions. A learning module may categorize computing entities inside the network into assets and generate asset data to monitor the computing entities. If one or more computing entities address a flow to an address of a host that no longer exists, ghost asset data may be recorded and updated in the asset data. When a computing entity inside the network contacts an object in the dark-net, the computing entity may be recorded a potential mapper. When the computing entity tries to contact a number of objects in the dark-net, such that a computed threshold is exceeded, the computing entity is identified a malicious entity performing network reconnaissance.
Public/Granted literature
- US20150264078A1 DETECTING NETWORK RECONNAISSANCE BY TRACKING INTRANET DARK-NET COMMUNICATIONS Public/Granted day:2015-09-17
Information query