Invention Grant
- Patent Title: Detecting computer security threats in electronic documents based on structure
-
Application No.: US15162233Application Date: 2016-05-23
-
Publication No.: US09609013B1Publication Date: 2017-03-28
- Inventor: Oren Falkowitz , Philip Syme
- Applicant: AREA 1 SECURITY, INC.
- Applicant Address: US CA Menlo Park
- Assignee: AREA 1 SECURITY, INC.
- Current Assignee: AREA 1 SECURITY, INC.
- Current Assignee Address: US CA Menlo Park
- Agency: Hickman Palermo Becker Bingham LLP
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
In an embodiment, a method providing an improvement in remediating vulnerabilities in computer security comprising: receiving, using a network tap of a sensor computer that is coupled to a compromised computer, a communication packet that was sent from the compromised computer to a target computer; using the sensor computer, determining that the target computer is one of a plurality of enterprise computers; reading, at the sensor computer, a plurality of fields within a header of the communication packet; and performing a remediation measure by generating a header of an action packet, wherein the header comprises duplicates of at least some fields of the plurality of fields so as to appear to be generated by the target computer, generating a payload of the action packet, and sending the action packet comprising the generated header and the generated payload to the compromised computer.
Information query