首页> 外国专利> Detecting lateral movement by malicious applications

Detecting lateral movement by malicious applications

机译:通过恶意应用程序检测横向移动

摘要

A computer program product for detecting malicious lateral movement in a network that when executed on a firewall for a plurality of endpoints, performs the steps of collecting notifications from each of the plurality of endpoints relating activities such as failed login attempts with other ones of the plurality of endpoints in the network. The notifications are analysed to identify, based on a pattern in the notifications, a compromised endpoint among the plurality of endpoints. When the pattern indicates a presence of malware on the compromised endpoint engaging in attempts at malicious lateral movement from the compromised endpoint, remediating the compromised endpoint by isolating the compromised endpoint from other ones of the plurality of endpoints. Remediating the compromised endpoint may also include removing a malware component associated with the malware, killing a process associated with a malware component or terminating a user session associated with a malware component.
机译:一种用于检测网络中恶意横向移动的计算机程序产品,当在多个端点的防火墙上执行该计算机程序时,该计算机程序产品执行从多个端点中的每个端点收集与活动相关的通知的步骤,例如,与多个端点中的其他端点进行失败的登录尝试网络中的端点数量。对通知进行分析,以基于通知中的模式在多个端点中识别受感染的端点。当模式指示受感染端点上存在恶意软件并试图从受感染端点进行恶意横向移动时,请通过将受感染端点与多个端点中的其他端点隔离来补救受感染端点。补救受感染的端点还可以包括:删除与恶意软件相关联的恶意软件组件,杀死与恶意软件组件相关联的进程或终止与恶意软件组件相关联的用户会话。

著录项

  • 公开/公告号GB2572471B

    专利类型

  • 公开/公告日2020-10-21

    原文格式PDF

  • 申请/专利权人 SOPHOS LIMITED;

    申请/专利号GB20190001182

  • 发明设计人 ANDREW J THOMAS;DANIEL STUTZ;

    申请日2016-06-30

  • 分类号G06F21/55;G06F21/44;G06F21/57;

  • 国家 GB

  • 入库时间 2022-08-21 10:59:47

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号