首页> 外国专利> TECHNIQUES FOR SECURELY DETECTING COMPROMISES OF ENTERPRISE END STATIONS UTILIZING TUNNEL TOKENS

TECHNIQUES FOR SECURELY DETECTING COMPROMISES OF ENTERPRISE END STATIONS UTILIZING TUNNEL TOKENS

机译:利用隧道令牌安全地检测企业终端站的缺陷的技术

摘要

A token tunnel server (TTS) within an enterprise network receives packets from a source address directed to a destination address (both of the enterprise network) that were caused to be originated by an attacker. The packets carry data including a token that was placed upon an end station of the enterprise and that appears to be useful for accessing an enterprise server, despite the apparent enterprise server not actually being deployed within the enterprise network. The TTS transmits packets carrying the data (that do not include the source address) across a public network outside of the enterprise network to a tunnel gateway server (TGS). The TGS sends the data to a trap server that acts as the apparent enterprise server. Actions of the attacker with regard to the trap server can be monitored while the source address is not provided to the TGS.
机译:企业网络中的令牌隧道服务器(TTS)从源地址接收指向目标地址(企业网络均是目标地址)的数据包,这些数据包是由攻击者发起的。数据包携带包含令牌的数据,令牌放置在企业的终端站上,并且尽管显然没有在企业网络中实际部署企业服务器,但似乎对于访问企业服务器很有用。 TTS通过企业网络外部的公共网络将承载数据(不包括源地址)的数据包传输到隧道网关服务器(TGS)。 TGS将数据发送到充当明显企业服务器的陷阱服务器。当源地址未提供给TGS时,可以监视攻击者针对陷阱服务器的操作。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号