首页> 外国专利> Method, system, and apparatus to identify and study advanced threat tactics, techniques and procedures

Method, system, and apparatus to identify and study advanced threat tactics, techniques and procedures

机译:识别和研究高级威胁策略,技术和程序的方法,系统和装置

摘要

The present disclosure provides an information technology security system, method and apparatus that differentiates advanced attackers from unsophisticated attackers by querying a proprietary Threat Intelligence database that houses known attack and attacker information. Advanced attackers are proxied, or filtered, into a virtual honeypot where their tools, methods, and attack procedures can be recorded and studied. Context and back story are implemented into the honeypot to make it appear as real as possible by using a hardware “host” device located at the customer site that transparently forwards all traffic it receives into the virtual honeypot where the customer's network environment is re-created. Advanced attackers are filtered into this virtual honeypot where the tools and attack strategies that they otherwise would keep secret can be logged, examined, and researched.
机译:本公开提供了一种信息技术安全系统,方法和装置,其通过查询存储已知攻击和攻击者信息的专有威胁情报数据库来将高级攻击者与不复杂的攻击者区分开。高级攻击者被代理或过滤到虚拟蜜罐中,可以在其中记录和研究他们的工具,方法和攻击过程。通过使用位于客户站点上的硬件“主机”设备将上下文和背景故事实现到蜜罐中,以使其看起来尽可能真实,该设备将接收到的所有流量透明地转发到虚拟蜜罐中,在虚拟蜜罐中重新创建客户的网络环境。高级攻击者被过滤到此虚拟蜜罐中,在该蜜罐中可以记录,检查和研究他们本应保密的工具和攻击策略。

著录项

  • 公开/公告号US10462181B2

    专利类型

  • 公开/公告日2019-10-29

    原文格式PDF

  • 申请/专利权人 QUADRANT INFORMATION SECURITY;

    申请/专利号US201715590540

  • 发明设计人 CHAMP CLARK III;ROBERT ALVIN NUNLEY;

    申请日2017-05-09

  • 分类号H04L29/06;G06F21/55;

  • 国家 US

  • 入库时间 2022-08-21 12:14:45

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号