首页> 外国专利> Enhanced Security Techniques for Remote Reverse Shell Prevention

Enhanced Security Techniques for Remote Reverse Shell Prevention

机译:增强的安全技术,用于远程反向Shell防护

摘要

When a computer system is compromised by a malicious user, detecting or preventing the malicious user can improve the security and efficiency of the computer system, as well as prevent data from being deleted or corrupted and/or stolen. An attacker who compromises a computer system is likely to take certain actions to exert control over the computer or avoid detection. When a compromised system is behind a network firewall, the attacker may seek to open a remote reverse shell on the compromised system to more easily issue commands, as the firewall may block direct attempts from outside the network to contact the compromised system. Detecting a reverse shell can be difficult, slow, and unreliable, however. The present disclosure discusses methods for detecting reverse shells based on analyzing redirection of data streams such as STDIN, STDOUT, and STDERR.
机译:当计算机系统被恶意用户入侵时,检测或阻止恶意用户可以提高计算机系统的安全性和效率,并防止数据被删除或破坏和/或被盗。攻击计算机系统的攻击者可能会采取某些措施来控制计算机或避免检测。当受感染的系统位于网络防火墙之后时,攻击者可能会试图在受感染的系统上打开远程反向外壳,以便更轻松地发出命令,因为防火墙可能会阻止来自网络外部的直接尝试来联系受感染的系统。但是,检测反向外壳可能很困难,缓慢且不可靠。本公开讨论了基于分析诸如STDIN,STDOUT和STDERR的数据流的重定向来检测反向壳的方法。

著录项

  • 公开/公告号US2018077201A1

    专利类型

  • 公开/公告日2018-03-15

    原文格式PDF

  • 申请/专利权人 PAYPAL INC.;

    申请/专利号US201615267037

  • 发明设计人 SHLOMI BOUTNARU;

    申请日2016-09-15

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 13:04:01

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号