首页> 外国专利> Method and Apparatus for Defending Against Zero-Day Worm-Based Attacks

Method and Apparatus for Defending Against Zero-Day Worm-Based Attacks

机译:防御基于零日蠕虫的攻击的方法和设备

摘要

Honey pots are used to attract computer attacks to a virtual operating system that is a virtual instantiation of a typical deployed operational system. Honey nets are a collection of these virtual systems assembled to create a virtual network. The subject system uses a forward deployed honey net combined with a parallel monitoring system collecting data into and from the honey net, leveraging the controlled environment to identify malicious behavior and new attacks. This honey net/monitoring pair is placed ahead of the real deployed operational network and the data it uncovers is used to reconfigure network protective devices in real time to prevent zero-day based attacks from entering the real network. The forward network protection system analyzes the data gathered by the honey pots and generates signatures and new rules for protection that are coupled to both advanced perimeter network security devices and to the real network itself so that these devices can be reconfigured with threat data and new rules to prevent infected packets from entering the real network and from propagating to other machines. Note the subject system applies to both zero-day exploit-based worms and also manual attacks conducted by an individual who is leveraging novel attack methods.
机译:蜜罐用于将计算机攻击吸引到虚拟操作系统,该虚拟操作系统是典型部署的操作系统的虚拟实例。蜜网是这些虚拟系统的集合,这些虚拟系统组装在一起以创建虚拟网络。主题系统使用前向部署的蜜网与并行监视系统相结合,该并行监控系统收集与蜜网之间的数据,并利用受控环境来识别恶意行为和新攻击。此蜜网/监视对放置在实际部署的运营网络之前,其发现的数据用于实时重新配置网络保护设备,以防止基于零时差的攻击进入真实网络。前向网络保护系统分析蜜罐收集的数据,并生成签名和新的保护规则,这些签名和新规则将与高级外围网络安全设备以及实际网络本身耦合在一起,以便可以使用威胁数据和新规则重新配置这些设备以防止受感染的数据包进入真实网络并传播到其他计算机。请注意,该主题系统既适用于基于零时差漏洞的蠕虫,也适用于利用新颖攻击方法的个人进行的手动攻击。

著录项

  • 公开/公告号US2008098476A1

    专利类型

  • 公开/公告日2008-04-24

    原文格式PDF

  • 申请/专利权人 JASON M SYVERSEN;

    申请/专利号US20060632669

  • 发明设计人 JASON M SYVERSEN;

    申请日2006-03-30

  • 分类号G06F15/18;

  • 国家 US

  • 入库时间 2022-08-21 20:13:44

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号