首页> 外国专利> Cyber-deception using network port projection

Cyber-deception using network port projection

机译:使用网络端口投影的网络欺骗

摘要

Decoy network ports and services are projected onto existing production workloads to facilitate cyber deception, without the need to modify production machines. The approach may be implemented in a production network that includes two segments. A production machine is reachable via the first segment, while a decoy machine that offers the network service expected from the production machine is reachable via the second segment. A deception router is configured in front of the two segments, and it is not visible on the link and network layers. The router inspects network traffic destined for the production machine. Based on a set of one or more conditions being met, the router determines whether to relay network packets to the production machine, or to redirect the packet to the decoy machine.
机译:诱饵网络端口和服务预计将在现有的生产工作负载上投入,以促进网络欺骗,而无需修改生产机器。该方法可以在包括两个段的生产网络中实现。通过第一段可以到达生产机器,而通过第二段可通过提供从生产机预期的网络服务提供诱饵机。欺骗路由器配置在两个段的前面,并且在链路和网络层上不可见。路由器检查用于生产机器的网络流量。基于一组或多个条件,路由器确定是否将网络数据包中继到生产机器,或将数据包重定向到诱饵机器。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号