首页> 外国专利> METHOD AND APPARATUS FOR COMBINING A FIREWALL AND A FORENSICS AGENT TO DETECT AND PREVENT MALICIOUS SOFTWARE ACTIVITY

METHOD AND APPARATUS FOR COMBINING A FIREWALL AND A FORENSICS AGENT TO DETECT AND PREVENT MALICIOUS SOFTWARE ACTIVITY

机译:用于组合防火墙和取证剂以检测和防止恶意软件活动的方法和装置

摘要

Methods and systems for detecting and preventing malicious software activity are presented. In one embodiment, a method is presented that includes monitoring network communications on a network. The method may also include detect a suspect network communication associated with a suspect network activity and, in response, determine an originating machine based on the suspect network activity. The method may further suspend network communications for the originating machine. A forensics software agent may then be selected based on the suspect network activity. Then, the forensics software agent may be deployed on the originating machine. After deployment, the forensics software agent may fetch computer forensics data from the originating machine. Once the computer forensics data is fetched, a response action may be selected and executed based on said computer forensics data.
机译:介绍了检测和防止恶意软件活动的方法和系统。在一个实施例中,提出了一种包括监视网络上的网络通信的方法。该方法还可以包括检测与嫌疑网络活动相关联的可疑网络通信,并且响应地,基于嫌疑网络活动确定始发机。该方法可以进一步暂停用于始发机的网络通信。然后可以基于可疑网络活动来选择取证软件代理。然后,可以在始发机上部署取证软件代理。部署后,取证软件代理可以从始发机获取计算机取证数据。一旦提取计算机取证数据,就可以基于所述计算机取证数据来选择和执行响应动作。

著录项

  • 公开/公告号US2021152585A1

    专利类型

  • 公开/公告日2021-05-20

    原文格式PDF

  • 申请/专利权人 PREEMPT SECURITY INC.;

    申请/专利号US201916689702

  • 发明设计人 EYAL KARNI;SAGI SHEINFELD;YARON ZINAR;

    申请日2019-11-20

  • 分类号H04L29/06;H04L12/24;

  • 国家 US

  • 入库时间 2022-08-24 18:45:03

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号