首页> 外国专利> Augmented data collection from suspected attackers of a computer network

Augmented data collection from suspected attackers of a computer network

机译:从计算机网络的疑似攻击者的增强数据收集

摘要

Technology for isolating suspicious activity on a plurality of servers for the purpose of mitigating damage (for example, unauthorized access to server data) to a network of computers and eliciting information about any suspicious clients involved in the suspicious activity. A suspicious client is identified, isolated, and permitted to continue interacting with the computer network to elicit information about the activity (for example, the identify of a suspicious client). Suspicious activity is defined by network administrators and determined using conventional techniques. The suspicious activity is isolated to prevent the suspicious client(s) from unauthorized and/or harmful actions on the network. The suspicious client(s) are permitted to resume network requests, in isolation, to covertly elicit information about the suspicious activity. Any data collected about the suspicious activity and/or suspicious client(s) are output, during and/or after the suspicious client(s) have disconnected from the network, for analysis.
机译:用于在多个服务器上隔离可疑活动的技术,以便减轻损坏(例如,未经授权访问服务器数据)到计算机网络,并引出关于可疑活动所涉及的任何可疑客户端的信息。识别,隔离和允许可疑客户端,继续与计算机网络交互以引出有关活动的信息(例如,识别可疑客户端)。可疑活动由网络管理员定义并使用传统技术确定。孤立可疑活动以防止可疑的客户从网络上未经授权和/或有害的行动。可疑客户端允许孤立地恢复网络请求,以隐瞒有关可疑活动的信息。关于可疑活动和/或可疑客户端收集的任何数据都是输出的,期间和/或在可疑客户端已与网络中断开连接,以进行分析。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号