首页> 外国专利> LEVERAGING NETWORK SECURITY SCANNING TO OBTAIN ENHANCED INFORMATION REGARDING AN ATTACK CHAIN INVOLVING A DECOY FILE

LEVERAGING NETWORK SECURITY SCANNING TO OBTAIN ENHANCED INFORMATION REGARDING AN ATTACK CHAIN INVOLVING A DECOY FILE

机译:利用网络安全扫描以获得有关涉及诱饵文件的攻击链的增强信息

摘要

Systems and methods for identifying a source of an attack chain based on network security scanning events triggered by movement of a decoy file are provided. A decoy file is stored on a deception host deployed by a deception-based intrusion detection system (IDS) within a private network. The decoy file contains therein a traceable object that is detectable by network security scanning performed by multiple network security devices protecting the private network. Information regarding an attack chain associated with an access to the decoy file or a transmission of the decoy file through the one or more network security devices is received by the deception-based IDS from the one or more network security devices. The information is created responsive to detection of a security incident by the network security scanning. Finally, an Internet Protocol (IP) address of a computer system that originated the attack chain is determined.
机译:提供了用于基于由诱饵文件的移动触发的网络安全扫描事件来识别攻击链源的系统和方法。 诱饵文件存储在专用网络中的基于欺骗性的入侵检测系统(IDS)部署的欺骗主机上。 诱饵文件在其中包含可追溯的对象,该对象可通过保护专用网络的多个网络安全设备执行的网络安全扫描来检测。 关于与对诱饵文件相关联的攻击链或通过一个或多个网络安全设备的访问相关联的攻击链的信息由来自一个或多个网络安全设备的欺骗性的ID接收。 响应于网络安全扫描的安全事件的检测,创建信息。 最后,确定了源自攻击链的计算机系统的Internet协议(IP)地址。

著录项

  • 公开/公告号US2021409446A1

    专利类型

  • 公开/公告日2021-12-30

    原文格式PDF

  • 申请/专利权人 FORTINET INC.;

    申请/专利号US202016910511

  • 发明设计人 ALDO DI MATTIA;

    申请日2020-06-24

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-24 23:06:56

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号