×

Predicting and preventing an attacker's next actions in a breached network

  • US 10,097,577 B2
  • Filed: 08/22/2017
  • Issued: 10/09/2018
  • Est. Priority Date: 06/08/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method for cyber security for a network of resources, wherein access to the resources via network connections that extend outside the network is governed by a firewall, the method comprising:

  • detecting, by a management server, a breach by an attacker of a resource within a network of resources;

    predicting, by the management server, the attacker'"'"'s target network subnet, based on network connections created by the attacker during the detected breach;

    isolating, by the management server, the predicted attacker'"'"'s target network subnet in response to said predicting the attacker'"'"'s target network subnet;

    predicting, by the management server, data leakage paths from inside the network to outside the network, based on an outbound network connection opened by the attacker and detected by the management server, during the breach; and

    creating, by the management server, firewall rules to re-direct the outbound network connection opened by the attacker to a resource within the network, in response to said predicting the data leakage paths, wherein the re-directed outbound network connection to a resource within the network appears to the attacker to be the attacker'"'"'s intended outbound network connection to the attacker'"'"'s intended destination outside the network.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×