×

System and method of detecting hidden processes by analyzing packet flows

  • US 10,623,282 B2
  • Filed: 06/02/2016
  • Issued: 04/14/2020
  • Est. Priority Date: 06/05/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • capturing first data associated with a first packet flow originating from a first host using a first capture agent deployed at the first host to yield first flow data;

    capturing second data associated with a second packet flow originating from the first host from a second capture agent deployed at a second host to yield second flow data, wherein the first capture agent is deployed at a first layer of a network and the second capture agent is deployed at a second layer of the network, wherein the first layer and the second layer are different layers;

    comparing the first flow data and the second flow data to yield a difference;

    when the difference is above a threshold value, yielding a determination, the determination including that the second packet flow includes a hidden process and the second packet flow was transmitted by a component that bypassed an operating stack of the first host; and

    taking a corrective action based on the determination, the corrective action including isolating a container, isolating a virtual machine, or isolating the first host.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×