×

SYSTEM AND METHOD OF SPOOF DETECTION

  • US 20160359709A1
  • Filed: 06/02/2016
  • Published: 12/08/2016
  • Est. Priority Date: 06/05/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • analyzing, via a first capture agent, packets processed by a first environment in a network associated with a first host to yield first data;

    analyzing, via a second capture agent, packets processed by a second environment in the network associated with a second host to yield second data, wherein the first capture agent is located within a first layer of the network and the second capture agent is located in a second layer of the network, and wherein the first layer and the second layer are different layers of the network;

    collecting the first data and the second data at a collector to yield aggregated data;

    based on the aggregated data, generating a database comprising a topological map of the network and a history of network activity associated with the first environment and the second environment to yield historical data;

    extracting network data from a packet to yield extracted network data, the extracted network data identifying a reported source of the packet;

    comparing the extracted network data with stored network data in the database to yield a comparison; and

    when the comparison indicates that the extracted network data does not match the stored network data, determining that the packet is a spoofed packet.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×