×

SYSTEM AND METHOD OF DETECTING WHETHER A SOURCE OF A PACKET FLOW TRANSMITS PACKETS WHICH BYPASS AN OPERATING SYSTEM STACK

  • US 20160359890A1
  • Filed: 06/02/2016
  • Published: 12/08/2016
  • Est. Priority Date: 06/05/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • capturing first data associated with a first packet flow originating from a first host using a first capture agent deployed at the first host to yield first flow data;

    capturing second data associated with a second packet flow originating from the first host using a second capture agent deployed at a second host to yield second flow data, wherein the first capturing agent is deployed in a first layer of a network and the second capturing agent is deployed in a second layer of the network;

    comparing the first flow data and the second flow data to yield a difference; and

    when the difference is above a threshold value, determining that the second packet flow was transmitted by a component that bypassed one of an operating stack of the first host and a packet capture agent on the first host, to yield a determination.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×