×

DETECTING ATTACKS USING PASSIVE NETWORK MONITORING

  • US 20180145995A1
  • Filed: 09/01/2017
  • Published: 05/24/2018
  • Est. Priority Date: 11/18/2016
  • Status: Active Grant
First Claim
Patent Images

1. A method for detecting one or more attacks in a network, wherein one or more processors in one or more network monitoring computers (NMCs) execute instructions to perform actions, comprising:

  • passively monitoring one or more network flows using the one or more NMCs; and

    responsive to detecting one or more file write operations based on information included in one or more packets of the one or more network flows, performing further actions, including;

    executing one or more detection rules to analyze one or more portions of the one or more packets to identify file information that is associated with the one or more file write operations;

    providing one or more metrics based on the one or more detection rules and a comparison of the one or more of the file information or the one or more file write operations; and

    responsive to one or more of the one or more metrics exceeding one or more threshold values, providing one or more reports of one or more attacks based on the one or more exceeded threshold values.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×