×

Method and device for detecting computer network intrusions

  • US 7,823,203 B2
  • Filed: 06/13/2003
  • Issued: 10/26/2010
  • Est. Priority Date: 06/17/2002
  • Status: Expired due to Fees
First Claim
Patent Images

1. A method for computer network intrusion detection on a computer network including a target server accessible by a client on the network and administered by a system administrator capable of authorizing attempts to execute software on the target server, a client on the network and a monitoring server coupled to the target server, the method comprising:

  • running on the target server a monitored latent software performing a latent software function upon successful completion, wherein the running monitored latent software comprises running a monitored command implemented using a wrapper for a system command on the target server and altering a file system of the target server to load the wrapper in a former location of the system command and relocating the system command to another location;

    receiving an attempt by the client to execute said monitored latent software on the target server while the client is connected to the target server, wherein said client is located remotely from said target server and said monitored latent software is monitored by the monitoring server that is physically separated from the target server and the client;

    determining at the monitoring server whether the client is an authorized client that is authorized to execute the monitored latent software prior to successful completion of the monitored latent software;

    successfully completing execution of the monitored latent software on the target server when the attempt to execute the monitored latent software is by said authorized client;

    sending a message to the system administrator when the attempt to execute the monitored latent software is not by an authorized client; and

    aborting the execution of the monitored latent software prior to successful completion when the attempt to execute the monitored latent software is not by an authorized client.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×