×

Decoy network technology with automatic signature generation for intrusion detection and intrusion prevention systems

  • US 8,656,493 B2
  • Filed: 02/05/2013
  • Issued: 02/18/2014
  • Est. Priority Date: 05/22/2006
  • Status: Active Grant
First Claim
Patent Images

1. A method for protecting a computer network with automatic signature generation for intrusion prevention systems, comprising:

  • providing a network connection on a computer network to a computer system that includes an operating system hosted on a monitoring module that includes a kernel driver coupled with said operating system and hidden from an attacker by preventing the kernel driver from registering with said operating system;

    monitoring a network attack on said computer network using the monitoring module, wherein said network attack comprises attack-identifying information that is based on activities on said operating system;

    processing said attack-identifying information using a processing module connected to said computer system through a second network connection to identify said network attack and generate an attack signature using the attack-identifying information that is based on activities on said operating system; and

    applying said attack signature generated using the attack-identifying information that is based on activities on said operating system to a library of signatures contained in an intrusion prevention system to control access to said computer network.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×