×

Remediating computer security threats using distributed sensor computers

  • US 9,712,557 B2
  • Filed: 05/27/2015
  • Issued: 07/18/2017
  • Est. Priority Date: 11/07/2014
  • Status: Active Grant
First Claim
Patent Images

1. A data processing system comprising:

  • a sensor computer that is coupled to, co-located with, and on a same LAN segment as a compromised computer, the compromised computer comprising at least one malware item that is configured to direct unauthorized network activity toward one or more enterprise networks or enterprise computers, wherein the compromised computer is coupled to a firewall that is configured to control ingress of packets to the compromised computer and the sensor computer from a network, wherein the one or more enterprise networks or enterprise computers are coupled to the network through an enterprise firewall, and the compromised computer is logically between one or more attacker computers and the one or more enterprise networks or enterprise computers;

    a security control computer that is coupled to the sensor computer;

    one or more non-transitory data storage media in the security control computer storing security logic comprising one or more sequences of instructions which when executed cause the security control computer to perform;

    causing selecting of one or more of network messages emitted from the compromised computer and directed toward the enterprise computer, wherein the selection comprises filtering the one or more network messages emitted from the compromised computer based upon one or more ports of interest;

    causing queuing of the selected one or more of network messages in queues at the sensor computer;

    obtaining, from the sensor computer, detection data relating to the network messages that the compromised computer emits, as the compromised computer emits the network messages;

    using the detection data, identifying one or more security threats that are indicated by the network messages;

    determining a specified remediation measure to remediate one or more of the security threats;

    providing the specified remediation measure to one or more of the compromised computer, the sensor computer, the firewall, and an enterprise computer;

    causing inspecting and modifying of the queued one or more of network messages to remove one or more security threats before forwarding the queued one or more of network messages to the enterprise computer.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×