KR101737726B1 - 네트워크 트래픽에서의 불일치들을 검출하기 위한 하드웨어 자원들의 사용에 의한 루트킷 검출 - Google Patents
네트워크 트래픽에서의 불일치들을 검출하기 위한 하드웨어 자원들의 사용에 의한 루트킷 검출 Download PDFInfo
- Publication number
- KR101737726B1 KR101737726B1 KR1020157033703A KR20157033703A KR101737726B1 KR 101737726 B1 KR101737726 B1 KR 101737726B1 KR 1020157033703 A KR1020157033703 A KR 1020157033703A KR 20157033703 A KR20157033703 A KR 20157033703A KR 101737726 B1 KR101737726 B1 KR 101737726B1
- Authority
- KR
- South Korea
- Prior art keywords
- monitor data
- programmable device
- environment
- operating system
- malware
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/552—Detecting local intrusion or implementing counter-measures involving long-term monitoring or reporting
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/554—Detecting local intrusion or implementing counter-measures involving event detection and direct action
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/556—Detecting local intrusion or implementing counter-measures involving covert channels, i.e. data leakage between processes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/12—Applying verification of the received information
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/145—Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/16—Implementing security features at a particular protocol layer
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- General Health & Medical Sciences (AREA)
- Virology (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
도 2는 하나의 실시예에 따라 보안 환경 및 비보안(insecure) 환경에서 모니터링되는 네트워크 트래픽 사이의 차들을 도시하는 차트이다.
도 3은 하나의 실시예에 따라 루트킷들을 검출하기 위한 컴퓨터 시스템을 도시하는 블록도이다.
도 4는 하나의 실시예에 따라 멀웨어를 검출하기 위한 기술을 도시하는 흐름도이다.
도 5는 다른 실시예에 따라 멀웨어를 검출하기 위한 기술을 도시하는 흐름도이다.
도 6은 또 다른 실시예에 따라 멀웨어를 검출하기 위한 기술을 도시하는 흐름도이다.
Claims (25)
- 명령어가 저장되어 있는 비일시적 컴퓨터 판독 가능 매체(non-transitory computer readable medium)로서,
상기 명령어는, 실행될 때 프로그램 가능 디바이스(programmable device)로 하여금,
상기 프로그램 가능 디바이스의 운영체제에 의해 제어되는 환경에서 상기 프로그램 가능 디바이스의 네트워크 트래픽(network traffic)을 모니터링하여, 제 1 모니터 데이터를 생성하게 하고,
상기 운영체제에 의해 제어되지 않는, 상기 프로그램 가능 디바이스의 암호로 보안된 하드웨어 환경(cryptographically secured hardware environment)에서 상기 프로그램 가능 디바이스의 네트워크 트래픽을 모니터링하여, 제 2 모니터 데이터를 생성하게 하고,
상기 제 1 모니터 데이터를 상기 제 2 모니터 데이터와 비교하게 하고,
상기 제 1 모니터 데이터가 상기 제 2 모니터 데이터와 동일한지 여부를 표시하게 하는 명령어를 포함하는
컴퓨터 판독 가능 매체.
- 제 1 항에 있어서,
실행될 때 상기 프로그램 가능 디바이스로 하여금 상기 제 1 모니터 데이터를 상기 제 2 모니터 데이터와 비교하게 하는 상기 명령어는, 실행될 때 상기 프로그램 가능 디바이스로 하여금,
상기 제 1 모니터 데이터를 상기 운영체제에 의해 제어되는 환경으로부터 상기 암호로 보안된 하드웨어 환경으로 송신하게 하고,
상기 제 1 모니터 데이터를 상기 암호로 보안된 하드웨어 환경에서 상기 제 2 모니터 데이터와 비교하게 하는 명령어를 포함하는
컴퓨터 판독 가능 매체.
- 제 1 항에 있어서,
실행될 때 상기 프로그램 가능 디바이스로 하여금 상기 제 1 모니터 데이터를 상기 제 2 모니터 데이터와 비교하게 하는 상기 명령어는, 실행될 때 상기 프로그램 가능 디바이스로 하여금,
상기 제 2 모니터 데이터를 상기 암호로 보안된 하드웨어 환경으로부터 상기 운영체제에 의해 제어되는 환경으로 송신하게 하고,
상기 제 1 모니터 데이터를 상기 운영체제에 의해 제어되는 환경에서 상기 제 2 모니터 데이터와 비교하게 하는 명령어를 포함하는
컴퓨터 판독 가능 매체.
- 제 1 항에 있어서,
실행될 때 상기 프로그램 가능 디바이스로 하여금 상기 제 1 모니터 데이터를 상기 제 2 모니터 데이터와 비교하도록 하는 상기 명령어는, 실행될 때 상기 프로그램 가능 디바이스로 하여금,
상기 제 1 모니터 데이터 및 상기 제 2 모니터 데이터를 외부 설비로 송신하게 하고,
상기 제 1 모니터 데이터를 상기 외부 설비에서 상기 제 2 모니터 데이터와 비교하게 하는 명령어를 포함하는
컴퓨터 판독 가능 매체.
- 제 1 항에 있어서,
상기 저장되어 있는 명령어는, 실행될 때 상기 프로그램 가능 디바이스로 하여금,
상기 프로그램 가능 디바이스 상에 멀웨어의 존재를 나타내는 경보를 발생시키게 하는 명령어를 더 포함하는
컴퓨터 판독 가능 매체.
- 제 1 항에 있어서,
실행될 때 상기 프로그램 가능 디바이스로 하여금 상기 제 1 모니터 데이터를 상기 제 2 모니터 데이터와 비교하도록 하는 상기 명령어는, 실행될 때 상기 프로그램 가능 디바이스로 하여금,
배제 목록에 의해 상기 비교를 제한하게 하는 명령어를 포함하는
컴퓨터 판독 가능 매체.
- 제 1 항에 있어서,
상기 저장되어 있는 명령어는, 실행될 때 상기 프로그램 가능 디바이스로 하여금, 상기 운영체제의 환경 또는 상기 암호로 보안된 하드웨어 환경에서 멀웨어 경보를 발생시키게 하는 명령어를 더 포함하는
컴퓨터 판독 가능 매체.
- 제 7 항에 있어서,
실행될 때 상기 프로그램 가능 디바이스로 하여금 상기 운영체제의 환경 또는 상기 암호로 보안된 하드웨어 환경에서 멀웨어 경보를 발생시키게 하는 상기 명령어는, 네트워크를 통해 상기 멀웨어 경보를 송신하기 위한 명령어를 포함하는
컴퓨터 판독 가능 매체.
- 제 1 항에 있어서,
상기 저장되어 있는 명령어는, 실행될 때 상기 프로그램 가능 디바이스로 하여금,
상기 프로그램 가능 디바이스를 격리하게 하는 명령어를 더 포함하는
컴퓨터 판독 가능 매체.
- 멀웨어를 검출하는 방법으로서,
프로그램 가능 디바이스에 대한 운영체제에 의해 제어되는 환경에서 상기 프로그램 가능 디바이스의 네트워크 트래픽을 모니터링하여, 제 1 모니터 데이터를 생성하는 단계와,
상기 운영체제에 의해 제어되지 않는 암호로 보안된 하드웨어 환경(cryptographically secured hardware environment)에서 상기 프로그램 가능 디바이스의 네트워크 트래픽을 모니터링하여, 제 2 모니터 데이터를 생성하는 단계와,
상기 제 1 모니터 데이터를 상기 제 2 모니터 데이터와 비교하는 단계와,
상기 제 1 모니터 데이터가 상기 제 2 모니터 데이터와 일치하지 않으면 멀웨어의 존재를 표시하는 단계를 포함하는
멀웨어를 검출하는 방법.
- 제 10 항에 있어서,
상기 프로그램 가능 디바이스에 대한 운영체제에 의해 제어되는 환경에서 상기 프로그램 가능 디바이스의 네트워크 트래픽을 모니터링하는 것은,
상기 운영체제에 의한 제어 하에 실행하는 침입 검출 시스템에서 네트워크 트래픽을 모니터링하는 것을 포함하는
멀웨어를 검출하는 방법.
- 제 10 항에 있어서,
상기 프로그램 가능 디바이스의 가동 시에 상기 암호로 보안된 하드웨어 환경에서 실행하기 위한 펌웨어를 로딩(loading)하는 단계를 더 포함하는
멀웨어를 검출하는 방법.
- 제 10 항에 있어서,
상기 제 1 모니터 데이터를 상기 제 2 모니터 데이터와 비교하는 단계는,
상기 제 1 모니터 데이터를 상기 암호로 보안된 하드웨어 환경에 송신하는 단계와,
상기 제 1 모니터 데이터를 상기 암호로 보안된 하드웨어 환경에서 상기 제 2 모니터 데이터와 비교하는 단계를 포함하는
멀웨어를 검출하는 방법.
- 제 10 항에 있어서,
멀웨어의 존재의 상기 표시에 응답하여 상기 프로그램 가능 디바이스를 격리하는 단계를 더 포함하는
멀웨어를 검출하는 방법.
- 제 10 항에 있어서,
상기 제 1 모니터 데이터를 상기 제 2 모니터 데이터와 비교하는 단계는,
상기 제 2 모니터 데이터를 상기 운영체제에 의한 제어 하에 실행하는 침입 검출 시스템에 송신하는 단계와,
상기 제 1 모니터 데이터를 침입 검출 시스템에 의해 상기 제 2 모니터 데이터와 비교하는 단계를 포함하는
멀웨어를 검출하는 방법.
- 제 10 항에 있어서,
상기 제 1 모니터 데이터를 상기 제 2 모니터 데이터와 비교하는 단계는,
상기 제 2 모니터 데이터와의 비교를 위해 상기 제 1 모니터 데이터를 상기 암호로 보안된 하드웨어 환경으로부터 외부 설비로 송신하는 단계와,
상기 제 1 모니터 데이터와의 비교를 위해 상기 제 2 모니터 데이터를 침입 검출 시스템으로부터 상기 외부 설비로 송신하는 단계를 포함하는
멀웨어를 검출하는 방법. - 제 16 항에 있어서,
상기 멀웨어의 존재를 표시하는 단계는,
상기 외부 설비에 의해 생성되는 경보를 수신하는 단계를 포함하는
멀웨어를 검출하는 방법.
- 제 10 항에 있어서,
상기 멀웨어의 존재를 표시하는 단계는,
상기 멀웨어의 존재를 표시하는 경보를 디스플레이하는 단계를 포함하는
멀웨어를 검출하는 방법.
- 제 10 항에 있어서,
상기 제 1 모니터 데이터 및 상기 제 2 모니터 데이터는 네트워크 플로우 데이터(network flow data)를 포함하는
멀웨어를 검출하는 방법.
- 프로그램 가능 디바이스로서,
프로세서와,
상기 프로세서에 의해 실행될 때 상기 프로세서를 제어하고 상기 프로세서 상에서 실행되는 다른 소프트웨어에 대한 운영체제 환경을 제공하는 명령어를 포함하는 운영체제와,
침입 검출 소프트웨어―상기 침입 검출 소프트웨어는, 상기 운영체제 환경에서 상기 프로세서에 의해 실행될 때 상기 프로세서로 하여금, 상기 프로그램 가능 디바이스의 네트워크 트래픽을 제 1 모니터 데이터로서 기록하도록 하는 명령어를 포함함―와,
상기 프로그램 가능 디바이스의 네트워크 트래픽을 제 2 모니터 데이터로서 기록하도록 구성되는 암호로 보안된 하드웨어 환경(cryptographically secured hardware environment)―상기 암호로 보안된 하드웨어 환경은 상기 운영체제 환경의 외부에 있음―을 포함하되,
상기 프로그램 가능 디바이스는,
상기 제 1 모니터 데이터를 상기 제 2 모니터 데이터와 비교하고,
상기 제 1 모니터 데이터가 상기 제 2 모니터 데이터와 동일하지 않으면 경보를 생성하도록 구성되는
프로그램 가능 디바이스.
- 제 20 항에 있어서,
상기 제 1 모니터 데이터 및 상기 제 2 모니터 데이터는 네트워크 플로우 데이터를 포함하는
프로그램 가능 디바이스.
- 제 20 항에 있어서,
침입 검출 시스템은, 상기 운영체제 환경에서 상기 프로세서에 의해 실행될 때 상기 프로세서로 하여금,
상기 암호로 보안된 하드웨어 환경으로부터 상기 제 2 모니터 데이터를 요청하게 하고,
상기 제 1 모니터 데이터를 상기 운영체제 환경에서 상기 침입 검출 시스템에 의해 상기 제 2 모니터 데이터와 비교하게 하는 명령어를 더 포함하는
프로그램 가능 디바이스.
- 제 20 항에 있어서,
상기 침입 검출 소프트웨어는 상기 프로세서로 하여금 네트워크 트래픽을 계속해서 기록하게 하도록 구성되는
프로그램 가능 디바이스.
- 제 20 항에 있어서,
상기 프로그램 가능 디바이스는 상기 제 1 모니터 데이터 및 상기 제 2 모니터 데이터를 주기적으로 비교하도록 구성되는
프로그램 가능 디바이스.
- 삭제
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US13/931,705 | 2013-06-28 | ||
| US13/931,705 US9197654B2 (en) | 2013-06-28 | 2013-06-28 | Rootkit detection by using HW resources to detect inconsistencies in network traffic |
| PCT/US2014/044227 WO2014210246A1 (en) | 2013-06-28 | 2014-06-26 | Rootkit detection by using hardware resources to detect inconsistencies in network traffic |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| KR20160004349A KR20160004349A (ko) | 2016-01-12 |
| KR101737726B1 true KR101737726B1 (ko) | 2017-05-29 |
Family
ID=52117087
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| KR1020157033703A Active KR101737726B1 (ko) | 2013-06-28 | 2014-06-26 | 네트워크 트래픽에서의 불일치들을 검출하기 위한 하드웨어 자원들의 사용에 의한 루트킷 검출 |
Country Status (5)
| Country | Link |
|---|---|
| US (2) | US9197654B2 (ko) |
| EP (1) | EP3014813B1 (ko) |
| KR (1) | KR101737726B1 (ko) |
| CN (1) | CN105409164B (ko) |
| WO (1) | WO2014210246A1 (ko) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20190109203A (ko) | 2018-03-15 | 2019-09-25 | 삼성에스디에스 주식회사 | 컨테이너 루트킷 탐지 장치 및 방법 |
Families Citing this family (75)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9043903B2 (en) | 2012-06-08 | 2015-05-26 | Crowdstrike, Inc. | Kernel-level security agent |
| US9292881B2 (en) | 2012-06-29 | 2016-03-22 | Crowdstrike, Inc. | Social sharing of security information in a group |
| US9286047B1 (en) | 2013-02-13 | 2016-03-15 | Cisco Technology, Inc. | Deployment and upgrade of network devices in a network environment |
| FR3012643B1 (fr) * | 2013-10-28 | 2017-03-17 | Oberthur Technologies | Systeme de detection d'intrusion dans un dispositif comprenant un premier systeme d'exploitation et un deuxieme systeme d'exploitation |
| US10289405B2 (en) | 2014-03-20 | 2019-05-14 | Crowdstrike, Inc. | Integrity assurance and rebootless updating during runtime |
| US10659478B2 (en) * | 2014-07-21 | 2020-05-19 | David Paul Heilig | Identifying stealth packets in network communications through use of packet headers |
| US9654498B2 (en) * | 2015-05-12 | 2017-05-16 | Assured Information Security, Inc. | Detecting deviation from a data packet send-protocol in a computer system |
| US10374904B2 (en) | 2015-05-15 | 2019-08-06 | Cisco Technology, Inc. | Diagnostic network visualization |
| US9800497B2 (en) | 2015-05-27 | 2017-10-24 | Cisco Technology, Inc. | Operations, administration and management (OAM) in overlay data center environments |
| US10033766B2 (en) | 2015-06-05 | 2018-07-24 | Cisco Technology, Inc. | Policy-driven compliance |
| US10536357B2 (en) | 2015-06-05 | 2020-01-14 | Cisco Technology, Inc. | Late data detection in data center |
| US9967158B2 (en) | 2015-06-05 | 2018-05-08 | Cisco Technology, Inc. | Interactive hierarchical network chord diagram for application dependency mapping |
| US10142353B2 (en) | 2015-06-05 | 2018-11-27 | Cisco Technology, Inc. | System for monitoring and managing datacenters |
| US10089099B2 (en) | 2015-06-05 | 2018-10-02 | Cisco Technology, Inc. | Automatic software upgrade |
| US10339316B2 (en) | 2015-07-28 | 2019-07-02 | Crowdstrike, Inc. | Integrity assurance through early loading in the boot phase |
| DE102015214993A1 (de) * | 2015-08-06 | 2017-02-09 | Siemens Aktiengesellschaft | Verfahren und Anordnung zur rückwirkungsfreien Übertragung von Daten zwischen Netzwerken |
| US10291496B1 (en) * | 2015-09-29 | 2019-05-14 | Juniper Networks, Inc. | Packet capture based capturing of protocol layer state information |
| US10623424B2 (en) * | 2016-02-17 | 2020-04-14 | Ziften Technologies, Inc. | Supplementing network flow analysis with endpoint information |
| US10705829B2 (en) * | 2016-03-30 | 2020-07-07 | International Business Machines Corporation | Software discovery using exclusion |
| US10528739B2 (en) | 2016-04-20 | 2020-01-07 | Sophos Limited | Boot security |
| US10931629B2 (en) | 2016-05-27 | 2021-02-23 | Cisco Technology, Inc. | Techniques for managing software defined networking controller in-band communications in a data center network |
| US10171357B2 (en) | 2016-05-27 | 2019-01-01 | Cisco Technology, Inc. | Techniques for managing software defined networking controller in-band communications in a data center network |
| US10289438B2 (en) | 2016-06-16 | 2019-05-14 | Cisco Technology, Inc. | Techniques for coordination of application components deployed on distributed virtual machines |
| US10187414B2 (en) | 2016-07-20 | 2019-01-22 | Cisco Technology, Inc. | Differential malware detection using network and endpoint sensors |
| US10708183B2 (en) | 2016-07-21 | 2020-07-07 | Cisco Technology, Inc. | System and method of providing segment routing as a service |
| CN107689975B (zh) * | 2016-08-05 | 2020-07-31 | 腾讯科技(深圳)有限公司 | 一种基于云计算的计算机病毒识别方法及系统 |
| US10698672B1 (en) * | 2016-10-07 | 2020-06-30 | Wells Fargo Bank, N.A. | Universal installer and uninstaller |
| US10972388B2 (en) | 2016-11-22 | 2021-04-06 | Cisco Technology, Inc. | Federated microburst detection |
| TWI617940B (zh) * | 2016-12-01 | 2018-03-11 | 財團法人資訊工業策進會 | 資料保護方法與資料保護系統 |
| US10387228B2 (en) | 2017-02-21 | 2019-08-20 | Crowdstrike, Inc. | Symmetric bridge component for communications between kernel mode and user mode |
| CN106980574A (zh) * | 2017-03-10 | 2017-07-25 | 武汉融卡智能信息科技有限公司 | 一种tee下全功能测试系统及测试方法 |
| US10476673B2 (en) | 2017-03-22 | 2019-11-12 | Extrahop Networks, Inc. | Managing session secrets for continuous packet capture systems |
| US10708152B2 (en) | 2017-03-23 | 2020-07-07 | Cisco Technology, Inc. | Predicting application and network performance |
| US10523512B2 (en) | 2017-03-24 | 2019-12-31 | Cisco Technology, Inc. | Network agent for generating platform specific network policies |
| US10594560B2 (en) | 2017-03-27 | 2020-03-17 | Cisco Technology, Inc. | Intent driven network policy platform |
| US10250446B2 (en) | 2017-03-27 | 2019-04-02 | Cisco Technology, Inc. | Distributed policy store |
| US10764141B2 (en) | 2017-03-27 | 2020-09-01 | Cisco Technology, Inc. | Network agent for reporting to a network policy system |
| US10873794B2 (en) | 2017-03-28 | 2020-12-22 | Cisco Technology, Inc. | Flowlet resolution for application performance monitoring and management |
| US20190026460A1 (en) * | 2017-07-19 | 2019-01-24 | Cisco Technology, Inc. | Dynamic creation of isolated scrubbing environments |
| US10680887B2 (en) | 2017-07-21 | 2020-06-09 | Cisco Technology, Inc. | Remote device status audit and recovery |
| US10554501B2 (en) | 2017-10-23 | 2020-02-04 | Cisco Technology, Inc. | Network migration assistant |
| US10523541B2 (en) | 2017-10-25 | 2019-12-31 | Cisco Technology, Inc. | Federated network and application data analytics platform |
| US9967292B1 (en) | 2017-10-25 | 2018-05-08 | Extrahop Networks, Inc. | Inline secret sharing |
| US10594542B2 (en) | 2017-10-27 | 2020-03-17 | Cisco Technology, Inc. | System and method for network root cause analysis |
| US11233821B2 (en) | 2018-01-04 | 2022-01-25 | Cisco Technology, Inc. | Network intrusion counter-intelligence |
| US11765046B1 (en) | 2018-01-11 | 2023-09-19 | Cisco Technology, Inc. | Endpoint cluster assignment and query generation |
| US10873593B2 (en) | 2018-01-25 | 2020-12-22 | Cisco Technology, Inc. | Mechanism for identifying differences between network snapshots |
| US10798015B2 (en) | 2018-01-25 | 2020-10-06 | Cisco Technology, Inc. | Discovery of middleboxes using traffic flow stitching |
| US10917438B2 (en) | 2018-01-25 | 2021-02-09 | Cisco Technology, Inc. | Secure publishing for policy updates |
| US10999149B2 (en) | 2018-01-25 | 2021-05-04 | Cisco Technology, Inc. | Automatic configuration discovery based on traffic flow data |
| US10826803B2 (en) | 2018-01-25 | 2020-11-03 | Cisco Technology, Inc. | Mechanism for facilitating efficient policy updates |
| US10574575B2 (en) | 2018-01-25 | 2020-02-25 | Cisco Technology, Inc. | Network flow stitching using middle box flow stitching |
| US11128700B2 (en) | 2018-01-26 | 2021-09-21 | Cisco Technology, Inc. | Load balancing configuration based on traffic flow telemetry |
| US10389574B1 (en) | 2018-02-07 | 2019-08-20 | Extrahop Networks, Inc. | Ranking alerts based on network monitoring |
| US10270794B1 (en) * | 2018-02-09 | 2019-04-23 | Extrahop Networks, Inc. | Detection of denial of service attacks |
| RU2706894C1 (ru) * | 2018-06-29 | 2019-11-21 | Акционерное общество "Лаборатория Касперского" | Система и способ анализа содержимого зашифрованного сетевого трафика |
| US10411978B1 (en) | 2018-08-09 | 2019-09-10 | Extrahop Networks, Inc. | Correlating causes and effects associated with network activity |
| US10965702B2 (en) * | 2019-05-28 | 2021-03-30 | Extrahop Networks, Inc. | Detecting injection attacks using passive network monitoring |
| US11165814B2 (en) | 2019-07-29 | 2021-11-02 | Extrahop Networks, Inc. | Modifying triage information based on network monitoring |
| US11388072B2 (en) | 2019-08-05 | 2022-07-12 | Extrahop Networks, Inc. | Correlating network traffic that crosses opaque endpoints |
| US10742530B1 (en) | 2019-08-05 | 2020-08-11 | Extrahop Networks, Inc. | Correlating network traffic that crosses opaque endpoints |
| US10742677B1 (en) | 2019-09-04 | 2020-08-11 | Extrahop Networks, Inc. | Automatic determination of user roles and asset types based on network monitoring |
| US11165823B2 (en) | 2019-12-17 | 2021-11-02 | Extrahop Networks, Inc. | Automated preemptive polymorphic deception |
| WO2022066910A1 (en) | 2020-09-23 | 2022-03-31 | Extrahop Networks, Inc. | Monitoring encrypted network traffic |
| US11463466B2 (en) | 2020-09-23 | 2022-10-04 | Extrahop Networks, Inc. | Monitoring encrypted network traffic |
| US11816205B2 (en) * | 2020-11-30 | 2023-11-14 | Red Hat, Inc. | Detecting and handling attacks on processes executing within a trusted execution environment |
| US11588835B2 (en) | 2021-05-18 | 2023-02-21 | Bank Of America Corporation | Dynamic network security monitoring system |
| US11792213B2 (en) | 2021-05-18 | 2023-10-17 | Bank Of America Corporation | Temporal-based anomaly detection for network security |
| US11799879B2 (en) | 2021-05-18 | 2023-10-24 | Bank Of America Corporation | Real-time anomaly detection for network security |
| US11349861B1 (en) | 2021-06-18 | 2022-05-31 | Extrahop Networks, Inc. | Identifying network entities based on beaconing activity |
| US11296967B1 (en) | 2021-09-23 | 2022-04-05 | Extrahop Networks, Inc. | Combining passive network analysis and active probing |
| US11843606B2 (en) | 2022-03-30 | 2023-12-12 | Extrahop Networks, Inc. | Detecting abnormal data access based on data similarity |
| US20240095367A1 (en) * | 2022-05-09 | 2024-03-21 | Amazon Technologies, Inc. | Verifying encryption of data traffic |
| CN115623531B (zh) * | 2022-11-29 | 2023-03-31 | 浙大城市学院 | 利用无线射频信号的隐藏监控设备发现和定位方法 |
| US12483384B1 (en) | 2025-04-16 | 2025-11-25 | Extrahop Networks, Inc. | Resynchronizing encrypted network traffic |
Family Cites Families (16)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9009084B2 (en) * | 2002-10-21 | 2015-04-14 | Rockwell Automation Technologies, Inc. | System and methodology providing automation security analysis and network intrusion protection in an industrial environment |
| US7565690B2 (en) * | 2003-08-04 | 2009-07-21 | At&T Intellectual Property I, L.P. | Intrusion detection |
| US20050229250A1 (en) * | 2004-02-26 | 2005-10-13 | Ring Sandra E | Methodology, system, computer readable medium, and product providing a security software suite for handling operating system exploitations |
| US7841006B2 (en) * | 2005-10-05 | 2010-11-23 | Computer Associates Think, Inc. | Discovery of kernel rootkits by detecting hidden information |
| US7665136B1 (en) * | 2005-11-09 | 2010-02-16 | Symantec Corporation | Method and apparatus for detecting hidden network communication channels of rootkit tools |
| US8291473B2 (en) * | 2007-01-10 | 2012-10-16 | International Business Machines Corporation | Methods, systems, and computer program products for modeling a secure production network |
| US7765374B2 (en) * | 2007-01-25 | 2010-07-27 | Microsoft Corporation | Protecting operating-system resources |
| US8079030B1 (en) * | 2007-03-13 | 2011-12-13 | Symantec Corporation | Detecting stealth network communications |
| US8104088B2 (en) * | 2007-05-11 | 2012-01-24 | Microsoft Corporation | Trusted operating environment for malware detection |
| US20100067390A1 (en) * | 2008-05-21 | 2010-03-18 | Luis Filipe Pereira Valente | System and method for discovery of network entities |
| US20100162399A1 (en) * | 2008-12-18 | 2010-06-24 | At&T Intellectual Property I, L.P. | Methods, apparatus, and computer program products that monitor and protect home and small office networks from botnet and malware activity |
| US20130247182A1 (en) * | 2009-04-21 | 2013-09-19 | Seagen James Levites | System, method, and computer program product for identifying hidden or modified data objects |
| US8443449B1 (en) * | 2009-11-09 | 2013-05-14 | Trend Micro, Inc. | Silent detection of malware and feedback over a network |
| FI20096394A0 (fi) * | 2009-12-23 | 2009-12-23 | Valtion Teknillinen | Tunkeutumisen havaitseminen viestintäverkoissa |
| US20120102568A1 (en) * | 2010-10-26 | 2012-04-26 | Mcafee, Inc. | System and method for malware alerting based on analysis of historical network and process activity |
| US8549648B2 (en) * | 2011-03-29 | 2013-10-01 | Mcafee, Inc. | Systems and methods for identifying hidden processes |
-
2013
- 2013-06-28 US US13/931,705 patent/US9197654B2/en active Active
-
2014
- 2014-06-26 KR KR1020157033703A patent/KR101737726B1/ko active Active
- 2014-06-26 WO PCT/US2014/044227 patent/WO2014210246A1/en not_active Ceased
- 2014-06-26 EP EP14817920.3A patent/EP3014813B1/en active Active
- 2014-06-26 CN CN201480030983.1A patent/CN105409164B/zh active Active
-
2015
- 2015-11-02 US US14/930,058 patent/US9680849B2/en active Active
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR20190109203A (ko) | 2018-03-15 | 2019-09-25 | 삼성에스디에스 주식회사 | 컨테이너 루트킷 탐지 장치 및 방법 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN105409164B (zh) | 2020-03-31 |
| EP3014813A4 (en) | 2017-03-01 |
| CN105409164A (zh) | 2016-03-16 |
| EP3014813A1 (en) | 2016-05-04 |
| US9680849B2 (en) | 2017-06-13 |
| EP3014813B1 (en) | 2020-03-25 |
| US20150007316A1 (en) | 2015-01-01 |
| US9197654B2 (en) | 2015-11-24 |
| US20160173512A1 (en) | 2016-06-16 |
| WO2014210246A1 (en) | 2014-12-31 |
| KR20160004349A (ko) | 2016-01-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| KR101737726B1 (ko) | 네트워크 트래픽에서의 불일치들을 검출하기 위한 하드웨어 자원들의 사용에 의한 루트킷 검출 | |
| JP7046111B2 (ja) | マルウェアのランタイム中の自動検出 | |
| US10454950B1 (en) | Centralized aggregation technique for detecting lateral movement of stealthy cyber-attacks | |
| US9954872B2 (en) | System and method for identifying unauthorized activities on a computer system using a data structure model | |
| US9794270B2 (en) | Data security and integrity by remote attestation | |
| US10587647B1 (en) | Technique for malware detection capability comparison of network security devices | |
| US20190347418A1 (en) | System and method for protection against ransomware attacks | |
| US10142343B2 (en) | Unauthorized access detecting system and unauthorized access detecting method | |
| US9690598B2 (en) | Remotely establishing device platform integrity | |
| CN113411295A (zh) | 基于角色的访问控制态势感知防御方法及系统 | |
| CN113660222A (zh) | 基于强制访问控制的态势感知防御方法及系统 | |
| Wang et al. | USBIPS framework: protecting hosts from malicious USB peripherals | |
| Malik et al. | Multi pronged approach for ransomware analysis | |
| TWI711939B (zh) | 用於惡意程式碼檢測之系統及方法 | |
| Sparks et al. | A chipset level network backdoor: bypassing host-based firewall & ids | |
| Kakareka | Detecting system intrusions | |
| Agarwal et al. | Anti-forensic= suspicious: Detection of stealthy malware that hides its network traffic | |
| GB2574468A (en) | Detecting a remote exploitation attack | |
| IL257134A (en) | Systems and methods for multi-layer security of a communication network | |
| CN103749001B (en) | The self-protection GU Generic Unit of Inner Network Security Monitor System | |
| Farley et al. | Roving bugnet: distributed surveillance threat and mitigation | |
| Alsadi et al. | Contemporary IoT Security Trends | |
| Ahmad | Advancing Intrusion Detection and Prevention Systems through the Use of Computer Virtualization |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| A201 | Request for examination | ||
| E13-X000 | Pre-grant limitation requested |
St.27 status event code: A-2-3-E10-E13-lim-X000 |
|
| P11-X000 | Amendment of application requested |
St.27 status event code: A-2-2-P10-P11-nap-X000 |
|
| P13-X000 | Application amended |
St.27 status event code: A-2-2-P10-P13-nap-X000 |
|
| PA0105 | International application |
St.27 status event code: A-0-1-A10-A15-nap-PA0105 |
|
| PA0201 | Request for examination |
St.27 status event code: A-1-2-D10-D11-exm-PA0201 |
|
| PG1501 | Laying open of application |
St.27 status event code: A-1-1-Q10-Q12-nap-PG1501 |
|
| E902 | Notification of reason for refusal | ||
| PE0902 | Notice of grounds for rejection |
St.27 status event code: A-1-2-D10-D21-exm-PE0902 |
|
| P11-X000 | Amendment of application requested |
St.27 status event code: A-2-2-P10-P11-nap-X000 |
|
| P13-X000 | Application amended |
St.27 status event code: A-2-2-P10-P13-nap-X000 |
|
| E701 | Decision to grant or registration of patent right | ||
| PE0701 | Decision of registration |
St.27 status event code: A-1-2-D10-D22-exm-PE0701 |
|
| GRNT | Written decision to grant | ||
| PR0701 | Registration of establishment |
St.27 status event code: A-2-4-F10-F11-exm-PR0701 |
|
| PR1002 | Payment of registration fee |
St.27 status event code: A-2-2-U10-U12-oth-PR1002 Fee payment year number: 1 |
|
| PG1601 | Publication of registration |
St.27 status event code: A-4-4-Q10-Q13-nap-PG1601 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| P22-X000 | Classification modified |
St.27 status event code: A-4-4-P10-P22-nap-X000 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| FPAY | Annual fee payment |
Payment date: 20200417 Year of fee payment: 4 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 4 |
|
| FPAY | Annual fee payment |
Payment date: 20210415 Year of fee payment: 5 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 5 |
|
| P22-X000 | Classification modified |
St.27 status event code: A-4-4-P10-P22-nap-X000 |
|
| FPAY | Annual fee payment |
Payment date: 20220329 Year of fee payment: 6 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 6 |
|
| R18-X000 | Changes to party contact information recorded |
St.27 status event code: A-5-5-R10-R18-oth-X000 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 7 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 8 |
|
| PR1001 | Payment of annual fee |
St.27 status event code: A-4-4-U10-U11-oth-PR1001 Fee payment year number: 9 |
|
| U11 | Full renewal or maintenance fee paid |
Free format text: ST27 STATUS EVENT CODE: A-4-4-U10-U11-OTH-PR1001 (AS PROVIDED BY THE NATIONAL OFFICE) Year of fee payment: 9 |