Invention Grant
- Patent Title: Detecting attacks using passive network monitoring
-
Application No.: US15694229Application Date: 2017-09-01
-
Publication No.: US10243978B2Publication Date: 2019-03-26
- Inventor: Thomas Lawrence Roeh , Samuel Kanen Clement , John Augustus Kiefer
- Applicant: ExtraHop Networks, Inc.
- Applicant Address: US WA Seattle
- Assignee: ExtraHop Networks, Inc.
- Current Assignee: ExtraHop Networks, Inc.
- Current Assignee Address: US WA Seattle
- Agency: Lowe Graham Jones PLLC
- Agent John W. Branch
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L12/861 ; H04L12/26

Abstract:
Embodiments are directed to detecting one or more attacks in a network. One or more network flows may be monitored using one or more network monitoring computers (NMCs). If one or more file write operations are detected based on information included in one or more packets of the one or more network flows, one or more detection rules may be executed to analyze one or more portions of the one or more packets to identify file information that is associated with the one or more file write operations. One or more metrics may be provided based on the one or more detection rules and one or more of the file information, the one or more file write operations, or the like. If one or more metrics exceed one or more threshold values, one or more reports of one or more attacks may be provided.
Public/Granted literature
- US20180145995A1 DETECTING ATTACKS USING PASSIVE NETWORK MONITORING Public/Granted day:2018-05-24
Information query