Invention Grant
- Patent Title: Detecting man-in-the-middle attacks
-
Application No.: US15204779Application Date: 2016-07-07
-
Publication No.: US10250636B2Publication Date: 2019-04-02
- Inventor: Venu Vissamsetty , Muthukumar Lakshmanan , Sreenivasa Sudheendra Penupolu , Ankur Rungta
- Applicant: Attivo Networks Inc.
- Applicant Address: US CA Fremont
- Assignee: ATTIVO NETWORKS INC
- Current Assignee: ATTIVO NETWORKS INC
- Current Assignee Address: US CA Fremont
- Agency: Stevens Law Group
- Agent David R. Stevens
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F7/04

Abstract:
MITM attacks are detected by intercepting network configuration traffic (name resolution, DHCP, ARP, ICMP, etc.) in order to obtain a description of network components. A computer system generates artificial requests for network configuration information and monitors responses. Multiple responses indicate a MITM attack. Responses that are different from previously-recorded responses also indicate a MITM attack. MITM attacks may be confirmed by transmitting fake credentials to a source of a response to a request for network configuration information. If the fake credentials are accepted or are subsequently used in an access attempt, then a MITM attack may be confirmed.
Public/Granted literature
- US20180013788A1 DETECTING MAN-IN-THE-MIDDLE ATTACKS Public/Granted day:2018-01-11
Information query