Invention Grant
- Patent Title: Apparatus and method for conducting endpoint-network-monitoring
-
Application No.: US15959037Application Date: 2018-04-20
-
Publication No.: US10762201B2Publication Date: 2020-09-01
- Inventor: Robert Julian Noeth , Ernest Gregory Ake
- Applicant: Level Effect LLC
- Applicant Address: US TX San Antonio
- Assignee: Level Effect LLC
- Current Assignee: Level Effect LLC
- Current Assignee Address: US TX San Antonio
- Agency: Pillsbury Winthrop Shaw Pittman, LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F21/55 ; G06F21/56 ; H04L29/06 ; H04L12/26 ; G06F12/14 ; H04L12/801

Abstract:
Provided is an intrusion detection technique configured to: obtain kernel-filter criteria indicative of which network traffic is to be deemed potentially malicious, determine that a network packet is resident in a networking stack, access at least part of the network packet, apply the kernel-filter criteria to the at least part of the network packet and, based on applying the kernel-filter criteria, determining that the network packet is potentially malicious, associate the network packet with an identifier of an application executing in userspace of the operating system and to which or from which the network packet is sent, and report the network packet in association with the identifier of the application to an intrusion-detection agent executing in userspace of the operating system of the host computing device, the intrusion-detection agent being different from the application to which or from which the network packet is sent.
Public/Granted literature
- US20180307833A1 APPARATUS AND METHOD FOR CONDUCTING ENDPOINT-NETWORK-MONITORING PACKET TAGGING Public/Granted day:2018-10-25
Information query