Patent classifications
H04L2463/146
METHOD AND SYSTEM FOR TRACKING MACHINES ON A NETWORK USING FUZZY GUID TECHNOLOGY
A method for querying a knowledge base of malicious hosts numbered from 1 through N. The method includes providing a network of computers, which has a plurality of unknown malicious host machines. In a specific embodiment, the malicious host machines are disposed throughout the network of computers, which includes a worldwide network of computers. The method includes querying a knowledge base including a plurality of known malicious hosts, which are numbered from 1 through N, where N is an integer greater than 1. In a preferred embodiment, the knowledge base is coupled to the network of computers. The method includes receiving first information associated with an unknown host from the network; identifying an unknown host and querying the knowledge base to determine if the unknown host is one of the known malicious hosts in the knowledge base, and outputting second information associated with the unknown host based upon the querying process.
TRAITOR TRACING FOR OBFUSCATED CREDENTIALS
A method, computer program product, and system for providing verification processes associated with a commitment-based authentication protocol are described. A request by a user for access to one or more resources is received, and a presentation policy is transmitted to the user indicating required credentials. A commitment to a revocation handle is received, including an indication of an associated Sigma protocol executed by the user. A challenge value selected from a challenge value set associated with the associated Sigma protocol is transmitted to the user. Based on the selected challenge value, a presentation token and a value parameter that is distinct from the presentation token are received from the user. Based on a determination as to whether the presentation token and value parameter are valid in accordance with the associated Sigma protocol, access for the user to the one or more resources is granted to the user or prevented.
System and method for creation, deployment and management of augmented attacker map
A system for network surveillance to detect attackers, including a deception management server within a network of resources, including a deployment module managing and planting one or more decoy attack vectors in one or more of the resources in the network, wherein an attack vector is an object in memory or storage of a first resource that may be used to access a second resource, and one or more decoy servers accessible from resources in the network, each decoy server including an alert module that issues an alert when a specific resource in the network accesses the decoy server via one or more of the decoy attack vectors planted in the specific resource by the deployment module, and a delay module, delaying access to data on the decoy server while a resource accesses the decoy server.
METHOD FOR PROTECTING A NETWORK AGAINST A CYBERATTACK
A method for protecting a network having multiple network subscribers against a cyberattack, in which bits or bit sequences of a message are transmitted between the network subscribers in the network via different voltage levels on at least one transmission route of the network. For this purpose, at least one characteristic of the voltage levels or of the transmitted bits or bit sequences is actively modified in at least one of the network subscribers or on the at least one transmission route and the origin of the transmitted bits or of the at least one transmission route is determined on the basis of the at least one characteristic. The cyberattack on the network is detected or the cyberattack on the network is localized in the network as a function of the ascertained origin.
Network security analysis for smart appliances
A method and system for detecting malicious behavior from smart appliances within a network. Smart appliances have a certain level of intelligence that allows them to perform a specific role more effectively and conveniently. Network traffic data and appliance identification data is collected about smart appliances within a network. The data is sent to a behavior analysis engine, which computes confidence levels for anomalies within the network traffic that may be caused by malicious behavior. If the behavior analysis engine determines that malicious behavior is present in the network, it sends an instruction to a network traffic hub to block network traffic relating to the anomaly. In some embodiments, network traffic is blocked based on source-destination pairs. In some embodiments, network traffic is blocked from a device outside the network that is determined to be malicious.
Zero day threat detection using host application/program to user agent mapping
A technique allows associating host applications and user agents in network traffic and detecting possible malware without relying on signatures of the user agents. A database of host applications and user agents is maintained, allowing automatic update of the database when a new application or new application to user agent mapping is discovered. Partial matches may be made when a change is made to the application, allowing learning the new mapping automatically. If an application is associated with more than a threshold number of user agents, an indication may be generated that the application is suspicious and possibly malware.
Detection and management of unauthorized use of cloud computing services
Concepts and technologies disclosed herein are for detecting and managing unauthorized use of cloud computing services from within an internal network of a business or other organization. A computer system may be configured to identify a plurality of Web resources that have been accessed by computing devices from within the internal network. The computer system may also be configured to obtain Internet protocol (IP) information from a network component of the internal network. The IP information may be used to determine whether each of the plurality of Web resources is a cloud computing service resource. The computer system may also be configured to block access to a cloud computing service resource of the plurality of Web resources upon determining that the IP information identifies the cloud computing service resource as being unauthorized.
BLOCKCHAIN TRACKING OF VIRTUAL UNIVERSE TRAVERSAL RESULTS
An exemplary computer-implemented method includes obtaining at least one teleportation invite block that records a virtual universe teleportation invite marked by at least one parameter. The teleportation invite identifies a virtual universe user as an invitee. Responsive to the parameter, assess whether the virtual universe teleportation invite is potentially malicious, and alert the invitee in case the virtual universe teleportation invite is potentially malicious. Another exemplary computer-implemented method includes obtaining at least one complaint block that records a complaint made against a virtual universe user; obtaining a plurality of traversal blocks that record virtual universe traversal events by the virtual universe user; identifying a pattern of harassment by analyzing a first plurality of traversal blocks that precede the complaint block; identifying a risk of future harassment by analyzing a second plurality of traversal blocks that follow the complaint block; and issuing an alert regarding the risk of future harassment.
BLOCKCHAIN TRACKING OF VIRTUAL UNIVERSE TRAVERSAL RESULTS
An exemplary computer-implemented method includes obtaining at least one teleportation invite block that records a virtual universe teleportation invite marked by at least one parameter. The teleportation invite identifies a virtual universe user as an invitee. Responsive to the parameter, assess whether the virtual universe teleportation invite is potentially malicious, and alert the invitee in case the virtual universe teleportation invite is potentially malicious. Another exemplary computer-implemented method includes obtaining at least one complaint block that records a complaint made against a virtual universe user; obtaining a plurality of traversal blocks that record virtual universe traversal events by the virtual universe user; identifying a pattern of harassment by analyzing a first plurality of traversal blocks that precede the complaint block; identifying a risk of future harassment by analyzing a second plurality of traversal blocks that follow the complaint block; and issuing an alert regarding the risk of future harassment.
Predicting and preventing an attacker's next actions in a breached network
A method for cyber security, including detecting, by a management server, a breach by an attacker of a resource within a network of resources, predicting, by the management server, an attacker target subnet, based on connections created during the breach, and isolating, by the management server, the target subnet in response to the predicting a target subnet.