首页> 外国专利> INTRUSION AND MISUSE DETERRENCE SYSTEM EMPLOYING A VIRTUAL NETWORK

INTRUSION AND MISUSE DETERRENCE SYSTEM EMPLOYING A VIRTUAL NETWORK

机译:使用虚拟网络的入侵和滥用防范系统

摘要

A method and apparatus is disclosed for increasing the security of computer networks through the use of an Intrusion and Misuse Deterrence System (IMDS) operating on the network. The IMDS is a system that creates a synthetic network complete with synthetic hosts and routers. It is comprised of a network server with associated application software that appears to be a legitimate portion of a real network to a network intruder. The IMDS consequently invites inquiry and entices the intruder away from the real network. Simulated services are configured to appear to be running on virtual clients with globally unique, class “C” IP addresses. Since there are no legitimate users of the virtual network simulated by the IMDS, all such activity must be inappropriate and can be treated as such. Consequently, the entire set of transactions by an intruder can be collected and identified rather than just those transactions that meet a predefined attack profile. Also, new exploits and attacks are handled just as effectively as known attacks, resulting in better identification of attack methodologies as well as the identification and analysis of new attack types. Since the IMDS only has to be concerned with the traffic going to its simulated hosts it additionally eliminates the bandwidth limitation that plagues a traditional IDS.
机译:公开了一种通过使用在网络上运行的入侵和滥用威慑系统(IMDS)来增加计算机网络的安全性的方法和装置。 IMDS是一个系统,可创建包含综合主机和路由器的综合网络。它由网络服务器和相关的应用程序软件组成,这些应用程序对于网络入侵者而言似乎是真实网络的合法部分。因此,IMDS邀请查询并诱使入侵者远离真实网络。将模拟服务配置为似乎在具有全局唯一的“ C”类IP地址的虚拟客户端上运行。由于没有IMDS模拟的虚拟网络的合法用户,因此所有此类活动都必须是不适当的,并且可以这样对待。因此,入侵者可以收集和识别整个交易集,而不仅仅是满足预定义攻击概况的那些交易。此外,新的攻击和攻击与已知攻击的处理方式一样有效,从而可以更好地识别攻击方法以及识别和分析新的攻击类型。由于IMDS只需要关心流向其模拟主机的流量,因此它就消除了困扰传统IDS的带宽限制。

著录项

  • 公开/公告号US2014115687A1

    专利类型

  • 公开/公告日2014-04-24

    原文格式PDF

  • 申请/专利权人 MARTIN F. ROESCH;RONALD J. GULA;

    申请/专利号US201113153541

  • 发明设计人 RONALD J. GULA;MARTIN F. ROESCH;

    申请日2011-06-06

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 16:06:23

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号