Patent · US Active

Using high-interaction networks for targeted threat intelligence

US10230745B2 · kind B2 · utility

8Cited by
5References
27Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJan 12, 2017
Grant dateMar 12, 2019
Priority date
Expiry dateJan 12, 2037

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1408
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Provided are methods, network devices, and computer-program products for targeted threat intelligence using a high-interaction network. In some implementations, a network device in a network may receive suspect network traffic. The suspect network traffic may include network traffic identified as potentially causing harm to the network. The network device may determine that the suspect traffic is associated with an unknown threat. The network device may further analyze the suspect network traffic using a high-interaction network. In various implementations, the high-interaction network may be configured to emulate at least a part of the network. In various implementations, analyzing the suspect network traffic may include determining a behavior of the suspect network traffic in the high-interaction network. The network device may further generate indicators, where the indicators may describe the suspect network traffic. In various implementations, the indicators facilitate analysis of a network's susceptibility to the unknown threat.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.