Patent · US Active

Efficient packet capture for cyber threat analysis

US11729144B2 · kind B2 · utility

5Cited by
83References
40Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 19, 2016
Grant dateAug 15, 2023
Priority date
Expiry dateDec 19, 2036

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/20
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Methods, systems, and computer-readable media for efficiently detecting threat incidents for cyber threat analysis are described herein. In various embodiments, a computing device, which may be located at a boundary between a protected network associated with the enterprise and an unprotected network, may combine one or more threat indicators received from one or more threat intelligence providers; may generate one or more packet capture and packet filtering rules based on the combined threat indicators; and, may capture or filter, on a packet-by-packet basis, at least one packet based on the generated rules. In other embodiments, a computing device may generate a packet capture file comprising raw packet content and corresponding threat context information, wherein the threat context information may comprise a filtering rule and an associated threat indicator that caused the packet to be captured.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.