Countering service enumeration through imposter-driven response
Abstract
Techniques for improving computer system security by detecting and responding to attacks on computer systems are described herein. A computer system monitors communications requests from external systems and, as a result of detecting one or more attacks on the computer system, the computer system responds to the attacks by analyzing the behavior of the attacker, relating that behavior to one or more attack profiles and creating a simulated environment to respond to the attack based in part on the attack profiles. The simulated environment responds to the attack by communicating with the attacker.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method, comprising:
receiving a first communication associated with a first type of attack; receiving a second communication associated with a second type of attack, the second type of attack different from the first type of attack; determining, based at least on the first type of attack and second type of attack, an attack pattern; determining that a received third communication matches the attack pattern; updating the attack pattern to be associated with the third communication; and transmitting an alert associated with the updated attack pattern to a host computer system.
2 . The computer-implemented method of claim 1 , further comprising:
determining that at least one of the first communication, second communication, or the third communication is indicative of suspicious behavior; and modifying a communication channel of the host computer system, the communication channel associated with a respective communication indicative of suspicious behavior.
3 . The computer-implemented method of claim 1 , wherein determining the attack pattern is based at least in part on one or more received communications associated with the first type of attack, and based at least in part on a weighting value associated with the type of attack.
4 . The computer-implemented method of claim 1 , further comprising:
receiving identifying information of one or more attackers associated with at least the first communication and the second communication; and determining that the received third communication matches the attack pattern by at least matching the received identifying information with additional identifying information associated with the third communication.
5 . The computer-implemented method of claim 1 , further comprising determining that the first communication, second communication, and the third communication are associated with an identified piece of software.
6 . The computer-implemented method of claim 1 , wherein at least one of the first communication, second communication, or the third communication is associated with one or more connection requests.
7 . A system comprising:
at least one processor; and a memory comprising instructions that, in response to execution by the at least one processor, cause the system to at least:
determine an attack pattern associated with at least a first communication indicative of a first attack type and a second communication indicative of a second attack type;
determine that one or more behaviors match the attack pattern;
update the attack pattern to include the one or more behaviors; and
transmit a notification associated with the updated attack pattern to a computer system.
8 . The system of claim 7 , wherein the instructions, in response to execution by the at least one processor, further cause the system to identify one or more attackers associated with at least the one or more behaviors.
9 . The system of claim 7 , wherein the instructions, in response to execution by the at least one processor, further cause the system to determine that the one or more behaviors match the attack pattern based on a common identifier of one or more attackers associated with the attack pattern and the one or more behaviors.
10 . The system of claim 7 , wherein the notification is a security alert based at least in part on the attack pattern.
11 . The system of claim 7 , wherein the instructions, in response to execution by the at least one processor, further cause the system to determine potential risk of an attack behavior based at least on an evaluation of the attack behavior relative to one or more tracked behaviors.
12 . The system of claim 7 , wherein the one or more behaviors comprise one or more connection requests to unused ports of a host computer system.
13 . The system of claim 7 , wherein the instructions, in response to execution by the at least one processor, further cause the system to communicate with a suspected attacker associated with the determined attack pattern.
14 . A non-transitory computer-readable storage medium comprising executable instructions that, in response to execution by one or more processors of a computer system, cause the computer system to at least:
determine that a first communication received from one or more attackers is associated with a first attack type; determine that a second communication received from the one or more attackers is associated with a second attack type, the second attack type different from the first attack type; determine, based at least on the first attack type and second attack type, an attack pattern; predict, based on the attack pattern, a third attack type, and send a host computer system an alert based on the predicted third attack type.
15 . The non-transitory computer-readable storage medium of claim 14 , comprising further instructions that, in response to execution by the one or more processors, cause the computer system to at least associate the attack pattern with an identifying characteristic of one or more attackers.
16 . The non-transitory computer-readable storage medium of claim 14 , wherein the attack pattern is generated based at least in part on a plurality of previously recognized attack patterns.
17 . The non-transitory computer-readable storage medium of claim 14 , wherein the second communication is determined to be associated with the second attack type based at least in part on receiving the second communication more than a threshold number of times.
18 . The non-transitory computer-readable storage medium of claim 14 , comprising further instructions that, in response to execution by the one or more processors, cause the computer system to at least identify one or more attacker elements associated with the attack pattern.
19 . The non-transitory computer-readable storage medium of claim 14 , comprising further instructions that, in response to execution by the one or more processors, cause the computer system to at least obtain information about software associated with at least one of the first attack type and the second attack type.
20 . The non-transitory computer-readable storage medium of claim 14 , comprising further instructions that, in response to execution by the one or more processors, cause the computer system to:
determine that a received third communication matches the attack pattern; update the attack pattern associated with the received third communication; and send a host computer system a notification based on the updated attack pattern.Join the waitlist — get patent alerts
Track US2019268358A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.