IP Library Granted Patent US 8,656,493
Granted Patent B2
US 8,656,493 · App. 13/759,335 · Granted Feb 18, 2014

Decoy network technology with automatic signature generation for intrusion detection and intrusion prevention systems

Inventor: Alen Capalik (Pacific Palisades, CA)
Assignee: NeuralIQ, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,656,493
App. No.
13/759,335
Granted
Feb 18, 2014
Kind
B2
Abstract

Improved methods and systems for decoy networks with automatic signature generation for intrusion detection and intrusion prevention systems. A modular decoy network with front-end monitor/intercept module(s) with a processing back-end that is separate from the protected network. The front-end presents a standard fully functional operating system that is a decoy so that the instigator of an attack is lead to believe a connection has been made to the protected network. The front-end includes a hidden sentinel kernal driver that monitors connections to the system and captures attack-identifying information. The captured information is sent to the processing module for report generation, data analysis and generation of an attack signature. The generated attack signature can then be applied to the library of signatures of the intrusion detection system or intrusion prevention system of the protected network to defend against network based attacks including zero-day attacks.

Claims (35)

1. A method for protecting a computer network with automatic signature generation for intrusion prevention systems, comprising:

providing a network connection on a computer network to a computer system that includes an operating system hosted on a monitoring module that includes a kernel driver coupled with said operating system and hidden from an attacker by preventing the kernel driver from registering with said operating system;

monitoring a network attack on said computer network using the monitoring module, wherein said network attack comprises attack-identifying information that is based on activities on said operating system;

processing said attack-identifying information using a processing module connected to said computer system through a second network connection to identify said network attack and generate an attack signature using the attack-identifying information that is based on activities on said operating system; and

applying said attack signature generated using the attack-identifying information that is based on activities on said operating system to a library of signatures contained in an intrusion prevention system to control access to said computer network.

2. The method of claim 1 , further comprising:

providing a network connection to a second computer system that includes a second operating system hosted on a second monitoring module, wherein said operating system and said second operating system are different operating systems.

3. The method of claim 1 , wherein said attack signature is generated based on an attack payload including keystrokes or ASCII or binary files.

4. The method of claim 1 , wherein the attack signature is generated if an attacker interacts with said operating system.

5. The method of claim 1 , wherein said attack signature is generated if an attacker is able to successfully gain access to said operating system.

6. The method of claim 1 , further comprising providing a report of said network attack to an administrator.

7. The method of claim 1 , wherein said attack signature is maintained in a database.

8. The method of claim 1 , wherein the all activities on the operating system include: connections to the operating system, activity on the operating system, and activity on services running on the operating system.

9. A system for a protecting a computer network with automatic signature generation for intrusion prevention systems, comprising:

a computer hardware system hosted on a computer network, wherein said computer system includes an operating system hosted on a monitoring module;

a kernel driver coupled with said operating system and hidden from an attacker by preventing the kernel driver from registering with said operating system, wherein the monitoring module including said kernel driver is configured to monitor a network attack on said computer network, and said network attack comprises attack-identifying information that is based on activities on said operating system;

a processing module comprising a processor, wherein said processing module is connected to said computer system through a second network connection, and said processing module is configured to identify said network attack and generate an attack signature from said attack-identifying information that is based on activities on said operating system; and

said processing module further configured to apply said attack signature generated from said attack-identifying information that is based on activities on said operating system to a library of signatures contained in an intrusion prevention system to control access to said computer network.

10. The system of claim 9 , further comprising:

a second computer system including a second operating system hosted on a second monitoring module, wherein said operating system and said second operating system are different operating systems.

11. The system of claim 9 , wherein said attack signature is generated based on an attack payload including keystrokes of ASCII or binary files.

12. The system of claim 9 , wherein said attack signatures are maintained in a database.

13. The system of claim 9 , where said attack signature is automatically generated based on said attack-identifying information.

14. A system for protecting a computer network having a library of signatures comprising:

means for providing a network connection on a computer network to a computer system that includes an operating system hosted on a monitoring module that includes a kernel driver coupled with said functional operating system and hidden from an attacker by preventing the kernel driver from registering with said operating system;

means for monitoring a network attack on said computer network using the monitoring module, wherein said network attack comprises attack-identifying information that is based on activities on said operating system;

means for processing said attack-identifying information using a processing module connected to said computer system through a second network connection to identify said network attack and generate an attack signature using the attack-identifying information that is based on activities on said operating system; and

means for applying said attack signature generated using the attack-identifying information that is based on activities on said operating system to a library of signatures contained in an intrusion prevention system to control access to said computer network.

15. The system of claim 14 , further comprising:

means for providing a network connection on said computer network to a second operating system hosted on a second monitoring module wherein said operating system and said second operating system are different operating systems.

16. The system of claim 14 , wherein said attack signature is generated based on an attack payload including keystrokes or ASCII or binary files.

17. The system of claim 14 , wherein said attack signature is maintained in a database.

18. The system of claim 14 , wherein said attack signature is generated if an attacker communicates with a port.

19. The system of claim 14 , wherein said attack signature is generated if an attacker is able to successfully gain access to said operating system.

20. The system of claim 14 , further comprising means for providing a report of said network attack to an administrator.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS DATA PREVIOUSLY RECORDED AT REEL: 70134 FRAME: 0413. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY TEREST . Recorded Feb 14, 2025
From: GOSECURE, INC.
To: COMERICA BANK
Reel/Frame 070235/0936 →
SECURITY INTEREST Recorded Feb 6, 2025
From: GOSECURE, INC.
To: COMERICA BANK
Reel/Frame 070134/0413 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2023
From: CAPALIK, ALEN
To: NEURALIQ, INC.
Reel/Frame 065863/0154 →
CHANGE OF NAME Recorded Dec 13, 2023
From: NEURALIQ, INC.
To: COUNTERTACK, INC.
Reel/Frame 065988/0287 →
CHANGE OF NAME Recorded Dec 13, 2023
From: COUNTERTACK, INC.
To: GOSECURE, INC.
Reel/Frame 065988/0293 →
CHANGE OF NAME Recorded Sep 28, 2023
From: COUNTERTACK, INC.
To: GOSECURE, INC.
Reel/Frame 065082/0059 →
RELEASE OF SECURITY INTEREST Recorded May 29, 2018
From: PACIFIC WESTERN BANK
To: COUNTERTACK INC.
Reel/Frame 045923/0804 →
SECURITY INTEREST Recorded Nov 21, 2016
From: COUNTERTACK INC.
To: PACIFIC WESTERN BANK
Reel/Frame 040384/0329 →
Continuity (3)
Continuation 11488743 · Jul 17, 2006
Provisional Application 60802543 · May 22, 2006
Related Publication 20130152199A1 · Jun 13, 2013