IP Library Granted Patent US 9,866,584
Granted Patent B2
US 9,866,584 · App. 14/542,376 · Granted Jan 9, 2018

System and method for analyzing unauthorized intrusion into a computer network

Inventor: Alen Capalik (Pacific Palisades, CA)
Assignee: CounterTack, Inc.
H04L63/145G06F9/45533G06F21/552G06F21/566H04L63/1408H04L63/1416H04L63/1491G06F2221/2123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,866,584
App. No.
14/542,376
Granted
Jan 9, 2018
Kind
B2
Abstract

The method analyzes unauthorized intrusion into a computer network. Access is allowed to a virtualized operating system running on a hypervisor operating system hosted on a network device. A network attack is intercepted on the virtualized operating system using an introspection module with a virtual-machine-based rootkit module and its associated userland processes running on the hypervisor operating system. The network attack includes attack-identifying information. Forensic data is generated on the network attack from the attack-identifying information.

Claims (17)

1. A computer system, comprising:

one or more processors, and

memory storing one or more programs for execution by the one or more processors, the one or more programs including:

a first fully-functional operating system configured to provide real information of the fully-functional operating system in response to an external scan; and

a monitoring module that (A) is coupled with the first operating system and hidden from an attacker attacking the first operating system, (B) monitors activities in the first operating system, (C) captures data including attack-identifying information based on the activities in the first operating system, and (D) provides captured data including the attack-identifying information to an information processing system that includes an operating system that is separate and distinct from the one or more operating systems of the computer system, wherein the information processing system is configured to generate an attack signature by analyzing the captured data, wherein the monitoring module includes a kernel module that monitors activities in the first operating system, and the kernel module is not included in a kernel module listing of the first operating system and kernel pointers for the kernel module are removed so that the kernel module is hidden from the attacker attacking the first operating system.

2. The computer system of claim 1 , wherein the one or more programs include:

a second operating system that is a hypervisor operating system, wherein:

the first operating system is a virtualized operating system;

the monitoring module is located outside the first operating system and inside the second operating system, thereby remaining hidden from the attacker attacking the first operating system; and

the monitoring module is configured to monitor memory segments of the first operating system.

3. The computer system of claim 1 , wherein the monitoring module is configured to monitor services running on the first operating system.

4. The computer system of claim 3 , wherein the information processing system is configured to apply the attack signature to a library of signatures contained in an intrusion prevention system, that is separate and distinct from the computer system, to control access to the computer system.

5. The computer system of claim 1 , wherein the computer system and the information processing system are connected through a secure communication channel that is hidden from and inaccessible by the attacker attacking the first operating system.

6. The computer system of claim 5 , wherein the secure communication channel is a private network interface communications channel.

7. The computer system of claim 1 , wherein the monitoring module is configured to open one or more ports of the first operating system prior to monitoring the activities in the first operating system.

8. The computer system of claim 1 , wherein the information processing system is configured to generate an attack signature by analyzing the captured data in accordance with a determination that the attacker has gained access to the first operating system.

9. The computer system of claim 1 , wherein the monitoring module includes rootkit code configured for hiding the monitoring module from the attacker.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS DATA PREVIOUSLY RECORDED AT REEL: 70134 FRAME: 0413. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY TEREST . Recorded Feb 14, 2025
From: GOSECURE, INC.
To: COMERICA BANK
Reel/Frame 070235/0936 →
SECURITY INTEREST Recorded Feb 6, 2025
From: GOSECURE, INC.
To: COMERICA BANK
Reel/Frame 070134/0413 →
CHANGE OF NAME Recorded Dec 15, 2023
From: NEURALIQ, INC.
To: COUNTERTACK, INC.
Reel/Frame 066046/0184 →
CHANGE OF NAME Recorded Dec 15, 2023
From: COUNTERTACK, INC.
To: GOSECURE, INC.
Reel/Frame 066046/0190 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2023
From: CAPALIK, ALEN
To: NEURALIQ, INC.
Reel/Frame 065889/0148 →
CHANGE OF NAME Recorded Sep 28, 2023
From: COUNTERTACK, INC.
To: GOSECURE, INC.
Reel/Frame 065082/0434 →
RELEASE OF SECURITY INTEREST Recorded May 29, 2018
From: PACIFIC WESTERN BANK
To: COUNTERTACK INC.
Reel/Frame 045923/0804 →
SECURITY INTEREST Recorded Nov 21, 2016
From: COUNTERTACK INC.
To: PACIFIC WESTERN BANK
Reel/Frame 040384/0329 →
Continuity (4)
Continuation 11788795 · Apr 20, 2007
Continuation In Part 11488743 · Jul 17, 2006
Provisional Application 60802543 · May 22, 2006
Related Publication 20150074811A1 · Mar 12, 2015