IP Library Patent Application 14596240
Patent Application
App. No. 14/596,240

PASSIVE DETECTION OF MALICIOUS NETWORK-MAPPING SOFTWARE IN COMPUTER NETWORKS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/596,240
Abstract

A method includes, in a computer network that includes multiple endpoints, configuring a network element to forward one or more specified packets from a selected endpoint to a detection unit. A malicious network-mapping software running on the selected endpoint is identified by analyzing the forwarded packets in the detection unit.

Claims (26)

1 . A method, comprising:

in a computer network that comprises multiple endpoints, configuring a network element to forward one or more specified packets from a selected endpoint to a detection unit; and

identifying a malicious network-mapping software running on the selected endpoint, by analyzing the forwarded packets in the detection unit.

2 . The method according to claim 1 , wherein configuring the network element comprises instructing the network element to send to the selected endpoint a packet that is expected to be discarded by a network interface of the selected endpoint unless the network interface operates in a promiscuous mode, and wherein identifying the network-mapping software comprises detecting that the selected endpoint responded to the packet.

3 . The method according to claim 1 , wherein configuring the network element comprises instructing the network element to send to the selected endpoint a packet having a layer-2 address that does not match the layer-2 address of the selected endpoint, and wherein identifying the network-mapping software comprises detecting that the selected endpoint responded to the packet.

4 . The method according to claim 1 , wherein configuring the network element comprises instructing the network element to forward to the detection unit reverse name resolution queries initiated by the selected endpoint, and wherein identifying the network-mapping software comprises analyzing the reverse name resolution queries.

5 . The method according to claim 4 , wherein identifying the network-mapping software comprises detecting that a rate of the reverse name resolution queries exceeds a threshold.

6 . The method according to claim 4 , wherein identifying the network-mapping software comprises detecting that at least one of the reverse name resolution queries specifies an address in a same subnet as the selected endpoint.

7 . The method according to claim 1 , wherein configuring the network element comprises instructing the network element to forward to the detection unit sniffing announcement packets.

8 . The method according to claim 1 , wherein configuring the network element comprises configuring a physical or virtual network switch.

9 . A method, comprising:

configuring a software module that runs on a node of a computer network to directly access a memory of a Virtual Machine (VM) running on the node; and

using the software module, identifying a malicious network-mapping software running in the VM, by directly accessing the memory of the VM.

10 . The method according to claim 9 , wherein identifying the network-mapping software comprises comparing a process running in the memory of the VM to one or more known network-mapping processes.

11 . The method according to claim 9 , wherein identifying the network-mapping software comprises accessing a virtual network interface in the memory of the VM, and detecting that the virtual network interface is operating in promiscuous mode.

12 . An apparatus, comprising:

an interface for communicating with a computer network that comprises multiple endpoints; and

a processor, which is arranged to configure a network element in the computer network to forward one or more specified packets from a selected endpoint to the apparatus, and to identify a malicious network-mapping software running on the selected endpoint by analyzing the forwarded packets.

13 . The apparatus according to claim 12 , wherein the processor is arranged to instruct the network element to send to the selected endpoint a packet that is expected to be discarded by a network interface of the selected endpoint unless the network interface operates in a promiscuous mode, and to identify the network-mapping software by detecting that the selected endpoint responded to the packet.

14 . The apparatus according to claim 12 , wherein the processor is arranged to instruct the network element to send to the selected endpoint a packet having a layer-2 address that does not match the layer-2 address of the selected endpoint, and to identify the network-mapping software by detecting that the selected endpoint responded to the packet.

15 . The apparatus according to claim 12 , wherein the processor is arranged to instruct the network element to forward reverse name resolution queries initiated by the selected endpoint, and to identify the network-mapping software by analyzing the reverse name resolution queries.

16 . The apparatus according to claim 15 , wherein the processor is arranged to identify the network-mapping software by detecting that a rate of the reverse name resolution queries exceeds a threshold.

17 . The apparatus according to claim 15 , wherein the processor is arranged to identify the network-mapping software by detecting that at least one of the reverse name resolution queries specifies an address in a same subnet as the selected endpoint.

18 . The apparatus according to claim 12 , wherein the processor is arranged to instruct the network element to forward sniffing announcement packets.

19 . The apparatus according to claim 12 , wherein the network element comprises a physical or virtual network switch.

20 . A computer software product, the product comprising a tangible non-transitory computer-readable medium in which program instructions are stored, which instructions, when read by a processor of a detection unit that is connected to a computer network comprising multiple endpoints, cause the processor to configure a network element in the computer network to forward one or more specified packets from a selected endpoint to the detection unit, and to identify a malicious network-mapping software running on the selected endpoint by analyzing the forwarded packets.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Oct 12, 2021
From: SILICON VALLEY BANK
To: GUARDICORE LTD
Reel/Frame 057768/0936 →
SECURITY INTEREST Recorded Jan 14, 2019
From: GUARDICORE LTD
To: SILICON VALLEY BANK
Reel/Frame 047989/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 14, 2015
From: TAL, ITAMAR; ZEITLIN, ARIEL; GURVICH, PAVEL; ZIV, OFRI
To: GUARDICORE LTD.
Reel/Frame 034702/0627 →