IP Library Granted Patent US 9,609,013
Granted Patent B1
US 9,609,013 · App. 15/162,233 · Granted Mar 28, 2017

Detecting computer security threats in electronic documents based on structure

Inventors: Oren Falkowitz (Redwood City, CA); Philip Syme (Ellicot City, MD)
Assignee: AREA 1 SECURITY, INC.
H04L63/1433H04L63/02H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,609,013
App. No.
15/162,233
Granted
Mar 28, 2017
Kind
B1
Abstract

In an embodiment, a method providing an improvement in remediating vulnerabilities in computer security comprising: receiving, using a network tap of a sensor computer that is coupled to a compromised computer, a communication packet that was sent from the compromised computer to a target computer; using the sensor computer, determining that the target computer is one of a plurality of enterprise computers; reading, at the sensor computer, a plurality of fields within a header of the communication packet; and performing a remediation measure by generating a header of an action packet, wherein the header comprises duplicates of at least some fields of the plurality of fields so as to appear to be generated by the target computer, generating a payload of the action packet, and sending the action packet comprising the generated header and the generated payload to the compromised computer.

Claims (5)

1. A method providing an improvement in remediating malware attacks in computer security, comprising:

receiving, using a network tap of a sensor computer that is coupled to and co-located with a compromised computer that hosts or executes malware, a communication packet that was sent from the compromised computer to a target computer and allowed to pass to the target computer;

reading, at the sensor computer, a plurality of fields within a header of the communication packet;

determining, at the sensor computer, that the communication packet is sent as part of a potential malware attack on the target computer;

performing, using the sensor computer, a remediation measure by generating a header of an action packet, wherein the header comprises duplicates of at least some fields of the plurality of fields so as to appear to be generated by the target computer, generating a payload of the action packet, and sending the action packet comprising the generated header and the generated payload to the target computer.

Assignments (4)
SECURITY INTEREST Recorded May 20, 2024
From: CLOUDFLARE, INC.
To: CITIBANK, N.A.
Reel/Frame 067472/0246 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2022
From: AREA 1 SECURITY, LLC
To: CLOUDFLARE, INC.
Reel/Frame 059615/0665 →
MERGER Recorded Apr 11, 2022
From: AREA 1 SECURITY, INC.
To: ANGLER MERGER SUB II, LLC
Reel/Frame 059565/0414 →
CHANGE OF NAME Recorded Apr 11, 2022
From: ANGLER MERGER SUB II, LLC
To: AREA 1 SECURITY, LLC
Reel/Frame 059565/0653 →
Continuity (1)
Continuation 14723251 · May 27, 2015