IP Library Granted Patent US 10,097,577
Granted Patent B2
US 10,097,577 · App. 15/682,577 · Granted Oct 9, 2018

Predicting and preventing an attacker's next actions in a breached network

Inventors: Shlomo Touboul (Kfar Chaim, IL); Hanan Levin (Tel Aviv, IL); Stephane Roubach (Herzliya, IL); Assaf Mischari (Petach Tikva, IL); Itai Ben David (Tel Aviv, IL); Itay Avraham (Tel Aviv, IL); Adi Ozer (Shoham, IL); Chen Kazaz (Tel Aviv, IL); Ofer Israeli (Tel Aviv, IL); Olga Vingurt (Shderot, IL); Liad Gareh (Herzliya, IL); Israel Grimberg (Ra'anana, IL); Cobby Cohen (Tel Aviv, IL); Sharon Sultan (Tel Aviv, IL); Matan Kubovsky (Tel Aviv, IL)
Assignee: ILLUSIVE NETWORKS, LTD.
H04L63/1441G06F21/55
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,097,577
App. No.
15/682,577
Granted
Oct 9, 2018
Kind
B2
Abstract

A method for cyber security, including detecting, by a management server, a breach by an attacker of a resource within a network of resources, predicting, by the management server, an attacker target subnet, based on connections created during the breach, and isolating, by the management server, the target subnet in response to the predicting a target subnet.

Claims (14)

1. A method for cyber security for a network of resources, wherein access to the resources via network connections that extend outside the network is governed by a firewall, the method comprising:

detecting, by a management server, a breach by an attacker of a resource within a network of resources;

predicting, by the management server, the attacker's target network subnet, based on network connections created by the attacker during the detected breach;

isolating, by the management server, the predicted attacker's target network subnet in response to said predicting the attacker's target network subnet;

predicting, by the management server, data leakage paths from inside the network to outside the network, based on an outbound network connection opened by the attacker and detected by the management server, during the breach; and

creating, by the management server, firewall rules to re-direct the outbound network connection opened by the attacker to a resource within the network, in response to said predicting the data leakage paths, wherein the re-directed outbound network connection to a resource within the network appears to the attacker to be the attacker's intended outbound network connection to the attacker's intended destination outside the network.

2. The method of claim 1 comprising creating, by the management server, firewall rules to block the attacker-created outbound network connection in response to said predicting the data leakage paths.

3. A method for cyber security for a network of resources, wherein access to the resources via network connections that extend outside the network is governed by a firewall, the method comprising:

detecting, by a management server, a breach by an attacker of a resource within a network of resources, wherein access to the resources via network connections is governed by a firewall;

predicting, by the management server, which resources of the network were exposed to the attacker, based on address pointers stored on the breached resource;

creating, by the management server, firewall rules to block access to the predicted attacker exposed resources from the breached resource, in response to said predicting which resources of the network were exposed to the attacker;

predicting, by the management server, data leakage paths from inside the network to outside the network, based on an outbound network connection opened by the attacker and detected by the management server, during the breach; and

creating, by the management server, firewall rules to re-direct the outbound network connection opened by the attacker to a resource within the network, in response to said predicting the data leakage paths, wherein the re-directed outbound network connection to a resource within the network appears to the attacker to be the attacker's intended outbound network connection to the attacker's intended destination outside the network.

4. The method of claim 3 comprising creating, by the management server, firewall rules to block the attacker-created outbound network connection in response to said predicting the data leakage paths.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2024
From: ILLUSV NETWORKS LTD.
To: PROOFPOINT ISRAEL HOLDINGS LTD.
Reel/Frame 069461/0191 →
Continuity (8)
Continuation 15619547 · Jun 12, 2017
Continuation 15175054 · Jun 7, 2016
Provisional Application 62172251 · Jun 8, 2015
Provisional Application 62172255 · Jun 8, 2015
Provisional Application 62172261 · Jun 8, 2015
Provisional Application 62172259 · Jun 8, 2015
Provisional Application 62172253 · Jun 8, 2015
Related Publication 20180020022A1 · Jan 18, 2018