The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 15, 2021

Filed:

May. 22, 2019
Applicant:

Attivo Networks Inc., Fremont, CA (US);

Inventors:

Venu Vissamsetty, San Jose, CA (US);

Muthukumar Lakshmanan, Bangalore, IN;

Assignee:

ATTIVO NETWORKS INC., Fremont, CA (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
H04L 5/00 (2006.01); H04L 29/06 (2006.01); H04L 12/721 (2013.01); H04L 29/12 (2006.01); H04L 12/823 (2013.01);
U.S. Cl.
CPC ...
H04L 5/0055 (2013.01); H04L 45/72 (2013.01); H04L 47/32 (2013.01); H04L 61/256 (2013.01); H04L 61/2592 (2013.01); H04L 63/0428 (2013.01); H04L 63/1491 (2013.01); H04L 69/16 (2013.01);
Abstract

An endpoint executes a deflection service that detects failed connection attempts (TCP RST packets) and evaluates whether they are likely the result of a reconnaissance attack. If an inbound connection fails, a connection request packet (TCP SYN) is sent to a decoy server that includes data from the TCP RST packet. The decoy server then completes a connection handshake with a destination of the TCP RST packet and engages a process at the destination. If an outbound connection fails, the deflection service facilitates a connection between a process executing on the endpoint and the decoy server and associated with a destination port referenced by the TCP RST packet.


Find Patent Forward Citations

Loading…