The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Sep. 05, 2017

Filed:

Nov. 18, 2016
Applicant:

Extrahop Networks, Inc., Seattle, WA (US);

Inventors:

Thomas Lawrence Roeh, Katy, TX (US);

Samuel Kanen Clement, Brentwood, TN (US);

John Augustus Kiefer, Klein, TX (US);

Assignee:

ExtraHop Networks, Inc., Seattle, WA (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); H04L 12/861 (2013.01); H04L 12/26 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1416 (2013.01); H04L 43/04 (2013.01); H04L 43/16 (2013.01); H04L 49/9047 (2013.01); H04L 63/1425 (2013.01); H04L 63/20 (2013.01);
Abstract

Embodiments are directed to detecting one or more attacks in a network. One or more network flows may be monitored using one or more network monitoring computers (NMCs). If one or more file write operations are detected based on information included in one or more packets of the one or more network flows, one or more detection rules may be executed to analyze one or more portions of the one or more packets to identify file information that is associated with the one or more file write operations. One or more metrics may be provided based on the one or more detection rules and one or more of the file information, the one or more file write operations, or the like. If one or more metrics exceed one or more threshold values, one or more reports of one or more attacks may be provided.


Find Patent Forward Citations

Loading…