Information security – Monitoring or scanning of software or data including attack... – Intrusion detection
Reexamination Certificate
2011-04-26
2011-04-26
Zand, Kambiz (Department: 2434)
Information security
Monitoring or scanning of software or data including attack...
Intrusion detection
C726S022000
Reexamination Certificate
active
07934259
ABSTRACT:
A stealth threat detection manager detects stealth threats. The stealth threat detection manager monitors system activities that are vulnerable to being used by stealth threats. Dynamic link libraries are often used by stealth threats, so in some embodiments the stealth threat detection manager monitors for the loading thereof. The stealth threat detection manager detects when a system activity being monitored occurs, and after the occurrence of the activity, determines whether a specific component associated with the activity (e.g., the dynamic link library being loaded) is accessible on the computer. If the component is accessible, the stealth threat detection manager concludes that the component is non-stealthed. On the other hand, if the component is not accessible, the stealth threat detection manager concludes that the component is a stealth threat, and takes appropriate action in response.
REFERENCES:
patent: 5696702 (1997-12-01), Skinner et al.
patent: 5740370 (1998-04-01), Battersby et al.
patent: 5838262 (1998-11-01), Kershner et al.
patent: 5991856 (1999-11-01), Spilo et al.
patent: 6088803 (2000-07-01), Tso et al.
patent: 6272519 (2001-08-01), Shearer et al.
patent: 6314409 (2001-11-01), Schneck
patent: 6728964 (2004-04-01), Butt
patent: 6782527 (2004-08-01), Kouznetsov et al.
patent: 6928553 (2005-08-01), Xiong et al.
patent: 7207061 (2007-04-01), Martin
patent: 2002/0083343 (2002-06-01), Crosbie
patent: 2002/0087882 (2002-07-01), Schneier et al.
patent: 2002/0157020 (2002-10-01), Royer
patent: 2003/0037251 (2003-02-01), Frieder
patent: 2003/0051026 (2003-03-01), Carter
patent: 2006/0282827 (2006-12-01), Yeap et al.
patent: WO 01/71499 (2001-09-01), None
Lee, Sin Yeung; Low, Wai Lup and Wong, Pei Yuen, “Learning Fingerprints for a Database Intrusion Detection System”, Computer Security Laboratory, DSO National Labortories, Singapore, ESORICS Nov. 2002, LNCS 2502, pp. 264-279.
Low, Wai Lup, et al., “DIDAFIT: Detecting Intrusions in Databases Through Fingerprinting Transactions,” ICEIS 2002, Fourth International Conference On Enterprise Information Systems, vol. 1, Apr. 3-6, 2002, pp. 121-128, Ciudad Real, Spain.
Change log for Analysis Console for Intrusion Detection (Acid), indicating release date of Sep. 8, 2000 [online]. Andrew.cmu.edu [retrieved Apr. 18, 2003]. Retrieved from the Internet: <URL: http://www.andrew.cmu.edu/˜rdanyliw/snort/CHANGELOG>, U.S.A.
AirCERT web page, last updated Sep. 18, 2000 [online]. Cert.org [retrieved Apr. 18, 2003]. Retrieved from the Internet: <URL: http://www.cert.org/kb/aircert/>, U.S.A.
Analysis Console For Intrusion Detection (ACID) web page [online]. Andrew.cmu.edu [retrieved Apr. 18, 2003]. Retrieved from the Internet: <URL: http://www.andrew.cmu.edu/˜rdanyliw/snort/snortacid.html>, U.S.A.
Schneier, Bruce, Managed Security Monitoring: Network Security for the 21st Century, 2001 [online]. Counterpane.com [retrieved Apr. 18, 2003]. Retrieved from the Internet: <URL: http://www.counterpane.com/msm.pdf>, U.S.A.
Web page, announcing Nov. 11, 2000 release of Dshield [online]. Deja.com [retrieved Apr. 18, 2003]. Retrieved from the Internet: >URL: http://groups.google.com/groups?selm=8vm48v%245pd%241%40nnrp1.deja.com&oe=UTF-8&output=gplain>, U.S.A.
e=Security, Inc., Correlation Technology for Security Event Management, Oct. 7, 2002 [online]. eSecurityins.com [retrieved Apr. 18, 2003]. Retrieved from the Internet: >URL: http://www.esecurityinc.com/downloads/Correlation—WP.pdf>, Vienna, VA.
MyNetWatchman.com web pages indicating 9/00 beta release [online]. MyNetWatchman.com [retrieved Apr. 18, 2003]. Retrieved from the Internet: <URL: http://www.mynetwatchman.com/mynetwatchman/relnotes.htm>, Alpharetta, GA.
2000 Review of eSecurity product on Network Security web page [online]. SCMagazine.com [retrieved Apr. 18, 2003]. Retrieved from the Internet: <URL: http://www.scmagazine.com/scmagazine/2000—12/testc
etwork.htm#Open>.
“Caltarian Security Technology Platform”, Riptech web pages [online]. Symantec.com [retrieved Apr. 18, 2003]. Retrieved from the Internet: <URL: http://enterprisesecurity.symantec.com/Content/displayPDF.cfm?SSSPDFID=35&EID=O>, U.S.A.
Slashdot.org web pages describing Dshield, dated Nov. 27, 2000 [online]. Slashdot.org [retrieved Apr. 18, 2003]. Retrieved from the Internet: <URL: http://slashdot.org/article.pl?sid=00/11/27/1957238&mode=thread>, U.S.A.
Chung, C., Gertz, M., and Levitt, K., “DEMIDS: A Misuse Detection System for Database Systems,” Department of Computer Science, University of California at Davis, Oct. 1, 1999, pp. 1-18.
SCIP Product, Microdasys—“The need to control, inspect and manage encrypted webtraffic.”[online]. Retrieved on Mar. 18, 2005. Retrieved from the Internet: <URL: http://www.microdasys.com/scipproduct+M54a708de802.html>. Author unknown, 2 pages, Czech Republic.
Microdasys, “S C I P Secured Content Inspection: Protecting the Enterprise from CryptoHacks,” 2003 by Microdasys Inc., 2 pages, Czech Republic.
Marketing, “Digital Certificates—Best Practices—A Microdasys Whitepaper,” bestpractice.doc, Revision 1.1 (Jul. 31, 2003), 6 pages, Czech Republic.
Network Computing Solutions—“Microdasys SCIP” [online]. Retrieved on Mar. 18, 2005. Retrieved from the Internet: <URL: http://www.ncs/cz/index.php?language=en&menuitem-4&subitem=13>, 2 pages, Czech Republic.
Network Computing Solutions—NSC Homepage—News [online]. Retrieved on Mar. 18, 2005. Retrieved from the Internet: <URL://http://www.nsc.cz/index.php?language=en&menuitem=0&subitem=4&subitem=13>, 3 pages, Czech Republic.
“SSL Stripper Installation Guide,” [online]. Retrieved in Mar. 2005 from the Internet: <URL: http://www.sslstripper.com>, 2 pages, U.S.A.
SSL Stripper Home Page, “Security Solutions: SSL Stripper,” [online]. Retrieved on Mar. 18, 2005. Retrieved from the Internet: <URL: http://www.vroyer.org/sslstripper/index.html>, 2 pages, Oct. 15, 2004, U.S.A.
SSL Stripper Sample Screenshots, “Security Solutions: Sample Screenshots,” [online]. Retrieved on Mar. 18, 2005. Retrieved from the Internet: <URL: http://www.vroyer.org/sslstripper/screenshots.html>, 3 pages, Oct. 15, 2004, U.S.A.
Webwasher AG/Full feature set, “Full feature set,” [online]. Retrieved on Mar. 18, 2005. Retrieved from the Internet: <URL: http://www.webwasher.com/enterprise/products/webwasher—products/ssl—scanner/full—feature—set..html?I...>, 2 pages.
Webwasher AG/Webwasher 1000 CSM Appliance, “Webwasher 1000 CSM Appliance,” [online]. Retrieved on Mar. 18, 2005. Retrieved from the Internet: <URL: http://www.webwasher.com/enterprise/products/webwasher—products/csm—appliance/index...> 2 pages.
Webwasher AG/Webwasher URL Filter, “Webwasher URL Filter,” [online]. Retrieved on Mar. 18, 2005. Retrieved from the Internet: <URL: http://www.webwasher.com/enterprise/products/webwasher—products/webwasher—url—filter..> 1 page.
Webwasher AG/Webwasher Anti Virus, “Webwasher Anti Virus,” [online]. Retrieved on Mar. 18, 2005. Retrieved from the Internet: <URL: http://www.webwasher.com/enterprise/products/webwasher—products/anti—virus/index.html...>, 2 pages.
Webwasher AG/Webwasher Anti Spam, “Webwasher Anti Spam,” [online]. Retrieved on Mar. 18, 2005. Retrieved from the Internet: <URL: http://www.webwasher.com/enterprise/products/webwasher—products/anti—spam/index.htm...>, 1 page.
Webwasher AG/Webwasher Content Protection, “Webwasher Content Protection,” [online]. Retrieved on Mar. 18, 2005. Retrieved from the Internet: <URL: http://www.webwas
Fenwick & West LLP
Harriman Dant B Shaifer
Symantec Corporation
Zand Kambiz
LandOfFree
Stealth threat detection does not yet have a rating. At this time, there are no reviews or comments for this patent.
If you have personal experience with Stealth threat detection, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Stealth threat detection will most certainly appreciate the feedback.
Profile ID: LFUS-PAI-O-2649058