Attack detection and prevention using global device fingerprinting

This disclosure describes a global attacker database that utilizes device fingerprinting to uniquely identify devices. For example, a device includes one or more processors and network interface cards to receive network traffic directed to one or more computing devices protected by the device, send,...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: BURNS, BRYAN, ADAMS, KYLE, IBATULLIN, OSKAR, MORALES, YULY TENORIO, QUINLAN, DANIEL, CAMERON, ROBERT
Format: Patent
Sprache:eng ; fre ; ger
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
container_end_page
container_issue
container_start_page
container_title
container_volume
creator BURNS, BRYAN
ADAMS, KYLE
IBATULLIN, OSKAR
MORALES, YULY TENORIO
QUINLAN, DANIEL
CAMERON, ROBERT
description This disclosure describes a global attacker database that utilizes device fingerprinting to uniquely identify devices. For example, a device includes one or more processors and network interface cards to receive network traffic directed to one or more computing devices protected by the device, send, to the remote device, a request for data points of the remote device, wherein the data points include characteristics associated with the remote device, and receive at least a portion of the requested data points. The device also includes a fingerprint module to compare the received portion of the data points to sets of data points associated with known attacker devices, and determine, based on the comparison, whether a first set of data points of a first known attacker device satisfies a similarity threshold. The device also includes an security module to selectively manage, based on the determination, additional network traffic directed to the computing devices.
format Patent
fullrecord <record><control><sourceid>epo_EVB</sourceid><recordid>TN_cdi_epo_espacenet_EP2779574A1</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>EP2779574A1</sourcerecordid><originalsourceid>FETCH-epo_espacenet_EP2779574A13</originalsourceid><addsrcrecordid>eNrjZHByLClJTM5WSEktSU0uyczPU0jMS1EoKEotS80Dc0uLM_PSFdJz8pMSc4CqyjKTUxXSgEKpRQVFmUAleek8DKxpiTnFqbxQmptBwc01xNlDN7UgPz61uCAxOTUvtSTeNcDI3NzS1NzE0dCYCCUAEvEyRA</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>patent</recordtype></control><display><type>patent</type><title>Attack detection and prevention using global device fingerprinting</title><source>esp@cenet</source><creator>BURNS, BRYAN ; ADAMS, KYLE ; IBATULLIN, OSKAR ; MORALES, YULY TENORIO ; QUINLAN, DANIEL ; CAMERON, ROBERT</creator><creatorcontrib>BURNS, BRYAN ; ADAMS, KYLE ; IBATULLIN, OSKAR ; MORALES, YULY TENORIO ; QUINLAN, DANIEL ; CAMERON, ROBERT</creatorcontrib><description>This disclosure describes a global attacker database that utilizes device fingerprinting to uniquely identify devices. For example, a device includes one or more processors and network interface cards to receive network traffic directed to one or more computing devices protected by the device, send, to the remote device, a request for data points of the remote device, wherein the data points include characteristics associated with the remote device, and receive at least a portion of the requested data points. The device also includes a fingerprint module to compare the received portion of the data points to sets of data points associated with known attacker devices, and determine, based on the comparison, whether a first set of data points of a first known attacker device satisfies a similarity threshold. The device also includes an security module to selectively manage, based on the determination, additional network traffic directed to the computing devices.</description><language>eng ; fre ; ger</language><subject>ELECTRIC COMMUNICATION TECHNIQUE ; ELECTRICITY ; TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</subject><creationdate>2014</creationdate><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktohtml>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20140917&amp;DB=EPODOC&amp;CC=EP&amp;NR=2779574A1$$EHTML$$P50$$Gepo$$Hfree_for_read</linktohtml><link.rule.ids>230,308,778,883,25553,76306</link.rule.ids><linktorsrc>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20140917&amp;DB=EPODOC&amp;CC=EP&amp;NR=2779574A1$$EView_record_in_European_Patent_Office$$FView_record_in_$$GEuropean_Patent_Office$$Hfree_for_read</linktorsrc></links><search><creatorcontrib>BURNS, BRYAN</creatorcontrib><creatorcontrib>ADAMS, KYLE</creatorcontrib><creatorcontrib>IBATULLIN, OSKAR</creatorcontrib><creatorcontrib>MORALES, YULY TENORIO</creatorcontrib><creatorcontrib>QUINLAN, DANIEL</creatorcontrib><creatorcontrib>CAMERON, ROBERT</creatorcontrib><title>Attack detection and prevention using global device fingerprinting</title><description>This disclosure describes a global attacker database that utilizes device fingerprinting to uniquely identify devices. For example, a device includes one or more processors and network interface cards to receive network traffic directed to one or more computing devices protected by the device, send, to the remote device, a request for data points of the remote device, wherein the data points include characteristics associated with the remote device, and receive at least a portion of the requested data points. The device also includes a fingerprint module to compare the received portion of the data points to sets of data points associated with known attacker devices, and determine, based on the comparison, whether a first set of data points of a first known attacker device satisfies a similarity threshold. The device also includes an security module to selectively manage, based on the determination, additional network traffic directed to the computing devices.</description><subject>ELECTRIC COMMUNICATION TECHNIQUE</subject><subject>ELECTRICITY</subject><subject>TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</subject><fulltext>true</fulltext><rsrctype>patent</rsrctype><creationdate>2014</creationdate><recordtype>patent</recordtype><sourceid>EVB</sourceid><recordid>eNrjZHByLClJTM5WSEktSU0uyczPU0jMS1EoKEotS80Dc0uLM_PSFdJz8pMSc4CqyjKTUxXSgEKpRQVFmUAleek8DKxpiTnFqbxQmptBwc01xNlDN7UgPz61uCAxOTUvtSTeNcDI3NzS1NzE0dCYCCUAEvEyRA</recordid><startdate>20140917</startdate><enddate>20140917</enddate><creator>BURNS, BRYAN</creator><creator>ADAMS, KYLE</creator><creator>IBATULLIN, OSKAR</creator><creator>MORALES, YULY TENORIO</creator><creator>QUINLAN, DANIEL</creator><creator>CAMERON, ROBERT</creator><scope>EVB</scope></search><sort><creationdate>20140917</creationdate><title>Attack detection and prevention using global device fingerprinting</title><author>BURNS, BRYAN ; ADAMS, KYLE ; IBATULLIN, OSKAR ; MORALES, YULY TENORIO ; QUINLAN, DANIEL ; CAMERON, ROBERT</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-epo_espacenet_EP2779574A13</frbrgroupid><rsrctype>patents</rsrctype><prefilter>patents</prefilter><language>eng ; fre ; ger</language><creationdate>2014</creationdate><topic>ELECTRIC COMMUNICATION TECHNIQUE</topic><topic>ELECTRICITY</topic><topic>TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</topic><toplevel>online_resources</toplevel><creatorcontrib>BURNS, BRYAN</creatorcontrib><creatorcontrib>ADAMS, KYLE</creatorcontrib><creatorcontrib>IBATULLIN, OSKAR</creatorcontrib><creatorcontrib>MORALES, YULY TENORIO</creatorcontrib><creatorcontrib>QUINLAN, DANIEL</creatorcontrib><creatorcontrib>CAMERON, ROBERT</creatorcontrib><collection>esp@cenet</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>BURNS, BRYAN</au><au>ADAMS, KYLE</au><au>IBATULLIN, OSKAR</au><au>MORALES, YULY TENORIO</au><au>QUINLAN, DANIEL</au><au>CAMERON, ROBERT</au><format>patent</format><genre>patent</genre><ristype>GEN</ristype><title>Attack detection and prevention using global device fingerprinting</title><date>2014-09-17</date><risdate>2014</risdate><abstract>This disclosure describes a global attacker database that utilizes device fingerprinting to uniquely identify devices. For example, a device includes one or more processors and network interface cards to receive network traffic directed to one or more computing devices protected by the device, send, to the remote device, a request for data points of the remote device, wherein the data points include characteristics associated with the remote device, and receive at least a portion of the requested data points. The device also includes a fingerprint module to compare the received portion of the data points to sets of data points associated with known attacker devices, and determine, based on the comparison, whether a first set of data points of a first known attacker device satisfies a similarity threshold. The device also includes an security module to selectively manage, based on the determination, additional network traffic directed to the computing devices.</abstract><oa>free_for_read</oa></addata></record>
fulltext fulltext_linktorsrc
identifier
ispartof
issn
language eng ; fre ; ger
recordid cdi_epo_espacenet_EP2779574A1
source esp@cenet
subjects ELECTRIC COMMUNICATION TECHNIQUE
ELECTRICITY
TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION
title Attack detection and prevention using global device fingerprinting
url https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-01-15T09%3A06%3A53IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-epo_EVB&rft_val_fmt=info:ofi/fmt:kev:mtx:patent&rft.genre=patent&rft.au=BURNS,%20BRYAN&rft.date=2014-09-17&rft_id=info:doi/&rft_dat=%3Cepo_EVB%3EEP2779574A1%3C/epo_EVB%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true