Pre-Grant Publication Number: 20070208822
Filing Date: March 01, 2006
Inventors: Yi-Min Wang, Douglas Beck
Assignee(s): Microsoft Corporation
Current U.S. Classification: 709, 709/217000
View Prior Art for Claim 00017
The method as recited in Claim 16, further comprising: waiting a predetermined time period (i) between the receiving and the ascertaining or (ii) between the requesting and the ascertaining.
Submitted by: Kathy WangLast updated: about 4 years ago
Title Using Honeyclients to Detect New Attacks
Description
Honeyclients are systems that drive a piece of vulnerable client software to potentially malicious sites, and monitor system behavior for indicators of compromise. Each honeyclient is a virtual host, and drives applications such as web browsers to user-specified URLs, looking for signs of malicious behavior when accessing that URL. The malicious behavior is flagged via an integrity check capability, which monitors for changes in files, registry key values, and processes. Upon detection of suspicious behavior, the honeyclient virtual machine is suspended, a new clone is created, and the spidering process continues.
2 thumbs up 0 thumbs down
Annotations(2)