METHOD AND APPARATUS FOR DETECTING HIDDEN NETWORK COMMUNICATION CHANNELS OF ROOTKIT TOOLS
Patent №
US 7,665,136
Granted
2010-02-16
Filed 2005
Owner
SYMANTEC CORPORATION
Lab
—
AI components
3
kr · planning · hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
11271327
Methods and apparatuses for detecting hidden network channels of rootkit tools are described. In one embodiment, critical endpoint events detected at an endpoint computer system are selectively logged to an endpoint database. Also, critical network events associated with the endpoint computer system and detected on a network are selectively logged to a gateway database. Periodically some or all of the entries in the endpoint database are compared to entries in the gateway database. Entries detected at the network but not detected at the endpoint computer system are presumed indicative of hidden network channels of rootkit tools.
AI classification
Ownership
SYMANTEC CORPORATION
assignment · 172310368
Assignors
SZOR, PETER
On an employer assignment, the assignors are typically the inventors.