Abstract: Disclosed is a device, system and method for detecting a Network Address Translation (“NAT”) gateway on a network. According to some embodiments of the present invention a detector including a network communication module may transmit one or more interrogation packets to a suspected NAT gateway.
Type:
Grant
Filed:
May 24, 2007
Date of Patent:
August 28, 2012
Assignee:
Forescout Technologies Inc.
Inventors:
Oren Nechushtan, Gil Friedrich, Oded Comay
Abstract: A method and a system for providing security to a network by at least identifying an unauthorized user who is attempting to gain access to a node on the network, and preferably by then actively blocking that unauthorized user from further activities. Detection is facilitated by the unauthorized user providing a “mark”, or specially crafted false data, which the unauthorized user gathers during the information collection stage performed before an attack. The mark is designed such that any attempt by the unauthorized user to use such false data results in the immediate identification of the unauthorized user as hostile, and indicates that an intrusion of the network is being attempted. Preferably, further access to the network is then blocked by diverting traffic from the unauthorized user to a secure zone, where the activities of the unauthorized user can be contained without damage to the network.
Type:
Grant
Filed:
November 29, 1999
Date of Patent:
March 26, 2002
Assignee:
Forescout Technologies Inc.
Inventors:
Oded Comay, Doron Shikmoni, Yehezkel Yeshurun, Oded Amir