IL273277A

Improved system, method, and computer program product for securing a computer system from threats introduced by malicious transparent network devices

Abstract

This record has no abstract on file.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

15 claims: 3 independent, 12 dependent

  1. 1
    CLAIMS 1. A network security system for detecting MAC’less/transparent devices, the system comprising:a data repository aka DB, operative to accumulate fingerprint data indicative of expected physical level characteristics for each of plural types of switch-device links (aka link types) interconnecting a switch and a hardware device, wherein at least one pair of links (i.e. at least 2 instances of links) of different types differ from one another at least with respect to the chipset residing in the respective device connected to the respective switch by each respective link;apparatus for reading physical level characteristics of links in at least one network to be protected;and an output device configured to generate alerts of possible presence of a transparent device along at least one link if the physical level characteristics of said at least one link, as read by said apparatus, is anomalous relative to said fingerprint data stored in said data repository.
  2. 14
    A network security method for detecting MAC’less/transparent devices, the method comprising:In a data repository, accumulating fingerprint data indicative of expected physical level characteristics for each of plural types of switch-device links interconnecting a switch and a hardware device, wherein at least one pair of links of different types differ from one another at least with respect to the chipset residing in the respective device connected to the respective switch by each respective link;reading physical level characteristics of links in at least one network to be protected;and 02708376\2-01 generating alerts of possible presence of a transparent device along at least one link if the physical level characteristics of said at least one link, as read, is anomalous relative to said fingerprint data stored in said data repository.
  3. 15
    A computer program product, comprising a non-transitory tangible computer readable medium having computer readable program code embodied therein, said computer readable program code adapted to be executed to implement a network security method for detecting MAC’less/transparent devices, the method comprising:In a data repository, accumulating fingerprint data indicative of expected physical level characteristics for each of plural types of switch-device links interconnecting a switch and a hardware device, wherein at least one pair of links of different types differ from one another at least with respect to the chipset residing in the respective device connected to the respective switch by each respective link;reading physical level characteristics of links in at least one network to be protected;and generating alerts of possible presence of a transparent device along at least one link if the physical level characteristics of said at least one link, as read, is anomalous relative to said fingerprint data stored in said data repository. 02708376\2-01