Rapid7, Inc.
MONITORING SCAN ATTEMPTS IN A NETWORK
Last updated:
Abstract:
Disclosed herein are methods, systems, and processes for monitoring scan attempts in a network. A virtual security appliance with multiple ports is deployed in a network. One or more ports are obfuscated via the virtual security appliance to make the various ports appear to be closed. An address of the virtual security appliance within the network is modified, the several ports are adjusted to assume a predetermined profile, a network neighbor's profile is discovered and emulated, and a received connection attempt intended for the virtual security appliance is monitored.
Status:
Application
Type:
Utility
Filling date:
15 Mar 2021
Issue date:
16 Sep 2021