Rapid7, Inc.
MONITORING SCAN ATTEMPTS IN A NETWORK

Last updated:

Abstract:

Disclosed herein are methods, systems, and processes for monitoring scan attempts in a network. A virtual security appliance with multiple ports is deployed in a network. One or more ports are obfuscated via the virtual security appliance to make the various ports appear to be closed. An address of the virtual security appliance within the network is modified, the several ports are adjusted to assume a predetermined profile, a network neighbor's profile is discovered and emulated, and a received connection attempt intended for the virtual security appliance is monitored.

Status:
Application
Type:

Utility

Filling date:

15 Mar 2021

Issue date:

16 Sep 2021