STARdeck™
STARDECK (Systematic Tracking of Attackers using Routing Data and Event Correlation Knowledge) is a patented attack attribution infrastructure (US Patent No: 8,806,634) that provides answers to two questions of interest to those investigating the origin and nature of network attacks:
- Level 1 Attribution: True Origins of IP Packets
- Level 2 Attribution: Controlling Mechanisms of Attacks
Given a possibly spoofed, single IP packet, determine the possible IP addresses of the machines that could have generated the packet.
Determine if the actions of machine of origin (Level 1 attribution), are being caused by or controlled by activity at other machine(s) and identify evidence about such machine(s).