US2018077178A1PendingUtilityA1
Method and system for detecting malicious payloads
Est. expirySep 12, 2036(~10.1 yrs left)· nominal 20-yr term from priority
H04L 63/0245H04W 12/12H04L 63/1416H04L 63/1425G06F 21/56G06N 20/00G06N 5/022G06N 99/005
43
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Disclosed is an improved method, system, and computer program product for identifying malicious payloads. The disclosed approach identifies potentially malicious payload exchanges which may be associated with payload injection or root-kit magic key usage.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for detecting a malicious network payload, comprising:
collecting network traffic corresponding to communications within a network; extracting metadata from the network traffic for a client-server session; in a learning phase, identifying from the metadata any representative sequences for payloads sent between a client and a server for the client-server session; and in a monitoring phase, detecting for any client-server sequences corresponding to a payload that are different from the representative sequences identified in the learning phase.
2 . The method of claim 1 , wherein the representative sequences are identified on the basis of a unique combination of the server and a port, where baseline payload characteristics are identified for the unique combination of the server and the port.
3 . The method of claim 2 , further comprising:
receiving a first communication for the unique combination of the server and the port; setting the baseline payload characteristics in correspondence to the first communications; for an additional communication, comparing the additional communication against the baseline payload characteristics to obtain a similarity score, and identifying new baseline payload characteristics that corresponds to the additional communication if the similarity score is not within a threshold distance and a minimum number of sessions or time has elapsed.
4 . The method of claim 1 , wherein identification of the representative sequences in the learning phase is performed by constructing one or more models corresponding to baseline behavior for the client and the server.
5 . The method of claim 4 , wherein new normal client-server sequences are identified even after an initial learning phase by updating the one or more model.
6 . The method of claim 1 , wherein the monitoring phase is implemented by:
receiving a new communication for analysis; comparing an extracted sequence for the new communication against the representative sequences identified in the learning phase to generate a score; determining if the score exceeds a threshold; and identifying the new communication as a potential threat for malicious payload if the score exceeds the threshold.
7 . The method of claim 1 , wherein the metadata extracted from the network traffic comprises some or more of IP address information for the client and the server, payload information, quantity information for transferred data, duration of communications, or length of time delay between a client request and a server response.
8 . A system for detecting a malicious network payload, comprising:
a processor; a memory for holding programmable code; and wherein the programmable code includes instructions collecting network traffic corresponding to communications within a network; extracting metadata from the network traffic for a client-server session; in a learning phase, identifying from the metadata any representative sequences for payloads sent between a client and a server for the client-server session; and in a monitoring phase, detecting for any client-server sequences corresponding to a payload that are different from the representative sequences identified in the learning phase.
9 . The system of claim 7 , wherein the representative sequences are identified on the basis of a unique combination of the server and a port, where baseline payload characteristics are identified for the unique combination of the server and the port.
10 . The system of claim 9 , wherein the programmable code further includes instructions for:
receiving a first communication for the unique combination of the server and the port; setting the baseline payload characteristics in correspondence to the first communications; for an additional communication, comparing the additional communication against the baseline payload characteristics to obtain a similarity score, and identifying new baseline payload characteristics that corresponds to the additional communication if the similarity score is not within a threshold distance and a minimum number of sessions or time has elapsed.
11 . The system of claim 7 , wherein identification of the representative sequences in the learning phase is performed by constructing one or more models corresponding to baseline behavior for the client and the server.
12 . The system of claim 11 , wherein new normal client-server sequences are identified even after an initial learning phase by updating the one or more model.
13 . The system of claim 7 , wherein the monitoring phase is implemented by:
receiving a new communication for analysis; comparing an extracted sequence for the new communication against the representative sequences identified in the learning phase to generate a score; determining if the score exceeds a threshold; and identifying the new communication as a potential threat for malicious payload if the score exceeds the threshold.
14 . The system of claim 7 , wherein the metadata extracted from the network traffic comprises some or more of IP address information for the client and the server, payload information, quantity information for transferred data, duration of communications, or length of time delay between a client request and a server response.
15 . A computer program product embodied on a computer readable medium, the computer readable medium having stored thereon a sequence of instructions which, when executed by a processor, executes a method detecting a malicious network payload, comprising:
collecting network traffic corresponding to communications within a network; extracting metadata from the network traffic for a client-server session; in a learning phase, identifying from the metadata any representative sequences for payloads sent between a client and a server for the client-server session; and in a monitoring phase, detecting for any client-server sequences corresponding to a payload that are different from the representative sequences identified in the learning phase.
16 . The computer program product of claim 15 , wherein the representative sequences are identified on the basis of a unique combination of the server and a port, where baseline payload characteristics are identified for the unique combination of the server and the port.
17 . The computer program product of claim 16 , wherein the sequence of instructions which, when executed by a processor, further performs:
receiving a first communication for the unique combination of the server and the port; setting the baseline payload characteristics in correspondence to the first communications; for an additional communication, comparing the additional communication against the baseline payload characteristics to obtain a similarity score, and identifying new baseline payload characteristics that corresponds to the additional communication if the similarity score is not within a threshold distance and a minimum number of sessions or time has elapsed.
18 . The computer program product of claim 15 , wherein identification of the representative sequences in the learning phase is performed by constructing one or more models corresponding to baseline behavior for the client and the server.
19 . The computer program product of claim 18 , wherein new normal client-server sequences are identified even after an initial learning phase by updating the one or more model.
20 . The computer program product of claim 15 , wherein the monitoring phase is implemented by:
receiving a new communication for analysis; comparing an extracted sequence for the new communication against the representative sequences identified in the learning phase to generate a score; determining if the score exceeds a threshold; and identifying the new communication as a potential threat for malicious payload if the score exceeds the threshold.
21 . The computer program product of claim 15 , wherein the metadata extracted from the network traffic comprises some or more of IP address information for the client and the server, payload information, quantity information for transferred data, duration of communications, or length of time delay between a client request and a server response.Join the waitlist — get patent alerts
Track US2018077178A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.