Detecting past intrusions and attacks based on historical network traffic information
Abstract
A device may receive information that identifies an attack signature for detecting an intrusion. The device may determine a device configuration that is vulnerable to the intrusion, may determine an endpoint device associated with the device configuration, and may determine a time period during which the endpoint device was associated with the device configuration. The device may determine an endpoint identifier associated with the endpoint device during the time period, and may identify network traffic information associated with the endpoint identifier during the time period. The device may apply the attack signature to the network traffic information, and may determine whether the endpoint device was subjected to the intrusion during the time period based on applying the attack signature to the network traffic information. The device may selectively perform an action based on determining whether the endpoint device was subjected to the intrusion.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method comprising:
identifying, by a device, information regarding temporary endpoint identifiers assigned to a first endpoint device; identifying, by the device and based on the temporary endpoint identifiers, network traffic information that includes information regarding data transmitted or received by the first endpoint device; determining, by the device and based on the network traffic information, that a second endpoint device sent repeated requests to the first endpoint device; determining, by the device, that the first endpoint device was subjected to an intrusion based on determining that the second endpoint device sent repeated requests to the first endpoint device; and performing, by the device, an action based on determining that the first endpoint device was subjected to the intrusion.
22 . The method of claim 21 , further comprising:
receiving information regarding a persistent endpoint identifier of the first endpoint device; and sending, based on the information regarding the persistent endpoint identifier, a request for mapping information,
where identifying the information regarding the temporary endpoint identifiers comprises:
receiving, as a response to the request for mapping information, the information regarding the temporary endpoint identifiers.
23 . The method of claim 21 , further comprising:
receiving information regarding a time period when the first endpoint device had a particular device configuration,
where identifying the information regarding the temporary endpoint identifiers comprises:
identifying the information regarding the temporary endpoint identifiers based on the time period when the first endpoint device had the particular device configuration.
24 . The method of claim 21 , where the temporary endpoint identifiers include:
a first temporary endpoint identifier assigned to the first endpoint device during a first time period, and a second temporary endpoint identifier assigned to the first endpoint device during a second time period.
25 . The method of claim 21 , where identifying the network traffic information comprises:
requesting, based on the temporary endpoint identifiers and from a traffic monitoring device, the network traffic information, and receiving, from the traffic monitoring device, the network traffic information.
26 . The method of claim 21 , further comprising:
applying an attack signature to the network traffic information,
where determining that the second endpoint device sent repeated requests to the first endpoint device comprises:
determining that the second endpoint device sent repeated requests to the first endpoint device based on applying the attack signature to the network traffic information.
27 . The method of claim 26 , further comprising:
receiving information identifying the attack signature before identifying the information regarding temporary endpoint identifiers.
28 . The method of claim 21 , further comprising:
identifying the action by searching a data structure using a persistent endpoint identifier of the first endpoint device.
29 . The method of claim 21 , where performing the action comprises:
providing, to a network device, an instruction to block traffic to or from the first endpoint device.
30 . A system comprising:
one or more device to:
identify information regarding temporary endpoint identifiers assigned to a first endpoint device;
identify, based on the temporary endpoint identifiers, network traffic information that includes information regarding data transmitted or received by the first endpoint device;
determine that the first endpoint device was subjected to an intrusion based on the network traffic information; and
perform an action based on determining that the first endpoint device was subjected to the intrusion.
31 . The system of claim 30 , where, when determining that the first endpoint device was subjected to the intrusion, the one or more processors are to:
determine, based on the network traffic information, that a second endpoint device sent repeated requests to the first endpoint device; and determine that the first endpoint device was subjected to the intrusion based on determining that the second endpoint device sent repeated requests to the first endpoint device.
32 . The system of claim 30 , where, when identifying the information regarding the temporary endpoint identifiers, the one or more processors are to:
identify the information regarding the temporary endpoint identifiers based on a persistent endpoint identifier of the first endpoint device.
33 . The system of claim 30 , where, when identifying the information regarding the temporary endpoint identifiers, the one or more processors are to:
identify the information regarding the temporary endpoint identifiers based on a time period when the first endpoint device had a particular device configuration.
34 . The system of claim 30 , where the one or more processors are further to:
receive information identifying a particular device configuration; and identify the first endpoint device based on the particular device configuration.
35 . The system of claim 30 , where, when determining that the first endpoint device was subjected to the intrusion, the one or more processors are to:
apply an attack signature to the network traffic information, and determine that that the first endpoint device was subjected to the intrusion based on applying the attack signature to the network traffic information.
36 . A non-transitory computer-readable medium storing instructions, the instructions comprising:
one or more instructions that, when executed by at least one processor, cause the at least one processor to:
identify information regarding temporary endpoint identifiers assigned to a first endpoint device;
identify, based on the temporary endpoint identifiers, network traffic information;
determine that the first endpoint device was subjected to an intrusion based on the network traffic information; and
perform an action based on determining that the first endpoint device was subjected to the intrusion.
37 . The non-transitory computer-readable medium of claim 36 , where the network traffic information includes information regarding data transmitted or received by the first endpoint device.
38 . The non-transitory computer-readable medium of claim 36 , where the one or more instructions, that cause the at least one processor to identify the information regarding the temporary endpoint identifiers, cause the at least one processor to:
identify the information regarding the temporary endpoint identifiers based on a time period when the first endpoint device had a particular device configuration.
39 . The non-transitory computer-readable medium of claim 38 , where the temporary endpoint identifiers include:
a first temporary endpoint identifier assigned to the first endpoint device during a first time period of the time period, and a second temporary endpoint identifier assigned to the first endpoint device during a second time period of the time period.
40 . The non-transitory computer-readable medium of claim 36 , where the one or more instructions, that cause the at least one processor to determine that the first endpoint device was subjected to the intrusion, cause the at least one processor to:
apply an attack signature to the network traffic information, and determine that that the first endpoint device was subjected to the intrusion based on applying the attack signature to the network traffic information.Join the waitlist — get patent alerts
Track US2018115571A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.