US2019044961A1PendingUtilityA1

System and methods for computer network security involving user confirmation of network connections

Assignee: CISCO TECH INCPriority: Feb 27, 2015Filed: Oct 5, 2018Published: Feb 7, 2019
Est. expiryFeb 27, 2035(~8.6 yrs left)· nominal 20-yr term from priority
H04L 63/1425H04L 63/1416H04L 63/0227
39
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods for detecting anomalies in network traffic and providing notification to the users of the computers that generated the network traffic for confirmation of the activities that resulted in the network traffic are described herein. According to particular embodiments, the system is configured to collect data regarding network activity (e.g., via sensors), generate inquiries to users regarding that activity, receive the user's response to those inquiries, and provide the user's response along with the network activity to a security analyst.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for monitoring a data communication network, comprising the steps of:
 collecting network communication metadata relating to a communication between a client and a server on a network;   based the communication metadata, determining that further information is needed regarding a server identified from the communication metadata;   querying a user associated with the client involved in the communication for further information about the connection with the server identified from the communication metadata;   receiving a user response to the query; and   storing the user response in a database in association with at least some of the communication metadata corresponding to the server identified from the communication metadata for use in evaluating a security risk of past, present, or subsequent connections to that server by users of the data communication network.   
     
     
         2 . The method of  claim 1 , wherein the communication metadata is selected from the group comprising: domain, IP address, port, application, duration of connection, frequency of connection, time of connection, number of bytes transferred. 
     
     
         3 . The method of  claim 1 , wherein the communication metadata corresponds to a communication session between the client and the server, the communication session comprising an exchange of one or more data packets sent between the client and the server. 
     
     
         4 . The method of  claim 1 , wherein the step of determining that a server may present a security risk comprises accessing data correlating the identity of the server involved in the communication with security characteristics of previously identified servers. 
     
     
         5 . The method of  claim 4 , wherein the data correlating the identity of the server involved in the communication comprises “previously seen” data obtained from a separate network security system. 
     
     
         6 . The method of  claim 1 , wherein the step of determining that further information is needed regarding a server identified from the communication metadata comprises determining one or more of the following characteristics regarding the server: (a) that the server presents a known security risk to the network, (b) that the server has not been seen in previous communications on the network, (c) that characteristics of the communication between the client and the server exhibits characteristics indicative of possible security risk. 
     
     
         7 . The method of  claim 1 , wherein the step of querying the user for information comprises querying the user for an indication of intention to connect to the particular server identified in the communication metadata. 
     
     
         8 . The method of  claim 1 , wherein the step of querying the user for information comprises eliciting context information from the user as to characteristics of the connection between the client and the server useful by a security analyst in assessing security risk of the server. 
     
     
         9 . The method of  claim 8 , wherein context information includes but is not limited to one or more of the following: whether the server is on a black list of known nefarious servers, whether the server is on white list of previously-approved servers, whether a particular application on the server is expected to execute, an expected duration of connection to the server, an expected frequency of connection to the server, whether use of a particular port in the communication protocol was expected by the user, whether a connection to the server at a particular time of day was expected, the role of the user. 
     
     
         10 . The method of  claim 1 , wherein the user responses are used in connection with prestored data obtained by logging of information derived from one or more prior communications with the particular server, to enable a security analyst to analyze historical traffic data with the particular server and use that historical traffic data to assess a security risk for the particular server. 
     
     
         11 . The method of  claim 1 , wherein the query to the user is communicated to the user by one or more of the following communication mechanisms: executing a browser script to generate a user interface for displaying information to the user and/or receiving user input; executing a stand-alone application for generating a user interface for displaying information to the user and/or receiving user input; providing a text message to the user with information about the query; providing an email to the user with information about the query. 
     
     
         12 . The method of  claim 1 , further comprising the step of generating an alert for communication to a security analyst in response to a determination that the server identified in the communication possesses characteristics that satisfy one or more terms of a security policy stored in the database. 
     
     
         13 . The method of  claim 12 , wherein the security policy comprises data corresponding to one or more of the following data items: a destination IP address for the server; an application identifier; a port identifier associated with the destination IP address; one or more permissions data items corresponding to IP address, application identifier, duration of connection, time of connection, frequency of connection, number of bytes transferred. 
     
     
         14 . The method of  claim 12 , further comprising the step of storing a user engagement policy in the database containing data for use in determining an appropriate manner of communication with a user. 
     
     
         15 . An apparatus comprising:
 a communication interface configured to enable communications in a data communication network;   a memory configured to store data in a database;   at least one processor coupled to the communication interface and the memory, wherein the processor is configured to:
 obtain network communication metadata relating to a communication between a client and a server on a network; 
 based the communication metadata, determine that further information is needed regarding a server identified from the communication metadata; 
 query a user associated with the client involved in the communication for further information about the connection with the server identified from the communication metadata; 
 receive a user response to the query; and 
 store the user response in the database in association with at least some of the communication metadata corresponding to the server identified from the communication metadata for use in evaluating a security risk of past, present, or subsequent connections to that server by users of the data communication network. 
   
     
     
         16 . The apparatus of  claim 15 , wherein the communication metadata is selected from the group comprising: domain, IP address, port, application, duration of connection, frequency of connection, time of connection, number of bytes transferred. 
     
     
         17 . The apparatus of  claim 15 , wherein the processor is configured to determine that a server may present a security risk by accessing data correlating the identity of the server involved in the communication with security characteristics of previously identified servers. 
     
     
         18 . One or more non-transitory storage media encoded with instructions that, when executed by a processor, cause the processor to perform operations including:
 collecting network communication metadata relating to a communication between a client and a server on a network;   based the communication metadata, determining that further information is needed regarding a server identified from the communication metadata;   querying a user associated with the client involved in the communication for further information about the connection with the server identified from the communication metadata   receiving a user response to the query; and   storing the user response in a database in association with at least some of the communication metadata corresponding to the server identified from the communication metadata for use in evaluating a security risk of past, present, or subsequent connections to that server by users of the data communication network.   
     
     
         19 . The non-transitory storage media of  claim 18 , wherein the communication metadata is selected from the group comprising: domain, IP address, port, application, duration of connection, frequency of connection, time of connection, number of bytes transferred. 
     
     
         20 . The non-transitory storage media of  claim 18 , wherein the instructions for determining that a server may present a security risk comprise instructions for accessing data correlating the identity of the server involved in the communication with security characteristics of previously identified servers.

Join the waitlist — get patent alerts

Track US2019044961A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.