System and method for identifying suspicious network traffic
Abstract
The disclosure includes a method that includes receiving network traffic having a first plurality of packets that each indicate a first packet source and a first packet destination; determining an analysis host destination for each of the first plurality of packets such that the packets are distributed among a plurality of analysis hosts with communications between a given source-destination pair being sent to the same analysis host; encapsulating the first plurality of packets to generate a second plurality of encapsulated packets having the first plurality of packets as a second packet payload; and sending the second plurality of encapsulated packets to respective analysis host destinations.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method, comprising:
encapsulating a first packet in a second packet, the first packet including a first packet payload and indicating a first packet source and a first packet destination, the second packet including the first packet as a second packet payload, the second packet indicating a second packet destination corresponding to an analysis host destination and a second packet source indicating a false source associated with a network link indicates a communication channel device between the first packet source and the first packet destination, wherein the analysis host destination is based at least in part on the first packet source and the first packet destination such that the second packet is routed to a particular analysis host of a set of analysis hosts wherein communications between a first packet source-destination pair are sent to the same analysis host; and providing the second packet to an analysis host as a result of the second packet destination being indicated in a header of the encapsulated second packet.
2 . The computer-implemented method of claim 1 , further comprising identifying abnormal network traffic based at least in part on the second packet destination as indicated in a header of the second packet and the second packet payload.
3 . The computer-implemented method of claim 2 , further comprising:
determining, based at least in part on the identified abnormal traffic, a first portion of the first packet, and a second portion of the second packet that a message included in the first packet payload corresponds to a conversation between the first packet source and the second packet source; converting the conversation including the message to a log; and providing the log to a security intelligence platform.
4 . The computer-implemented method of claim 2 , further comprising prohibiting the identified suspicious network traffic, within a core network from being provided to a border network via an internet connection by one or more respective layers of firewalls.
5 . The computer-implemented method of claim 1 , further comprising receiving the first packet from a split, wherein the split duplicated network traffic of communications between an end user and an interne endpoint that are connected by a network that comprises a firewall and a router.
6 . The computer-implemented method of claim 1 , further comprising:
receiving the first packet, the first packet encoded with a first communication protocol; detecting the first communication protocol is incompatible with the second packet destination; and encoding the encapsulated packet with a second communication protocol different from the first communication protocol.
7 . The computer-implemented method of claim 1 , wherein the at least one computing device acts as a reverse proxy and distributes network or application traffic across a number of servers or other target devices.
8 . A system, comprising:
one or more processors; and memory that stores computer-executable instructions that, as a result of execution, cause the one or more processors to: obtain a first packet; determine an analysis host destination based at least in part on the first packet source and the first packet destination; encapsulate a first packet within a second packet; wherein:
the first packet includes a first packet payload and a first header indicating a first packet source and a first packet destination;
the encapsulated second packet includes a second packet payload comprising at least a portion of the first packet payload and the second packet includes a second header indicating a second packet destination corresponding to an analysis host destination and a second packet source, the second packet source corresponding to a false source associated with a network link indicates a communication channel device between the first packet source and the first packet destination; and
provide the encapsulated packet to the analysis host based at least in part on the second packet destination.
9 . The system of claim 8 , wherein the instructions further include instructions that, as a result of execution by the one or more processors, further cause the system to identify a characteristic of suspicious network traffic based at least in part on the second packet destination.
10 . The system of claim 9 , wherein the instructions further include instructions that, as a result of execution by the one or more processors, further cause the system to prevent the suspicious network traffic, identified by the characteristic, within an edge network comprising at least two network splits.
11 . The system of claim 8 , wherein the instructions further include instructions that, as a result of execution by the one or more processors, further cause the system to send communications between a pair of devices to the analysis host based at least in part on a header in the encapsulated packet indicating the pair of devices.
12 . The system of claim 8 , wherein the encapsulated second packet includes a payload of an additional packet and the payload of the first packet.
13 . The system of claim 8 , wherein the instructions further include instructions that, as a result of execution by the one or more processors, further cause the system to:
receive the first packet, the first packet encoded with a first communication protocol; and encode the encapsulated packet with a second communication protocol different from the first communication protocol.
14 . The system of claim 8 , wherein the analysis host implements one or more analysis services, wherein the one or more analysis services:
determine, based at least a portion of the encapsulated packet and at least a portion of the first packet, that a message included in the first packet payload corresponds to a session between the first packet source and the second packet source; and convert the session including the message to a log.
15 . The system of claim 14 , wherein the one or more analysis services further provide the log to a security intelligence platform.
15 . A non-transitory computer-readable storage medium having stored thereon instructions that, upon execution by a computing device, cause the computing device at least to:
at least one computing device implementing one or more services, wherein the one or more services: receive a first packet, the first packet including a first packet payload and indicating a first packet source and a first packet destination; generate a second packet by encapsulating a portion of the first packet, wherein the second packet indicates a second packet destination corresponding to an analysis host destination and a second packet source indicating a false source associated with a network link indicative of a communication channel node between the first packet source and the first packet destination, wherein the analysis host destination is based at least in part on the first packet source and the first packet destination; and provide the encapsulated packet to an analysis host based at least in part on the second packet destination.
16 . The computer-readable storage medium of claim 15 , wherein the analysis host destination is determined such that the second packet is routed to a particular analysis host of a set of analysis hosts wherein previous communications between the first packet destination and the first packet source were assigned to the particular analysis host.
17 . The computer-readable storage medium of claim 15 , wherein the second packet combines the portion of the first packet with a portion of an additional packet.
18 . The computer-readable storage medium of claim 15 , comprising further instructions that, upon execution by the at least one computing device, cause the computing device at least to identify a characteristic of potential malicious network traffic based at least in part on the network link.
19 . The computer-readable storage medium of claim 18 , comprising further instructions that, upon execution by the at least one computing device, cause the at least one computing device at least to insulate the identified potential malicious network traffic within at least one of a border network, an edge network, or a core network by one or more respective layers of firewalls.
20 . The computer-readable storage medium of claim 15 , comprising further instructions that, upon execution by the at least one computing device, cause the at least one computing device at least to receive the first packet from a split, wherein the split duplicated network traffic of communications between an end user and an internet endpoint that are connected by a network that comprises a firewall.Join the waitlist — get patent alerts
Track US2021006580A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.