IP Library Granted Patent US 7,461,404
Granted Patent B2
US 7,461,404 · App. 10/701,400 · Granted Dec 2, 2008

Detection of unauthorized access in a network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,461,404
App. No.
10/701,400
Granted
Dec 2, 2008
Kind
B2
Abstract

A system for detecting network intrusions and other conditions in a network is described. The system includes a plurality of collector devices that are disposed to collect data and statistical information on packets that are sent between nodes on a network. An aggregator device is disposed to receive data and statistical information from the plurality of collector devices. The aggregator device produces a connection table that maps each node on the network to a record that stores information about traffic to or from the node. The aggregator runs processes that determine network events from aggregating of anomalies into network events.

Claims (57)

1. A computer implemented method comprising:

retrieving connection pairs from a connection table for a host that is attempting to gain access to another host in a networked computer system;

determining whether that one host attempting to gain access has accessed the other host accessed previously; and if that one host has not accessed the other host previously,

determining if other anomalies in the connection patterns of each host exist to establish an event severity level indicating a likelihood that the host attempting to access another host is attempting an unauthorized access,

determining whether conditions exit to decrease the severity level assigned to an event; and if an event is still indicated,

sending an event warning message with a determined level of severity to an operator.

2. The method of claim 1 wherein determining other anomalies includes determining whether previous connection patterns of the hosts indicate that the hosts are in roles that are not normal for the hosts.

3. The method of claim 1 determining other anomalies includes determining whether the connection request uses the transport control protocol (TCP).

4. The method of claim 3 determining other anomalies includes determining whether the connection requests use ports that are not well-known indicating a possible Trojan virus attack.

5. The method of claim 3 determining other anomalies includes using heuristics to provide an indication to an operator that elevates severity of a possible unauthorized access event.

6. The method of claim 1 wherein determining other anomalies includes determining whether the connection requests use ports that have not been used previously.

7. The method of claim 1 wherein determining other anomalies includes determining if several short connections occurred over a short time period by examining connection behavior between two hosts based on connection pattern data retrieved from the connection table.

8. The method of claim 1 further comprising:

determining whether conditions exist to decrease the severity assigned to an event.

9. The method of claim 8 wherein determining whether conditions exist to decrease the severity assigned to an event, comprises:

determining whether the hosts are in roles that commonly access each other.

10. The method of claim 8 wherein determining whether conditions exist to decrease the severity assigned to an event, comprises:

determining whether the host being connected to commonly receives connections from new hosts.

11. A computer program product embodied on a computer readable medium for detecting unauthorized access in a computer network comprising instructions for causing a computing device to:

retrieve connection pairs from a connection table for a host that is attempting to gain access to another host;

determine whether that one host attempting to gain access has accessed the other host accessed previously; and if that one host has not accessed the other host previously,

determine if other anomalies in the connection patterns of each host exist to establish an event severity level indicating a likelihood that the host attempting to access another host is attempting an unauthorized access,

determining whether conditions exit to decrease the severity level assigned to an event; and if an event is still indicated,

sending an event warning message with a determined level of severity to an operator.

12. The computer program product of claim 11 wherein instructions to determine other anomalies includes instructions to determine whether previous connection patterns of the hosts indicate that the hosts are in roles that are not normal for the hosts.

13. The computer program product of claim 11 wherein instructions to determine other anomalies includes instructions to determine whether the connection request uses the transport control protocol (TCP).

14. The computer program product of claim 11 wherein instructions to determine other anomalies includes instructions to determine whether the connection requests use ports that are not well-known indicating a possible Trojan virus attack.

15. The computer program product of claim 11 wherein instructions to determine includes instructions to use heuristics to provide an indication to an operator that elevates severity of a possible unauthorized access event.

16. The computer program product of claim 11 wherein instructions to determine other anomalies includes instructions to determine whether the connection requests use ports that have not been used previously.

17. The computer program product of claim 11 wherein instructions to determine other anomalies includes instructions to determine if several short connections occurred over a short time period by examining connection behavior between two hosts based on connection pattern data retrieved from the connection table.

18. The computer program product of claim 11 further comprising instructions to:

determine whether conditions exist to decrease the severity assigned to an event.

19. The computer program product of claim 18 wherein instructions to determine whether conditions exist to decrease the severity assigned to an event, comprises instructions to:

determine whether the hosts are in roles that commonly access each other.

20. The computer program product of claim 18 wherein instructions to determine whether conditions exist to decrease the severity assigned to an event, comprises instructions to:

determine whether the host being connected to commonly receives connections from new hosts.

21. Apparatus comprising:

a processing device;

a memory;

a computer readable medium storing a computer program product for detecting unauthorized access in a computer network comprising instructions for causing the device to:

retrieve connection pairs from a connection table for a host that is attempting to gain access to another host;

determine whether that one host attempting to gain access has accessed the other host accessed previously; and if that one host has not accessed the other host previously,

determine if other anomalies in the connection patterns of each host exist to establish an event severity level indicating a likelihood that the host attempting to access another host is attempting an unauthorized access,

determining whether conditions exit to decrease the severity level assigned to an event; and if an event is still indicated,

sending an event warning message with a determined level of severity to an operator.

22. The apparatus of claim 21 wherein instructions to determine other anomalies includes instructions to determine whether previous connection patterns of the hosts indicate that the hosts are in roles that are not normal for the hosts.

23. The apparatus of claim 21 wherein instructions to determine other anomalies includes instructions to determine whether the connection request uses the transport control protocol (TCP).

24. The apparatus of claim 21 wherein instructions to determine other anomalies includes instructions to determine whether the connection requests use ports that are not well-known indicating a possible Trojan virus attack.

25. The apparatus of claim 21 wherein instructions to determine includes instructions to use heuristics to provide an indication to an operator that elevates severity of a possible unauthorized access event.

26. The apparatus of claim 21 wherein instructions to determine other anomalies includes instructions to determine whether the connection requests use ports that have not been used previously.

27. The apparatus of claim 21 wherein instructions to determine other anomalies includes instructions to determine if several short connections occurred over a short time period by examining connection behavior between two hosts based on connection pattern data retrieved from the connection table.

28. The apparatus of claim 21 further comprising instructions to:

determine whether conditions exist to decrease the severity assigned to an event.

29. The apparatus of claim 28 wherein instructions to determine whether conditions exist to decrease the severity assigned to an event, comprises instructions to:

determine whether the hosts are in roles that commonly access each other.

30. The apparatus of claim 28 wherein instructions to determine whether conditions exist to decrease the severity assigned to an event, comprises instructions to:

determine whether the host being connected to commonly receives connections from new hosts.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 11, 2023
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC; RIVERBED HOLDINGS, INC.
Reel/Frame 064673/0739 →
CHANGE OF NAME Recorded Feb 18, 2022
From: RIVERBED TECHNOLOGY, INC.
To: RIVERBED TECHNOLOGY LLC
Reel/Frame 059232/0551 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0169 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0108 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 27, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 058593/0046 →
SECURITY INTEREST Recorded Dec 10, 2021
From: RIVERBED TECHNOLOGY LLC (FORMERLY RIVERBED TECHNOLOGY, INC.); ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS U.S. COLLATERAL AGENT
Reel/Frame 058486/0216 →
PATENT SECURITY AGREEMENT Recorded Oct 27, 2021
From: RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 057943/0386 →
PATENT SECURITY AGREEMENT SUPPLEMENT - SECOND LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 057810/0559 →
PATENT SECURITY AGREEMENT SUPPLEMENT - FIRST LIEN Recorded Oct 14, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 057810/0502 →
RELEASE OF SECURITY INTEREST IN PATENTS RECORED AT REEL 056397, FRAME 0750 Recorded Oct 13, 2021
From: MACQUARIE CAPITAL FUNDING LLC
To: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
Reel/Frame 057983/0356 →
SECURITY INTEREST Recorded May 26, 2021
From: RIVERBED HOLDINGS, INC.; RIVERBED TECHNOLOGY, INC.; ATERNITY LLC
To: MACQUARIE CAPITAL FUNDING LLC
Reel/Frame 056397/0750 →
PATENT SECURITY AGREEMENT Recorded Mar 5, 2021
From: RIVERBED TECHNOLOGY, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 055514/0249 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CONVEYING PARTY NAME PREVIOUSLY RECORDED ON REEL 035521 FRAME 0069. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST IN PATENTS. Recorded Jun 2, 2015
From: JPMORGAN CHASE BANK, N.A.
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035807/0680 →
SECURITY INTEREST Recorded May 1, 2015
From: RIVERBED TECHNOLOGY, INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 035561/0363 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Apr 28, 2015
From: BARCLAYS BANK PLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 035521/0069 →
PATENT SECURITY AGREEMENT Recorded Dec 27, 2013
From: RIVERBED TECHNOLOGY, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 032421/0162 →
RELEASE OF PATENT SECURITY INTEREST Recorded Dec 26, 2013
From: MORGAN STANLEY & CO. LLC, AS COLLATERAL AGENT
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 032113/0425 →
SECURITY AGREEMENT Recorded Dec 20, 2012
From: RIVERBED TECHNOLOGY, INC.; OPNET TECHNOLOGIES, INC.
To: MORGAN STANLEY & CO. LLC
Reel/Frame 029646/0060 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2009
From: MAZU NETWORKS, LLC
To: RIVERBED TECHNOLOGY, INC.
Reel/Frame 022542/0800 →
CHANGE OF NAME Recorded Mar 30, 2009
From: MAZU NETWORKS, INC.
To: MAZU NETWORKS, LLC
Reel/Frame 022460/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2004
From: DUDFIELD, ANNE ELIZABETH; POLETTO, MASSIMILIANO ANTONIO; WEBER, DANIEL
To: MAZU NETWORKS, INC.
Reel/Frame 015491/0833 →