IP Library Granted Patent US 8,789,174
Granted Patent B1
US 8,789,174 · App. 12/798,854 · Granted Jul 22, 2014

Method and apparatus for examining network traffic and automatically detecting anomalous activity to secure a computer

Inventor: Prashant Gupta (Cheltenham, GB)
Assignee: Symantec Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,789,174
App. No.
12/798,854
Granted
Jul 22, 2014
Kind
B1
Abstract

A method and apparatus for examining network traffic and automatically detecting anomalous activity to secure a computer is described. In one embodiment, the method includes examining network traffic that is directed to at least one endpoint computer, accessing profile information associated with the at least one endpoint computer to determine confidence indicia associated with each portion of the network traffic, comparing the confidence indicia with heuristic information to identify anomalous activity for the at least one endpoint computer and communicating indicia of detection as to the anomalous activity to the at least one endpoint computer.

Claims (53)

1. A method for using one or more processors automatically detecting anomalous activity in memory to secure a computer, comprising:

examining at least one data segment of network traffic that is directed to at least one endpoint computer wherein examining network traffic comprises generating profile information for each of the at least one endpoint computer and wherein generating profile information comprises:

extracting features from the at least one data segment of network traffic;

defining file groupings based on the extracted features;

classifying the at least one data segment of network traffic into the file groupings using the extracted features; and

assigning confidence values to the file groupings;

accessing the profile information associated with the at least one endpoint computer, wherein the profile information indicates characteristics of non-anomalous network traffic;

computing confidence indicia for the at least one data segment of network traffic, wherein the confidence indicia are computed based on the accessed profile information and at least a portion of the at least one data segment of network traffic;

comparing the confidence indicia with heuristic information to identify anomalous network activity for the at least one endpoint computer; and

communicating indicia of detection as to the anomalous activity to the at least one endpoint computer.

2. The method of claim 1 , further comprising transforming the at least one data segment of network traffic and the heuristic information into the indicia of detection.

3. The method of claim 1 , wherein the characteristics of non-anomalous network traffic comprise characteristics of anomalous network traffic.

4. The method of claim 1 , wherein comparing the confidence indicia with the heuristic information further comprises:

receiving a file that is communicated to an endpoint computer of the at least one endpoint computer, wherein the file forms a portion of a file grouping;

identifying a confidence value for the communicated file; and

comparing the confidence value with a pre-defined threshold value, wherein the pre-defined threshold value is configured to identify the anomalous network activity, wherein the communicated file forms a portion of the anomalous network activity if the confidence value falls below the pre-defined threshold value.

5. The method of claim 4 , wherein identifying the confidence value further comprises adjusting the confidence value based on the heuristic information.

6. The method of claim 4 , further comprising performing a security scan on the communicated file.

7. The method of claim 6 , further comprising communicating scanned files to a backend computer for further analysis based on the security scan.

8. The method of claim 1 , wherein comparing the heuristic information with the confidence indicia further comprises applying the heuristic information to each file being communicated to the at least one endpoint computer.

9. A system for automatically detecting anomalous activity in memory to secure a computer, comprising:

one or more processors communicatively coupled to a network; wherein the one or more processors are configured to:

examine at least one data segment of network traffic that is directed to at least one endpoint computer;

extract features from the at least one data segment of network traffic;

define file groupings based on the extracted features;

classify the at least one data segment of network traffic into the file groupings using the extracted features; and

assign confidence values to the file groupings;

generate profile information, wherein the profile information is generated from the file groupings;

access profile information associated with the at least one endpoint computer, wherein the profile information indicates characteristics of non-anomalous network traffic;

compute confidence indicia for the at least one data segment of network traffic, wherein the confidence indicia are computed based on the accessed profile information and at least a portion of the at least one data segment of network traffic;

apply the heuristic information to the confidence indicia to identify anomalous network activity; and

communicate indicia of detection as to the anomalous network activity to the at least one endpoint computer.

10. The system of claim 9 , wherein the one or more processors are further configured to:

receive a file that is communicated to an endpoint computer of the at least one endpoint computer, wherein the file forms a portion of a file grouping; identify a confidence value for the communicated file; and compare the confidence value with a pre-defined threshold value, wherein the pre-defined threshold value is configured to identify the anomalous network activity, wherein the communicated file forms a portion of the anomalous network activity if the confidence value falls below the pre-defined threshold value.

11. A non-transitory computer-readable-storage medium comprising one or more processor-executable instructions that, when executed by at least one processor, cause the at least one processor to:

examine at least one data segment of network traffic that is directed to at least one endpoint computer;

extract features from the at least one data segment of network traffic;

define file groupings based on the extracted features;

classify the at least one data segment of network traffic into the file groupings using the extracted features; and

assign confidence values to the file groupings;

generate profile information, wherein the profile information is generated from the file groupings;

access profile information associated with the at least one endpoint computer, wherein the profile information indicates characteristics of non-anomalous network traffic;

compute confidence indicia for the at least one data segment of network traffic, wherein the confidence indicia are computed based on the accessed profile information and at least a portion of the at least one data segment of network traffic;

compare the confidence indicia with heuristic information to identify anomalous network activity for the at least one endpoint computer; and

communicate indicia of detection as to the anomalous network activity to the at least one endpoint computer.

12. The non-transitory computer-readable-storage medium of claim 11 , further comprising one or more processor-executable instructions that, when executed by the at least one processor, cause the at least one processor to:

receive a file that is communicated to an endpoint computer of the at least one endpoint computer, wherein the file forms a portion of a file grouping;

identify a confidence value for the communicated file; and

compare the confidence value with a pre-defined threshold value, wherein the pre-defined threshold value is configured to identify the anomalous network activity, wherein the communicated file forms a portion of the anomalous network activity if the confidence value falls below the pre-defined threshold value.

13. The non-transitory computer-readable-storage medium of claim 12 , further comprising one or more processor-executable instructions that, when executed by the at least one processor, cause the at least one processor to:

instruct security software to perform a security scan on the communicated file.

14. The non-transitory computer-readable-storage medium of claim 13 , further comprising one or more processor-executable instructions that, when executed by the at least one processor, cause the at least one processor to:

communicate scanned files to a backend computer for further analysis based on the security scan.

Assignments (6)
CHANGE OF NAME Recorded May 18, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 063697/0493 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Mar 5, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 052109/0186 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2010
From: GUPTA, PRASHANT
To: SYMANTEC CORPORATION
Reel/Frame 024285/0356 →