IP Library Patent Application 13693226
Patent Application
App. No. 13/693,226

Cyber Behavior Analysis and Detection Method, System and Architecture

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/693,226
Abstract

A scalable cyber-security system, method and architecture for the identification of malware and malicious behavior in a computer network. Host flow, host port usage, host information and network data at the application, transport and network layers are aggregated from within the network and correlated to identify a network behavior such as the presence of malicious code.

Claims (24)

1 . A method for analyzing network, transport and application protocols in a computer network to identify a predetermined network behavior comprising the steps of:

monitoring and logging a port usage in a first host in a computer network,

monitoring and logging a set of first host information,

monitoring and logging a set of data activities in the network for a predetermined change in the first host information and in a first host data flow, and,

generating an alert to a user based on a correlation between the logged port usage, the logged first host information and the logged first host data flow.

2 . The method of claim 1 wherein the first host information is selected from at least one member of the group of information consisting of an IP address used by the first host, an operating system used by the first host, a service being provided by the first host, an IP protocol used by the first host, a TCP port used by the first host, a UDP port used by the first host, connected host information with which the first host communicates, services used by the first host, a TCP port contacted by the first host, and a UDP port contacted by the first host.

3 . The method of claim 1 wherein the data logged consists of data selected from at least one of the group consisting of a timestamp, an event or alert type, a rating, a network layer protocol, a transport layer protocol, an application layer protocol, a source IP address, a destination IP address, a source and destination TCP and UDP port, an ICMP type and code, a packet header field, a predetermined policy violation, a use of a predetermined application service, an IP time-to-live, a number of bytes and packets sent by a source host and a destination host for a connection, a prevention action performed, a connection or session ID, a decoded payload data, an application request and response, and a state-related information set.

4 . A device for analyzing network, transport and application protocols in a computer network to identify a predetermined activity comprising:

a sensor platform comprising at least one sensor configured to collect and export a predetermined data structure from within the firewall of the network comprising aggregated data about a network host, flow and address block, and comprising a sensor control processor,

a correlator server configured to support at least one sensor control processor,

an optical I/O module,

an SRAM processing module, and,

a DRAM processing module.

5 . The device of claim 4 wherein at least one of the I/O modules, SRAM modules or DRAM modules is comprised of a combined memory array and field programmable gate array device comprising a field programmable gate array (FPGA),

an access lead network electrically coupled and proximate to the FPGA,

a plurality of external memories electrically coupled and proximate to the access lead network, and,

wherein the FPGA can independently access each of the plurality of external memories via the access lead network without use of an address/data bus.

6 . The device of claim 4 wherein the SRAM module comprises a plurality of interconnect ports and a plurality of independent SRAM memories and the DRAM module comprises a plurality of interconnect ports, at least one independent DRAM memory, and at least one SRAM memory.

7 . The device of claim 4 further comprising a hash spectrum detector and a spectral Bloom filter.

8 . The device of claim 4 further comprising a TCP flow rectifier configured to re-order and align a TCP flow content into a predetermined format.

9 . The device of claim 8 where the predetermined format comprises TCP payload information and a header that identifies a data flow.

10 . The device of claim 8 wherein the TCP flow rectifier module is configured for input header processing/flow ID extraction processing, TCP flow state and gap record management processing, buffer bypass TCP payload packet processing, DRAM buffer processing, buffer playout manager processing and output header generation processing.

11 . The device of 8 wherein the TCP flow rectifier is configured to output TCP payload streams in interleaved blocks for multiple flows simultaneously.

12 . The device of claim 8 wherein the TCP flow rectifier is comprised of a DRAM-based buffer memory configured for storing payload segments, and an SRAM-based flow state memory for storing a TCP flow state and a TCP gap records.

Assignments (7)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2015
From: ISC8 INC.
To: CYBER ADAPT, INC.
Reel/Frame 035789/0679 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2015
From: PFG IP LLC
To: ISC8, INC.
Reel/Frame 035621/0746 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2014
From: PARTNERS FOR GROWTH III, L.P.
To: PFG IP LLC
Reel/Frame 033793/0508 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2014
From: ISC8 INC.
To: PFG IP LLC
Reel/Frame 033777/0371 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 7, 2013
From: RHODES, KEITH
To: ISC8 INC.
Reel/Frame 029575/0344 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2012
From: DEERMAN, JAMES
To: ISC8 INC.
Reel/Frame 029427/0960 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2012
From: RHODES, KEITH; JOLL, BILL
To: ISC8 INC.
Reel/Frame 029426/0033 →