IP Library Granted Patent US 9,961,095
Granted Patent B2
US 9,961,095 · App. 14/214,088 · Granted May 1, 2018

System and method for extracting and preserving metadata for analyzing network communications

Inventors: Gene Savchuk (Bethesda, MD); Anubhav Arora (Bethesda, MD)
Assignee: FIDELIS CYBERSECURITY, INC.
H04L63/1425H04L43/026H04L43/12H04L63/0227H04L63/1416H04L63/1433H04L43/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,961,095
App. No.
14/214,088
Granted
May 1, 2018
Kind
B2
Abstract

Systems and methods are provided for advanced persistent threat detection on a network. The method includes capturing data packets from a network and performing layered session decoding on the captured packets. Metadata is extracted from the decoded packets and is stored for analysis. Analysis of the metadata is used to detect advanced persistent threats on the network. The system includes a network and a processor coupled to the network. The processor is configured to capture data packets from the network and perform layered session decoding on the captured packets. Metadata is extracted by the processor and stored in a memory coupled to the processor. The metadata may then be analyzed to detect advanced persistent threats on the network.

Claims (43)

1. A computer-implemented method for protecting a computer network from electronic communication containing malicious code in the form of an advanced persistent threat, comprising executing on a processor the steps of:

capturing the electronic communication as it is received by a network via the processor to provide captured data;

determining a packet type for the captured data;

decoding the data packets to provide decoded packet data;

reassembling a communication session from the decoded packet data to provide a reassembled communication session;

performing layered session decoding on the reassembled communication session while the electronic communication is in progress to provide decoded session data;

extracting session metadata from the decoded session data while the electronic communication is in progress;

extract packet metadata from the decoded packet data while the electronic communication is in progress;

storing the session metadata and packet metadata; and

analyzing the session metadata and packet metadata to detect the advanced persistent threat on the network.

2. The method of claim 1 , further comprising the processor capturing data from a network proxy server.

3. The method of claim 1 , further comprising the processor capturing data from an SMTP hub.

4. The method of claim 1 , further comprising the processor extracting the session metadata in accordance with a configuration.

5. The method of claim 1 , further comprising the processor utilizing application protocol decoders when performing the layered session decoding.

6. The method of claim 1 , further comprising the processor utilizing format decoders when performing the layered session decoding.

7. A system for protecting a computer network from electronic communication containing malicious code in the form of an advanced persistent threat, comprising:

a network;

a processor coupled to the network and configured to;

capture the electronic communication from the network as it is received to provide captured data;

determining a packet type for data packets of the captured data;

decoding the data packets to provide decoded packet data;

reassembling a communication session from the decoded packet data to provide a reassembled communication session;

perform layered session decoding on the reassembled communication session while the electronic communication is in progress to provide decoded session data; and

extract session metadata from the decoded session data while the electronic communication is in progress;

extract packet metadata from the decoded packet data while the electronic communication is in progress;

a memory coupled to the processor for storing the session metadata and packet metadata; and

wherein, the session metadata and packet metadata may be analyzed to detect the advanced persistent threat on the network.

8. The system of claim 7 , wherein the processor is further configured to capturing data from a network proxy server of the network.

9. The system of claim 7 , wherein the processor is further configured to capturing data from an SMTP hub of the network.

10. The system of claim 7 , further comprising the processor extracting the session metadata in accordance with a configuration.

11. The system of claim 7 , further comprising application protocol decoders for performing the layered session decoding.

12. The system of claim 7 , further comprising format decoders for performing the layered session decoding.

13. A non-transitory computer readable medium for protecting a computer network from electronic communication containing malicious code in the form of an advanced persistent threat, comprising instructions stored thereon, that when executed by a processor, perform the steps of:

detecting an advanced persistent threat by:

capturing the electronic communication from a network as it is received via a processor to provide captured data;

determining a packet type for the captured data;

decoding the data packets to provide decoded packet data;

reassembling a communication session from the decoded packet data to provide a reassembled communication session;

performing layered session decoding on the reassembled communication session while the electronic communication is in progress to provide decoded session data;

extracting session metadata from the decoded session data while the electronic communication is in progress;

extract packet metadata from the decoded packet data while the electronic communication is in progress; and

analyzing the session metadata and packet metadata to detect the advanced persistent threat on the network.

14. The non-transitory computer readable medium embodying a computer program product of claim 13 , wherein the advanced persistent threat detection program is further configured to extract the sessions metadata in accordance with a configuration.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2023
From: FIDELIS CYBERSECURITY, INC.
To: RUNWAY GROWTH FINANCE CORP.
Reel/Frame 065041/0694 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2023
From: RUNWAY GROWTH FINANCE CORP. (F/K/A RUNWAY GROWTH CREDIT FUND INC.)
To: FIDELIS SECURITY LLC
Reel/Frame 064455/0804 →
SECURITY INTEREST Recorded Jun 3, 2021
From: FIDELIS CYBERSECURITY, INC.
To: RUNWAY GROWTH CREDIT FUND INC.
Reel/Frame 056434/0248 →
RELEASE OF SECURITY INTEREST Recorded Dec 17, 2019
From: OBSIDIAN AGENCY SERVICES, INC, IN ITS CAPACITY AS COLLATERAL AGENT
To: FIDELIS CYBERSECURITY, INC. (FORMERLY KNOWN AS GENERAL DYNAMICS FIDELIS CYBERSECURITY SOLUTIONS, INC.)
Reel/Frame 051309/0772 →
CHANGE OF NAME Recorded Jul 28, 2015
From: GENERAL DYNAMICS FIDELIS CYBERSECURITY SOLUTIONS, INC.
To: FIDELIS CYBERSECURITY, INC.
Reel/Frame 036192/0267 →
SECURITY INTEREST Recorded May 4, 2015
From: GENERAL DYNAMICS FIDELIS CYBERSECURITY SOLUTIONS, INC.
To: OBSIDIAN AGENCY SERVICES, INC.
Reel/Frame 035559/0332 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY NAME PREVIOUSLY RECORDED AT REEL: 035210 FRAME: 0228. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 9, 2015
From: GENERAL DYNAMICS ADVANCED INFORMATION SYSTEMS, INC.
To: GENERAL DYNAMICS FIDELIS CYBERSECURITY SOLUTIONS, INC.
Reel/Frame 035389/0671 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2015
From: GENERAL DYNAMICS ADVANCED INFORMATION SYSTEMS, INC.
To: GENERAL DYNAMICS FIDELIS CYBER SECURITY SOLUTIONS, INC.
Reel/Frame 035210/0228 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 14, 2014
From: SAVCHUK, GENE; ARORA, ANUBHAV
To: GENERAL DYNAMICS ADVANCED INFORMATION SYSTEMS, INC.
Reel/Frame 032447/0209 →
Continuity (1)
Related Publication 20150264072A1 · Sep 17, 2015