IP Library Patent Application 14643931
Patent Application
App. No. 14/643,931

SYSTEM AND METHOD FOR DETECTING INTRUSIONS THROUGH REAL-TIME PROCESSING OF TRAFFIC WITH EXTENSIVE HISTORICAL PERSPECTIVE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/643,931
Abstract

A real-time perspective engine that can detect network intrusions by accepting network packets as input, organizing the packets, and processing them through a series of detection schemes to identify potentially malicious network behavior. The detection system can implement stateless detection that detects network threats in real-time. The detection system can implement state-full detection that detects network threats which in small amounts may appear innocuous but over time evidence a network attack or malicious activity.

Claims (39)

1 . A system for detecting threats on a network, comprising:

a flow engine having a parsing module to separate received network packets into one or more session datasets, wherein a session dataset corresponds to one or more flows;

a near-real-time processing engine that performs state-based detection on the one or more session datasets to generate preliminary detection data;

a real-time processing engine that performs stateless detection on the one or more session datasets to generate preliminary detection data; and

a scoring engine that generates detection data scores by analyzing the preliminary detection data.

2 . The system of claim 1 , further comprising: a host analysis engine that generates host identifications for a plurality of hosts in a network and manages host scores for the plurality of hosts, wherein the received network packets correspond to the plurality of hosts.

3 . The system of claim 2 , wherein a reporting engine periodically checks whether a host's score has changed, and updates the host score.

4 . The system of claim 1 further comprising:

a correlation engine configured to receive the preliminary detection data and determine whether to send the preliminary detection data to the scoring engine or store the preliminary detection data in an accumulation data structure.

5 . The system of claim 1 , further comprising:

a reporting engine having a rate limiting module that generates a single point data item to be written to a host database.

6 . The system of claim 1 , wherein the flow engine uses a zero-copy driver to receive the network packets.

7 . The system of claim 1 , wherein state-based detection identifies data from the one or more session datasets to hold in a accumulation data structure.

8 . A computer -implemented method for detecting threats on a network, comprising:

separating received network packets into one or more session datasets, wherein a session dataset corresponds to one or more flows;

performing state-based detection on the one or more session datasets to generate preliminary detection data;

performing stateless detection on the one or more session datasets to generate preliminary detection data; and

generating detection data scores by analyzing the preliminary detection data.

9 . The method of claim 8 , further comprising: generating host identifications for a plurality of hosts in a network and manages host scores for the plurality of hosts, wherein the received network packets correspond to the plurality of hosts.

10 . The method of claim 9 , wherein a reporting engine periodically checks whether a host's score has changed, and updates the host score.

11 . The method of claim 8 further comprising:

receiving the preliminary detection data and determining whether to send the preliminary detection data to a scoring engine or storing the preliminary detection data in an accumulation data structure.

12 . The method of claim 8 , further comprising:

generating a single point data item to be written to a host database using a rate limiting module.

13 . The method of claim 8 , wherein a flow engine uses a zero-copy driver to receive the network packets.

14 . The method of claim 8 , wherein state-based detection identifies data from the one or more session datasets to hold in a accumulation data structure.

15 . A computer program product embodied on a non-transitory computer usable medium, the non-transitory computer readable medium having stored thereon a sequence of instructions which, when executed by a processor causes the processor to execute a method for detecting network intrusions, the method comprising:

separating received network packets into one or more session datasets, wherein a session dataset corresponds to one or more flows;

performing state-based detection on the one or more session datasets to generate preliminary detection data;

performing stateless detection on the one or more session datasets to generate preliminary detection data; and

generating detection data scores by analyzing the preliminary detection data.

16 . The computer program product of claim 15 , wherein the non-transitory computer readable medium further comprises instructions which, when executed by the processor, causes the processor to execute the method further comprising:

generating host identifications for a plurality of hosts in a network and manages host scores for the plurality of hosts, wherein the received network packets correspond to the plurality of hosts.

17 . The computer program product of claim 15 , wherein a reporting engine periodically checks whether a host's score has changed, and updates the host score.

18 . The computer program product of claim 15 , wherein the non-transitory computer readable medium further comprises instructions which, when executed by the processor, causes the processor to execute the method further comprising:

receiving the preliminary detection data and determining whether to send the preliminary detection data to a scoring engine or storing the preliminary detection data in an accumulation data structure.

19 . The computer program product of claim 15 , wherein the non-transitory computer readable medium further comprises instructions which, when executed by the processor, causes the processor to execute the method further comprising:

generating a single point data item to be written to a host database using a rate limiting module.

20 . The computer program product of claim 15 , wherein state-based detection identifies data from the one or more session datasets to hold in a accumulation data structure.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Mar 19, 2021
From: SILVER LAKE WATERMAN FUND, L.P., AS AGENT
To: VECTRA AI, INC.
Reel/Frame 055656/0351 →
CHANGE OF NAME Recorded Nov 4, 2019
From: VECTRA NETWORKS, INC.
To: VECTRA AI, INC.
Reel/Frame 050925/0913 →
SECURITY INTEREST Recorded Mar 13, 2019
From: VECTRA AI, INC.
To: SILVER LAKE WATERMAN FUND, L.P., AS AGENT
Reel/Frame 048591/0071 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2016
From: TAVAKOLI, OLIVER KOUROSH; HUANG, PANNING; VENABLE, JEFFREY CHARLES, SR.
To: VECTRA NETWORKS, INC.
Reel/Frame 040806/0376 →