IP Library Granted Patent US 9,565,208
Granted Patent B2
US 9,565,208 · App. 14/644,166 · Granted Feb 7, 2017

System and method for detecting network intrusions using layered host scoring

Inventors: Oskar Ibatullin (San Jose, CA); Ryan James Prenger (Oakland, CA); Nicolas Beauchesne (Miami Beach, FL); Karl Matthew Lynn (Winter Garden, FL); Oliver Kourosh Tavakoli (Monte Sereno, CA)
Assignee: Vectra Networks, Inc.
H04L63/145H04L63/1433H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,565,208
App. No.
14/644,166
Granted
Feb 7, 2017
Kind
B2
Abstract

Approaches for detecting network intrusions, such as malware infection, Trojans, worms, or bot net mining activities includes: identifying one or more threat detections in session datasets, the session datasets corresponding to network traffic from a plurality of hosts; determining a layered detection score, the layered detection score corresponding to a certainty score and threat score; determining a layered host score, the layered host score corresponding to a certainty score and threat score; and generating alarm data comprising the layered detection score and the layered host score. In some embodiments, the network traffic may be received passively through a network switch; for example, by “tapping” the switch. Other additional objects, features, and advantages of the invention are described in the detailed description, figures and claims.

Claims (51)

1. A method for generating layered host scores, comprising:

identifying one or more computer contaminate detections by analyzing one or more session datasets, the session datasets corresponding to network traffic from a plurality of hosts;

generating host certainty score data that corresponds to a confidence that a host is compromised by one or more computer contaminants;

generating host threat score data that corresponds to a potential harm from the one or more computer contaminants compromising the host; and

storing the host certainty score data and the host threat score data as a layered detection score in a database, wherein the layered detection score is generated by comprising:

combining a first detection certainty score data for a first detection type and a second detection certainty score data for a second detection type into a combined host certainty score;

combining a first detection threat score for the first detection type and a second detection threat score for the second detection type into a combined host threat score; and

combining the combined host certainty score with the combined host threat score.

2. The method of claim 1 , further comprising:

generating detection certainty score data that corresponds to a confidence that one or more computer contaminant detections are valid.

3. The method of claim 2 , wherein the host certainty score data is generated based at least in part on the detection certainty score data.

4. The method of claim 2 , wherein detection certainty score data older than an expiration limit is expired.

5. The method of claim 1 , further comprising:

generating detection threat score data that corresponds to a potential harm from the one or more computer contaminants.

6. The method of claim 5 , wherein the host threat score data is generated based at least in part on the detection threat score data.

7. The method of claim 1 , wherein the network traffic is received passively through a network switch.

8. The method of claim 1 , wherein detection certainty score data comprises of combining individual instances of detections for contaminants of a same type.

9. The method of claim 1 , wherein detection threat score data comprises of combining individual instances of detections for contaminants of a same type.

10. The method of claim 1 , wherein the layered detection score is generated based at least in part on analyzing an effect of the host threat score data and host certainty over time.

11. system for generating layered host scores, comprising:

a computer processor to execute a set of program code instructions;

a memory to hold the program code instructions, in which the program code instructions comprises program code to: identify one or more computer contaminate detections by analyzing one or more session datasets, the session datasets corresponding to network traffic from a plurality of hosts; generate host certainty score data that corresponds to a confidence that a host is compromised by one or more computer contaminants; generate host threat score data that corresponds to a potential harm from the one or more computer contaminants compromising the host; and store the host certainty score data and the host threat score data as a layered detection score in a database, wherein the layered detection score is generated by comprising:

combining a first detection certainty score data for a first detection type and a second detection certainty score data for a second detection type into a combined host certainty score;

combining a first detection threat score for the first detection type and a second detection threat score for the second detection type into a combined host threat score; and

combining the combined host certainty score with the combined host threat score.

12. The system of claim 11 , in which the program code instructions further comprises program code to generate detection certainty score data that corresponds to a confidence that one or more computer contaminant detections are valid.

13. The system of claim 12 , wherein the host certainty score data is generated based at least in part on the detection certainty score data.

14. The system of claim 12 , wherein detection certainty score data older than an expiration limit is expired.

15. The system of claim 11 , in which the program code instructions further comprises program code to generate detection threat score data that corresponds to a potential harm from the one or more computer contaminants.

16. The system of claim 15 , wherein the host threat score data is generated based at least in part on the detection threat score data.

17. The system of claim 11 , wherein the network traffic is received passively through a network switch.

18. The method of claim 11 , wherein detection certainty score data comprises of combining individual instances of detections for contaminants of a same type.

19. The method of claim 11 , wherein detection threat score data comprises of combining individual instances of detections for contaminants of a same type.

20. The method of claim 11 , wherein the layered detection score is generated based at least in part on analyzing an effect of the host threat score data and host certainty over time.

21. A computer program product embodied on a non-transitory computer readable medium, the non-transitory computer readable medium having stored thereon a sequence of instructions which, when executed by a processor causes the processor to execute a method for generating layered host scores, the method comprising:

identifying one or more computer contaminate detections by analyzing one or more session datasets, the session datasets corresponding to network traffic from a plurality of hosts;

generating host certainty score data that corresponds to a confidence that a host is compromised by one or more computer contaminants;

generating host threat score data that corresponds to a potential harm from the one or more computer contaminants compromising the host; and

storing the host certainty score data and the host threat score data as a layered detection score in a database, wherein the layered detection score is generated by comprising:

combining a first detection certainty score data for a first detection type and a second detection certainty score data for a second detection type into a combined host certainty score;

combining a first detection threat score for the first detection type and a second detection threat score for the second detection type into a combined host threat score; and

combining the combined host certainty score with the combined host threat score.

22. The computer program product of claim 21 , wherein the non-transitory computer readable medium further comprises instructions which, when executed by the processor, causes the processor to execute the method further comprising: generating detection certainty score data that corresponds to a confidence that one or more computer contaminant detections are valid.

23. The computer program product of claim 22 , wherein the host certainty score data is generated based at least in part on the detection certainty score data.

24. The computer program product of claim 22 , wherein detection certainty score data older than an expiration limit is expired.

25. The computer program product of claim 21 , wherein the non-transitory computer readable medium further comprises instructions which, when executed by the processor, causes the processor to execute the method further comprising: generating detection threat score data that corresponds to a potential harm from the one or more computer contaminants.

26. The computer program product of claim 25 , wherein the host threat score data is generated based at least in part on the detection threat score data.

27. The computer program product of claim 21 , wherein the network traffic is received passively through a network switch.

28. The method of claim 21 , wherein detection certainty score data comprises of combining individual instances of detections for contaminants of a same type.

29. The method of claim 21 , wherein detection threat score data comprises of combining individual instances of detections for contaminants of a same type.

30. The method of claim 21 , wherein the layered detection score is generated based at least in part on analyzing an effect of the host threat score data and host certainty over time.

Assignments (6)
SECURITY INTEREST Recorded Oct 29, 2024
From: VECTRA AI, INC.
To: AB PRIVATE CREDIT INVESTORS LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 069061/0588 →
CHANGE OF NAME Recorded Sep 20, 2024
From: VECTRA NETWORKS, INC.
To: VECTRA AI, INC.
Reel/Frame 069013/0452 →
RELEASE OF SECURITY INTEREST Recorded Mar 19, 2021
From: SILVER LAKE WATERMAN FUND, L.P., AS AGENT
To: VECTRA AI, INC.
Reel/Frame 055656/0351 →
CHANGE OF NAME Recorded Nov 4, 2019
From: VECTRA NETWORKS, INC.
To: VECTRA AI, INC.
Reel/Frame 050925/0991 →
SECURITY INTEREST Recorded Mar 13, 2019
From: VECTRA AI, INC.
To: SILVER LAKE WATERMAN FUND, L.P., AS AGENT
Reel/Frame 048591/0071 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2016
From: IBATUILLIN, OSKAR; PRENGER, RYAN JAMES; BEAUCHESNE, NICOLAS; LYNN, KARL MATTHEW; TAVAKOLI, OLIVER KOUROSH
To: VECTRA NETWORKS, INC.
Reel/Frame 039743/0759 →
Continuity (2)
Provisional Application 61951102 · Mar 11, 2014
Related Publication 20150264061A1 · Sep 17, 2015