IP Library Granted Patent US 9,641,550
Granted Patent B2
US 9,641,550 · App. 14/991,957 · Granted May 2, 2017

Network protection system and method

Inventors: Ron Kraitsman (Petach Tikva, IL); Alex Milstein (Raanana, IL); Aviv Raff (Kiryat Ono, IL); David Matot (Kiryat Ono, IL)
Assignee: Radware, Ltd.
H04L63/1491G06F17/30864G06F21/554H04L63/1408H04L63/1416H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,641,550
App. No.
14/991,957
Granted
May 2, 2017
Kind
B2
Abstract

Systems and methods for protecting at least one client from becoming part of at least one botnet by monitoring and analyzing botnet communications to and from criminal servers and identifying at least one botnet attack on at least one client. The system may comprise virtual machines deliberately infected with malicious content and operable to record botnet communications to and from criminal servers. The virtual machines are in communication with a processing unit configured to index data collected. Data related to the prevalence of cyber threats may be presented to users in response to queries.

Claims (25)

1. A method for use in a remote intelligence gathering system operable to provide intelligence to at least one network manager for protecting at least one asset from becoming part of at least one botnet,

said intelligence comprising information relating to potential security threats to said at least one asset,

said remote intelligence gathering system comprising at least one communication unit configured to receive data queries from said at least one network manager and to send said intelligence in response to said data queries;

the at least one asset having at least one client address and the botnet being controlled by at least one criminal server having at least one bot address, the botnet operable to communicate data between said at least one client address and said at least one bot address, the method comprising:

sending, by said network manager, at least one query relating to characteristics of said at least one asset;

receiving, by said network manager, said intelligence pertaining to the characteristics of said at least one asset;

defining automatically, by said network manager, said at least one asset which requires botnet protection, said at least one asset having at least one asset address;

processing traffic, by said network manager, sent to and from said at least one asset address and said at least one bot address;

identifying, by said network manager, at least one bot attack pertaining to said at least one asset; and

generating, by said network manager, an indication associated with said at least one bot attack.

2. The method of claim 1 , wherein defining automatically said at least one asset comprises defining at least one IP range representing said asset.

3. The method of claim 1 , wherein defining said at least one asset comprises defining at least one network interface representing said asset.

4. The method of claim 1 , further comprising gathering said intelligence by collecting potential bot data.

5. The method of claim 4 , wherein collecting potential bot data comprises:

exposing at least one honeypot asset having at least one honeypot address to said traffic;

monitoring honeypot-traffic, said honeypot-traffic traveling between said at least one honeypot address and said at least one bot address; and

identifying bot-traffic patterns from said honeypot-traffic, said bot-traffic patterns indicative of at least one bot-infected asset.

6. The method of claim 5 , wherein processing traffic sent to and from said at least one asset address and said at least one bot address comprises:

classifying said traffic into classified-traffic, said classifying performed according to at least one IP range representing said at least one asset and according to said bot-traffic patterns.

7. The method of claim 2 , wherein processing traffic sent to and from said at least one asset address and said at least one bot address comprises:

classifying said traffic into classified-traffic, said classifying performed according to said at least one IP range representing said at least one asset and according to bot-traffic patterns.

8. The method of claim 7 , wherein identifying said at least one bot attack pertaining to said asset comprises filtering said classified-traffic according to said at least one asset address.

9. The method of claim 1 , wherein generating said indication associated with said at least one bot attack comprises displaying said at least one bot attack pertaining to said at least one asset.

10. The method of claim 1 , further comprising mitigating said at least one bot attack.

11. The method of claim 1 , wherein said intelligence comprises at least one item selected from: at least one current IP address of said criminal server, at least one future IP address of said criminal server, at least one current URL of said criminal server, at least one future URL of said criminal server, at least one current domain name of said criminal server, at least one future domain name of said criminal server, at least one geographical location of said security threat; at least one vulnerability exploited by said malicious software, time stamps and combinations thereof.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2022
From: SECULERT LTD.
To: RADWARE LTD.
Reel/Frame 059647/0285 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2022
From: RADWARE LTD.
To: CNP LTD.
Reel/Frame 059335/0684 →
RELEASE OF REEL/FRAME 037287/0062 Recorded Feb 7, 2017
From: CITY NATIONAL BANK
To: SECULERT
Reel/Frame 041644/0877 →
SECURITY INTEREST Recorded Jul 5, 2016
From: SECULERT LTD.; SECULERT, INC.
To: CITY NATIONAL BANK
Reel/Frame 039077/0128 →
Continuity (5)
Continuation 13810450
Provisional Application 61366168 · Jul 21, 2010
Provisional Application 61411006 · Nov 8, 2010
Provisional Application 61482223 · May 4, 2011
Related Publication 20160127413A1 · May 5, 2016