IP Library Granted Patent US 9,838,407
Granted Patent B1
US 9,838,407 · App. 15/085,551 · Granted Dec 5, 2017

Detection of malicious web activity in enterprise computer networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,838,407
App. No.
15/085,551
Granted
Dec 5, 2017
Kind
B1
Abstract

A processing device in one embodiment comprises a processor coupled to a memory and is configured to obtain internal log data of a computer network of an enterprise, to extract values of a plurality of designated internal features from the log data, to obtain additional data from one or more external data sources, and to extract values of a plurality of designated external features from the additional data. The extracted values are applied to a regression model based on the internal and external features to generate malicious activity risk scores for respective ones of a plurality of domains, illustratively external domains having fully-qualified domain names (FQDNs). A subset of the domains are identified based on their respective malicious activity risk scores, and one or more proactive security measures are taken against the identified subset of domains. The processing device may be implemented in the computer network or an associated network security system.

Claims (53)

1. A method comprising steps of:

obtaining internal log data of a computer network of an enterprise;

extracting values of a plurality of designated internal features from the log data;

obtaining additional data from one or more external data sources;

extracting values of a plurality of designated external features from the additional data;

applying the extracted values to a regression model based on the internal and external features to generate malicious activity risk scores for respective ones of a plurality of domains;

identifying a subset of the domains based on their respective malicious activity risk scores; and

taking one or more proactive security measures against the identified subset of domains;

wherein the malicious activity risk scores indicate likelihoods that the respective domains are associated with malware;

wherein the designated internal features comprise one or more communication related features, one or more domain structure related features, one or more uniform resource locator (URL) related features, and one or more user agent (UA) related features;

wherein the designated external features comprise one or more registration related features, one or more autonomous system related features, and one or more country related features; and

wherein the steps are performed by at least one processing device comprising a processor coupled to a memory.

2. The method of claim 1 wherein the plurality of domains comprise respective ones of a plurality of external fully-qualified domain name (FQDN) domains contacted by host devices of the enterprise.

3. The method of claim 1 wherein the internal log data comprises HTTP log data stored in security logs of the enterprise and wherein the one or more external data sources comprise at least one of a WHOIS data source, a hosting type data source, and an IP geolocation data source.

4. The method of claim 1 wherein the one or more communication related features comprise one or more of a total number of hosts, a total number of connections, an average, maximum or minimum number of connections per host, a total number of bytes sent, a total number of bytes received, an average, maximum or minimum ratio of total number of bytes sent and total number of bytes received on a per host basis, a total number of POST and GET connections, and an average, maximum or minimum ratio of POST and GET connections on a per host basis.

5. The method of claim 1 wherein the one or more domain structure related features comprise one or more of a domain name length, a number of domain levels, a number of sub-domains, and a top-level domain.

6. The method of claim 1 wherein the one or more URL related features comprise one or more of a total number of distinct URLs, an average, maximum or minimum path length per URL, an average, maximum or minimum path depth per URL, a total number of parameters, an average, maximum or minimum number of parameters per URL, an average, maximum or minimum number of values per parameter, a fraction of URLs with file name or extension, a total number of file names and extensions, a fraction of URLs with query strings, a fraction of URLs with fragments, a total number of fragments, and a fraction of domain URLs.

7. The method of claim 1 wherein the one or more UA related features comprise one or more of a total number of UAs, a ratio of distinct UAs over hosts, an average, maximum or minimum number of UAs per host, a fraction of connections without a UA, a fraction of unpopular UAs, an inverse average UA popularity, a dominant browser type, an average number of browsers per host, a dominant operating system (OS) type, and an average number of OSs per host.

8. The method of claim 1 wherein the designated internal features further comprise one or more result code related features including at least one of a fraction of connections having particular predetermined result codes, a number of connections having particular predetermined result codes, and a ratio of failing connections and successful connections.

9. The method of claim 1 wherein the designated internal features further comprise one or more referrer related features including at least one of a fraction of connections without a referrer, a number of distinct referrer domains, a ratio of distinct referrer domains and hosts, an average, maximum or minimum number of referrer domains per host, and a different referrer domain than itself indicator.

10. The method of claim 1 wherein the designated internal features further comprise one or more content type features including at least one of a number of distinct content types, and a fraction of content types in each of a plurality of categories.

11. The method of claim 1 wherein the one or more registration related features comprise one or more of a registration age, a registration validity, an update age, an update validity and a registration email category.

12. The method of claim 1 wherein the one or more autonomous system related features comprise one or more of autonomous system numbers (ASNs) of resolved domain IP addresses, and a number of distinct ASNs.

13. The method of claim 1 wherein the one or more country related features comprise one or more of countries of resolved domain IP addresses, and number of distinct countries.

14. The method of claim 1 wherein the designated external features further comprise one or more hosting type features including one or more of a free-hosting indicator, a dynamic domain name service (DNS) indicator, and a shortener indicator.

15. The method of claim 1 wherein the regression method is trained on a training set that comprises a plurality of unclassified domains and a plurality of domains previously classified as malicious domains but that excludes a global whitelist of popular domains.

16. The method of claim 1 wherein the regression model comprises one of a random forest model, a logistic regression model and a decision trees regression model.

17. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes said at least one processing device:

to obtain internal log data of a computer network of an enterprise;

to extract values of a plurality of designated internal features from the log data;

to obtain additional data from one or more external data sources;

to extract values of a plurality of designated external features from the additional data;

to apply the extracted values to a regression model based on the internal and external features to generate malicious activity risk scores for respective ones of a plurality of domains;

to identify a subset of the domains based on their respective malicious activity risk scores; and

to take one or more proactive security measures against the identified subset of domains;

wherein the malicious activity risk scores indicate likelihoods that the respective domains are associated with malware;

wherein the designated internal features comprise one or more communication related features, one or more domain structure related features, one or more uniform resource locator (URL) related features, and one or more user agent (UA) related features; and

wherein the designated external features comprise one or more registration related features, one or more autonomous system related features, and one or more country related features.

18. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

said at least one processing device being configured:

to obtain internal log data of a computer network of an enterprise;

to extract values of a plurality of designated internal features from the log data;

to obtain additional data from one or more external data sources;

to extract values of a plurality of designated external features from the additional data;

to apply the extracted values to a regression model based on the internal and external features to generate malicious activity risk scores for respective ones of a plurality of domains;

to identify a subset of the domains based on their respective malicious activity risk scores; and

to take one or more proactive security measures against the identified subset of domains;

wherein the malicious activity risk scores indicate likelihoods that the respective domains are associated with malware;

wherein the designated internal features comprise one or more communication related features, one or more domain structure related features, one or more uniform resource locator (URL) related features, and one or more user agent (UA) related features; and

wherein the designated external features comprise one or more registration related features, one or more autonomous system related features, and one or more country related features.

19. The apparatus of claim 18 wherein the designated internal features further comprise one or more referrer related features including at least one of a fraction of connections without a referrer, a number of distinct referrer domains, a ratio of distinct referrer domains and hosts, an average, maximum or minimum number of referrer domains per host, and a different referrer domain than itself indicator.

20. The apparatus of claim 18 wherein the apparatus is implemented in a network security system.

Assignments (21)
NOTICE OF PARTIAL TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN TRADEMARK RIGHTS AND PATENT RIGHTS RECORDED AT REEL/FRAME: 056098/0534 Recorded Jun 3, 2025
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: RSA SECURITY LLC
Reel/Frame 071484/0819 →
NOTICE OF PARTIAL TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN TRADEMARK RIGHTS AND PATENT RIGHTS RECORDED AT REEL/FRAME: 056096/0525 Recorded Jun 3, 2025
From: JPMORGAN CHASE BANK, N.A.
To: RSA SECURITY LLC
Reel/Frame 071482/0733 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2025
From: RSA SECURITY LLC
To: NETWITNESS SECURITY LLC
Reel/Frame 071495/0168 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 053666, FRAME 0767 Recorded Apr 29, 2021
From: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056095/0574 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 056096/0525 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 29, 2021
From: RSA SECURITY LLC
To: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
Reel/Frame 056098/0534 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN PATENTS RECORDED AT REEL 054155, FRAME 0815 Recorded Apr 29, 2021
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: RSA SECURITY LLC
Reel/Frame 056104/0841 →
PARTIAL RELEASE OF SECURITY INTEREST Recorded Nov 9, 2020
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054362/0008 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 7, 2020
From: EMC IP HOLDING COMPANY LLC
To: RSA SECURITY LLC
Reel/Frame 053717/0020 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054191/0287 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045482/0131) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 053701/0112 →
RELEASE OF SECURITY INTEREST IN CERTAIN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (049452/0223) Recorded Sep 3, 2020
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS AGENT
To: DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 054250/0372 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 054155/0815 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Sep 1, 2020
From: RSA SECURITY LLC
To: JEFFERIES FINANCE LLC
Reel/Frame 053666/0767 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 045482/0395 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Mar 1, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 045482/0131 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2017
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 041872/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2016
From: BOWERS, KEVIN D.
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040270/0864 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 5, 2016
From: OPREA, ALINA M.; LI, ZHOU; NORRIS, ROBIN
To: EMC CORPORATION
Reel/Frame 039946/0377 →