IP Library Granted Patent US 10,623,282
Granted Patent B2
US 10,623,282 · App. 15/171,930 · Granted Apr 14, 2020

System and method of detecting hidden processes by analyzing packet flows

Inventors: Khawar Deen (Sunnyvale, CA); Navindra Yadav (Cupertino, CA); Anubhav Gupta (Sunnyvale, CA); Shashidhar Gandham (Fremont, CA); Rohit Chandra Prasad (Sunnyvale, CA); Abhishek Ranjan Singh (Pleasanton, CA); Shih-Chun Chang (San Jose, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F16/122G06F16/137G06F16/162G06F16/17G06F16/173G06F16/174G06F16/1744G06F16/1748G06F16/235G06F16/2322G06F16/2365G06F16/248G06F16/24578G06F16/285G06F16/288G06F16/29G06F16/9535G06F21/53G06F21/552G06F21/566G06N20/00G06N99/00G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/2007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/145H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/10H04L67/1002H04L67/12H04L67/16H04L67/36H04L67/42H04L69/16H04L69/22H04W72/08H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595G06F2221/033G06F2221/2101G06F2221/2105G06F2221/2111G06F2221/2115G06F2221/2145H04L67/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,623,282
App. No.
15/171,930
Granted
Apr 14, 2020
Kind
B2
Abstract

A method includes capturing first data associated with a first packet flow originating from a first host using a first capture agent deployed at the first host to yield first flow data, capturing second data associated with a second packet flow originating from the first host from a second capture agent deployed outside of the first host to yield second flow data and comparing the first flow data and the second flow data to yield a difference. When the difference is above a threshold value, the method includes determining that a hidden process exists and corrective action can be taken.

Claims (39)

1. A method comprising:

capturing first data associated with a first packet flow originating from a first host using a first capture agent deployed at the first host to yield first flow data;

capturing second data associated with a second packet flow originating from the first host from a second capture agent deployed at a second host to yield second flow data, wherein the first capture agent is deployed at a first layer of a network and the second capture agent is deployed at a second layer of the network, wherein the first layer and the second layer are different layers;

comparing the first flow data and the second flow data to yield a difference;

when the difference is above a threshold value, yielding a determination, the determination including that the second packet flow includes a hidden process and the second packet flow was transmitted by a component that bypassed an operating stack of the first host; and

taking a corrective action based on the determination, the corrective action including isolating a container, isolating a virtual machine, or isolating the first host.

2. The method of claim 1 , wherein the first data and the second data comprise metadata associated respectively with the first packet flow and the second packet flow.

3. The method of claim 1 , wherein the first data comprises first packet content of the first packet flow and the second data comprise second packet content of the second packet flow.

4. The method of claim 1 , wherein the first flow data and the second flow data are captured at a collector.

5. The method of claim 1 , wherein a collector receives the first flow data and the second flow data and performs the step of comparing the first flow data and the second flow data.

6. The method of claim 1 , further comprising:

identifying the first host as a generator of the hidden process.

7. The method of claim 1 , wherein the first flow data and the second flow data comprise network data.

8. The method of claim 1 , further comprising:

predicting a presence of a malicious entity within the first host based on the determination.

9. The method of claim 1 , wherein the corrective action is shutting down the first host.

10. The method of claim 1 , wherein the corrective action includes one or more of limiting packets to and from the first host, requiring all packets to and from the first host to flow through the operating stack of the first host, or notifying an administrator.

11. A system comprising:

a processor; and

a non-transitory computer-readable storage medium storing instructions which, when executed by the processor, cause the processor to perform operations comprising:

capturing first data associated with a first packet flow originating from a first host using a first capture agent deployed at the first host to yield first flow data;

capturing second data associated with a second packet flow originating from the first host from a second capture agent deployed on a second host to yield second flow data, wherein the first capture agent is deployed at a first layer of a network and the second capture agent is deployed at a second layer of the network, wherein the first layer and the second layer are different layers;

comparing the first flow data and the second flow data to yield a difference;

when the difference is above a threshold value, yielding a determination, the determination including that the second packet flow was transmitted by a component that bypassed an operating stack of the first host and the second packet flow includes a hidden packet; and

taking a limiting action associated with a flow of packets to or from the first host based on the determination, the limiting action including isolating a container, isolating a virtual machine, or isolating the first host.

12. The system of claim 11 , wherein the first data and the second data comprise metadata associated respectively with the first packet flow and the second packet flow.

13. The system of claim 11 , wherein the first data comprises first packet content of the first packet flow and the second data comprise second packet content of the second packet flow.

14. The system of claim 11 , wherein the first flow data and the second flow data are captured at a collector.

15. The system of claim 11 , wherein a collector receives the first flow data and the second flow data and performs the step of comparing the first flow data and the second flow data.

16. The system of claim 11 , wherein the operations include predicting a presence of a malicious entity within first host or the second host based on determination.

17. The system of claim 11 , wherein the limiting action comprises one of limiting packets to and from the first host, requiring all packets to and from the first host to flow through the operating stack of the first host, shutting down the first host, or notifying an administrator.

18. A non-transitory computer-readable storage device that stores instructions which, when executed by a processor, cause the processor to perform further operations comprising:

capturing first data associated with a first packet flow originating from a first host using a first capture agent deployed at the first host to yield first flow data;

capturing second data associated with a second packet flow originating from the first host from a second capture agent deployed at a second host to yield second flow data, wherein the first capture agent is deployed at a first layer of a network and the second capture agent is deployed at a second layer of the network, wherein the first layer and the second layer are different layers;

comparing the first flow data and the second flow data to yield a difference;

when the difference is above a threshold value, yielding a determination, the determination including that the second packet flow was transmitted by a component that bypassed an operating stack of the first host and the second packet flow includes a hidden packet; and

taking a limiting action associated with a flow of packets to or from the first host based on the determination, the limiting action including isolating a container, isolating a virtual machine, or isolating the first host.

19. The non-transitory computer-readable storage device of claim 18 , wherein the first data and the second data comprise metadata associated respectively with the first packet flow and the second packet flow.

20. The non-transitory computer-readable storage device of claim 18 , wherein the first packet flow and the second packet flow are captured at a collector, the collector configured to perform the comparing of the first packet flow and the second packet flow and to yield the difference.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2016
From: DEEN, KHAWAR; YADAV, NAVINDRA; GUPTA, ANUBHAV; GANDHAM, SHASHIDHAR; PRASAD, ROHIT CHANDRA; SINGH, ABHISHEK RANJAN; CHANG, SHIH-CHUN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 040069/0665 →
Continuity (2)
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20160359879A1 · Dec 8, 2016
Cited By (1)
US 12,659,324