IP Library Granted Patent US 9,979,742
Granted Patent B2
US 9,979,742 · App. 15/286,643 · Granted May 22, 2018

Identifying anomalous messages

Inventors: Michael Mumcuoglu (Jerusalem, IL); Giora Engel (Mevasseret-Zion, IL); Eyal Firstenberg (Ramat HaSharon, IL)
Assignee: Palo Alto Networks (Israel Analytics) Ltd.
H04L63/1425G06F21/552G06F21/566H04L61/1511H04L63/0227H04L63/1416H04L63/1441H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,979,742
App. No.
15/286,643
Granted
May 22, 2018
Kind
B2
Abstract

A method for computer system forensics includes receiving an identification of an anomalous message transmitted by a host computer in a computer network comprising multiple host computers. Messages transmitted by the host computers are monitored so as to detect, for each monitored message, a respective process that initiated the message. Responsively to the identification, a forensic indicator is extracted of the respective process that initiated the anomalous message.

Claims (26)

1. A method for computer system forensics, comprising:

monitoring traffic passing through network switching elements in a computer network comprising multiple host computers;

identifying an anomalous message in the monitored traffic passing through network switching elements;

defining a filter responsive to the identified anomalous message;

transmitting the filter to respective monitoring programs running on the multiple host computers;

monitoring messages transmitted by the multiple host computers, by the respective monitoring programs, so as to detect messages matching the defined filter;

detecting, by the respective monitoring programs on the multiple host computers, for each message matching the defined filter, a respective process that initiated the message;

sampling by a forensic analyzer of the computer network from the multiple host computers, lists of messages matching the defined filter and corresponding processes that initiated the message;

responsively to the sampled lists from the multiple host computers, extracting a forensic indicator characteristic of the respective processes that initiated the matching messages; and

applying preventive actions to processes matching the extracted forensic indicator, on the multiple host computers.

2. The method according to claim 1 , wherein identifying the anomalous message comprises determining that the anomalous message is associated with a specified destination.

3. The method according to claim 2 , wherein detecting a respective process that initiated the message comprises configuring a filter on the host computers to detect the respective process that initiates the messages that are associated with the specified destination.

4. The method according to claim 1 , wherein detecting a respective process that initiated the message comprises detecting calls to a specified application program interface (API).

5. The method according to claim 1 , wherein detecting a respective process that initiated the message comprises detecting Domain Name System (DNS) lookups.

6. Apparatus for computer system forensics, comprising:

an interface, which is configured to receive an identification of an anomalous message transmitted by a host computer in a computer network comprising multiple host computers; and

a hardware processor, which is coupled to cause the multiple host computers to monitor messages transmitted by the host computers so as to detect, for each monitored message matching the received identification, a respective process that initiated the message, and which is configured to sample from the multiple host computers, lists of messages matching the received identification and corresponding processes that initiated the message, to extract, responsively to the sampled lists, a forensic indicator characteristic of the respective process that initiated the matching message, and to apply preventive actions to processes matching the extracted forensic indicator, on the multiple host computers.

7. The apparatus according to claim 6 , wherein the identification indicates that the anomalous message is associated with a specified destination.

8. The apparatus according to claim 7 , wherein the processor is coupled to configure a filter on the host computers to detect the respective process that initiates the messages that are associated with the specified destination.

9. The apparatus according to claim 6 , wherein the processor is configured to cause the host computers to monitor the messages by detecting calls to a specified application program interface (API).

10. The apparatus according to claim 6 , wherein the processor is configured to cause the host computers to monitor the messages by detecting Domain Name System (DNS) lookups.

11. A computer software product, comprising a non-transitory computer-readable medium in which program instructions are stored, which instructions, when read by a computer, cause the computer to receive an identification of an anomalous message transmitted by a host computer in a computer network comprising multiple host computers, to cause the multiple host computers to monitor messages transmitted by the host computers so as to detect, for each monitored message matching the received identification, a respective process that initiated the message, to sample from the multiple host computers, lists of messages matching the received identification and corresponding processes that initiated the message, to extract, responsively to the sampled lists, a forensic indicator characteristic of the respective process that initiated the matching message, and to apply preventive actions to processes matching the extracted forensic indicator, on the multiple host computers.

12. The product according to claim 11 , wherein the identification indicates that the anomalous message is associated with a specified destination.

13. The product according to claim 12 , wherein the instructions cause the computer to configure a filter on the host computers to detect the respective process that initiates the messages that are associated with the specified destination.

14. The product according to claim 11 , wherein the instructions cause the computer to cause the host computers to monitor the messages by detecting calls to a specified application program interface (API).

15. The product according to claim 11 , wherein the instructions cause the computer to cause the host computers to monitor the messages by detecting Domain Name System (DNS) lookups.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
To: PALO ALTO NETWORKS INC.
Reel/Frame 068823/0886 →
CHANGE OF NAME Recorded Mar 18, 2018
From: LIGHT CYBER LTD.
To: PALO ALTO NETWORKS (ISRAEL 2) LTD.
Reel/Frame 045628/0287 →
CHANGE OF NAME Recorded Mar 18, 2018
From: PALO ALTO NETWORKS (ISRAEL 2) LTD.
To: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
Reel/Frame 045628/0291 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 6, 2016
From: MUMCUOGLU, MICHAEL; ENGEL, GIORA; FIRSTENBERG, EYAL
To: LIGHT CYBER LTD.
Reel/Frame 039953/0913 →
Continuity (3)
Division 14758966
Provisional Application 61752984 · Jan 16, 2013
Related Publication 20170026398A1 · Jan 26, 2017