IP Library Granted Patent US 10,454,792
Granted Patent B2
US 10,454,792 · App. 15/342,818 · Granted Oct 22, 2019

Apparatus and method for utilizing fourier transforms to characterize network traffic

Inventors: Matthew S. Wood (Salt Lake City, UT); Joseph H. Levy (Eagle Mountain, UT)
Assignee: SYMANTEC CORPORATION
H04L43/04G06F21/55H04L41/142H04L43/026H04L43/028H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,454,792
App. No.
15/342,818
Granted
Oct 22, 2019
Kind
B2
Abstract

A non-transitory computer readable storage medium, comprising executable instructions to collect network traffic data, produce a Fourier signature from the network traffic data, associate the Fourier signature with a known pattern, collect new network traffic data, produce a new Fourier signature from the new network traffic data, compare the new Fourier signature with the Fourier signature to selectively identify a match and associate the new network traffic data with the known pattern upon a match.

Claims (38)

1. A computer implemented method for characterizing network traffic, at least a portion of the method being performed by a processor, the method comprising:

collecting packet based network traffic timing data into an array;

forming a histogram by binning the array into individual bins representing units of time;

producing a Fourier signature from the packet based network traffic timing data, including using each bin as a binary amplitude signal measurement that is Fourier transformed;

associating the Fourier signature with a known pattern associated with a dangerous application or user;

adding the Fourier signature to a Fourier signature library comprising previously produced Fourier signatures associated with dangerous applications or users;

collecting new packet based network traffic timing data into a new array;

forming a histogram by binning the new array into individual bins representing units of time;

producing a new Fourier signature from the new packet based network traffic timing data, including using each bin as a binary amplitude signal measurement that is Fourier transformed;

comparing the new Fourier signature with the Fourier signature of the Fourier signature library to selectively identify a Fourier signature match;

associating the new network traffic data with the known pattern upon the Fourier signature match; and

taking computer security prophylactic actions against the dangerous application or user in response to the Fourier signature match.

2. The method of claim 1 , wherein the packet based network traffic timing data is selected from a packet transmit time, a packet flow start time, a packet flow end time, and a packet flow duration time.

3. The method of claim 1 , wherein the Fourier signature has a frequency spectrum indicative of network packet traffic.

4. The method of claim 3 , further comprising computing the mean and standard deviation of frequency modes present in the frequency spectrum to identify signal outliers.

5. The method of claim 3 , further comprising identifying clustered frequencies in the frequency spectrum.

6. The method of claim 3 , further comprising identifying cluster peaks in the frequency spectrum.

7. The method of claim 1 , further comprising performing a correlation test between the new Fourier signature and the Fourier signature.

8. The method of claim 1 , further comprising logging the new Fourier signature for further evaluation upon failure to identify a match.

9. A non-transitory computer-readable medium containing instructions that, when executed by a processor, are configured to:

collect packet based network traffic timing data into an array;

form a histogram by binning the array into individual bins representing units of time;

produce a Fourier signature from the packet based network traffic timing data, wherein the instructions to produce include instructions to use each bin as a binary amplitude signal measurement that is Fourier transformed;

associate the Fourier signature with a known pattern associated with a dangerous application or user;

add the Fourier signature to a Fourier signature library comprising previously produced Fourier signatures associated with dangerous applications or users;

collect new packet based network traffic timing data into a new array;

form a histogram by binning the new array into individual bins representing units of time;

produce a new Fourier signature from the new packet based network traffic timing data, wherein the instructions to produce include instructions to use each bin as a binary amplitude signal measurement that is Fourier transformed;

compare the new Fourier signature with the Fourier signature of the Fourier signature library to selectively identify a Fourier signature match;

associate the new network traffic data with the known pattern upon the Fourier signature match; and

take computer security prophylactic actions against the dangerous application or user in response to the Fourier signature match.

10. The computer-readable medium of claim 9 , wherein the packet based network traffic timing data is selected from a packet transmit time, a packet flow start time, a packet flow end time, and a packet flow duration time.

11. The computer-readable medium of claim 9 , wherein the Fourier signature has a frequency spectrum indicative of network packet traffic.

12. The computer-readable medium of claim 11 , the instructions further configured to compute the mean and standard deviation of frequency modes present in the frequency spectrum to identify signal outliers.

13. The computer-readable medium of claim 11 , the instructions further configured to identify clustered frequencies in the frequency spectrum.

14. The computer-readable medium of claim 11 , the instructions further configured to identify cluster peaks in the frequency spectrum.

15. The computer-readable medium of claim 9 , the instructions further configured to perform a correlation test between the new Fourier signature and the Fourier signature.

16. The computer-readable medium of claim 9 , the instructions further configured to log the new Fourier signature for further evaluation upon failure to identify a match.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2016
From: WOOD, MATTHEW S.; LEVY, JOSEPH H.
To: SOLERA NETWORKS, INC.
Reel/Frame 040216/0893 →
MERGER Recorded Nov 3, 2016
From: SOLERA NETWORKS, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 040217/0129 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 040560/0851 →
Continuity (2)
Continuation 13861655 · Apr 12, 2013
Related Publication 20170078166A1 · Mar 16, 2017