IP Library Granted Patent US 10,382,467
Granted Patent B2
US 10,382,467 · App. 15/494,181 · Granted Aug 13, 2019

Recursive multi-layer examination for computer network security remediation

Inventors: Ryan Wager (Kansas City, MO); Fyodor Yarochkin (Taipei, TW); Zach Dahlgren (Omaha, NE)
Assignee: vArmour Networks, Inc.
H04L63/1425H04L63/0227H04L63/08H04L63/10H04L63/1416H04L63/1441H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,467
App. No.
15/494,181
Granted
Aug 13, 2019
Kind
B2
Abstract

Computer-implemented methods and apparatuses for recursive multi-layer examination for computer network security remediation may include: identifying one or more first communications originating from or directed to a first node; identifying at least one of a protocol and an application used for each of the one or more first communications; examining each of the one or more first communications for malicious behavior; receiving a first risk score for each of the one or more first communications responsive to the examining; determining the first risk score associated with one of the one or more first communications exceeds a first predetermined threshold; and indicating the first node and a second node in communication with the first node via the one of the one or more first communications are malicious. Exemplary methods may further include: providing the identified malicious nodes and communications originating from or directed to the malicious nodes.

Claims (85)

1. A computer-implemented method for recursive multi-layer examination for computer network security remediation comprising:

identifying one or more first communications originating from or directed to a first node;

identifying at least one of a protocol and an application used for each of the one or more first communications;

examining each of the one or more first communications for malicious behavior using a respective first scanlet of one or more scanlets, the respective first scanlet associated with the at least one of the protocol and the application used for the each of the one or more first communications;

receiving a first risk score from the respective first scanlet for each of the one or more first communications responsive to the examining of the each of the one or more first communications;

determining the first risk score associated with one of the one or more first communications exceeds a first predetermined threshold;

indicating the first node and a second node in communication with the first node via the one or more first communications are malicious;

identifying one or more second communications originating from or directed to the second node;

identifying at least one of a protocol and an application used for each of the one or more second communications;

examining each of the one or more second communications for malicious behavior using a respective second scanlet of the one or more scanlets, the respective second scanlet associated with the at least one of the protocol and the application used for the each of the one or more second communications;

receiving a second risk score from the respective second scanlet for each of the one or more second communications responsive to the examining of the each of the one or more second communications;

determining the second risk score associated with one of the one or more second communications exceeds the first predetermined threshold;

indicating a third node in communication with the second node via the one of the one or more second communications is malicious;

providing the indicated malicious nodes and communications originating from or directed to the indicated malicious nodes, such that progress of a security breach or intrusion through the indicated malicious nodes and communications is indicated;

remediating the security breach;

assigning a node risk score to an additional second node in which additional second risk scores, for additional second communications originating from or directed to the additional second node, do not exceed the first predetermined threshold, the node risk score being an average of the additional second risk scores; and

determining the node risk score exceeds a second predetermined threshold and indicating the additional second node is malicious.

2. The method of claim 1 , further comprising:

identifying one or more third communications originating from or directed to the third node;

identifying at least one of a protocol and an application used for each of the one or more third communications;

examining each of the one or more third communications for malicious behavior using a respective third scanlet of the one or more scanlets, the respective third scanlet associated with the at least one of the protocol and the application used for the each of the one or more third communications;

receiving a third risk score from the respective third scanlet for each of the one or more third communications responsive to the examining of the each of the one or more third communications;

determining the third risk score associated with one of the one or more third communications exceeds the first predetermined threshold; and

indicating a fourth node in communication with the third node via the one of the one or more third communications is malicious.

3. The method of claim 2 , wherein another one of the one or more third communications is not examined if the another one of the one or more third communications is the same as one of the one or more first or second communications.

4. The method of claim 1 , wherein each of the first and second nodes is at least one of a physical host, virtual machine, container, client system, and other computing system on a communications network.

5. The method of claim 1 , wherein the identifying of the one or more first communications uses first metadata retrieved from the first node using a first identifier, and wherein the identifying of the one or more second communications uses second metadata retrieved from the second node using a second identifier.

6. The method of claim 5 , wherein each of the first and second metadata includes information logged by an enforcement point.

7. The method of claim 5 , wherein each of the first and second metadata comprises at least one of a source (IP) address and/or hostname, source port, destination (IP) address and/or hostname, destination port, protocol, application, username and/or other credentials used to gain access to computing resources on a network, and number of bytes in a communication.

8. The method of claim 1 , wherein each of the one or more scanlets detects malicious activity in network communications using at least one of a particular protocol and a particular application.

9. The method of claim 1 , wherein each of the first and second risk scores and the first predetermined threshold is a number within a predetermined range of numbers.

10. An analytic engine comprising:

a processor; and

a memory coupled to the processor, the memory storing instructions executable by the processor to perform the following operations for recursive multi-layer examination for computer network security remediation:

identifying one or more first communications originating from or directed to a first node;

identifying at least one of a protocol and an application used for each of the one or more first communications;

examining each of the one or more first communications for malicious behavior using a respective first scanlet of one or more scanlets, the respective first scanlet associated with the at least one of the protocol and the application used for the each of the one or more first communications;

receiving a first risk score from the respective first scanlet for each of the one or more first communications responsive to the examining of the each of the one or more first communications;

determining the first risk score associated with one of the one or more first communications exceeds a first predetermined threshold;

indicating the first node and a second node in communication with the first node via the one of the one or more first communications are malicious;

identifying one or more second communications originating from or directed to the second node;

identifying at least one of a protocol and an application used for each of the one or more second communications;

examining each of the one or more second communications for malicious behavior using a respective second scanlet of the one or more scanlets, the respective second scanlet associated with the at least one of the protocol and the application used for the each of the one or more second communications;

receiving a second risk score from the respective second scanlet for each of the one or more second communications responsive to the examining of the each of the one or more second communications;

determining the second risk score associated with one of the one or more second communications exceeds the first predetermined threshold;

indicating a third node in communication with the second node via the one of the one or more second communications is malicious;

providing the indicated malicious nodes and communications originating from or directed to the indicated malicious nodes, such that progress of a security breach or intrusion through the indicated malicious nodes and the communications is indicated;

remediating the security breach;

assigning a node risk score to an additional second node in which additional second risk scores, for additional second communications originating from or directed to the additional second node, do not exceed the first predetermined threshold, the node risk score being an average of the additional second risk scores; and

determining the node risk score exceeds a second predetermined threshold and

indicating the additional second node is malicious.

11. The analytic engine of claim 10 , wherein the memory stores further instructions executable by the processor to perform the following operations:

identifying one or more third communications originating from or directed to the third node;

identifying at least one of a protocol and an application used for each of the one or more third communications;

examining the each of the one or more third communications for malicious behavior using a respective third scanlet of the one or more scanlets, the respective third scanlet associated with the at least one of the protocol and the application used for the each of the one or more third communications;

receiving a third risk score for the each of the one or more third communications responsive to the examining of the each of the one or more third communications;

determining the third risk score associated with one of the one or more third communications exceeds the first predetermined threshold; and

indicating a fourth node in communication with the third node via the one or more third communications is malicious.

12. The analytic engine of claim 11 , wherein another one of the one or more third communications is not examined if the another one of the one or more third communications is the same as one of the one or more first or second communications.

13. The analytic engine of claim 10 , wherein each of the first and second nodes is at least one of a physical host, virtual machine, container, client system, and other computing system on a communications network.

14. The analytic engine of claim 10 , wherein the identifying of the one or more first communications uses first metadata retrieved from the first node using a first identifier, and wherein the identifying of the one or more second communications uses second metadata retrieved from the second node using a second identifier.

15. The analytic engine of claim 14 , wherein each of the first and second metadata includes information logged by an enforcement point.

16. The analytic engine of claim 14 , wherein each of the first and second metadata comprises at least one of a source (IP) address and/or hostname, source port, destination (IP) address and/or hostname, destination port, protocol, application, username and/or other credentials used to gain access to computing resources on a network, and number of bytes in a communication.

17. The analytic engine of claim 10 , wherein each of the first and second risk scores and the first predetermined threshold is a number within a predetermined range of numbers.

18. A computer-implemented method for recursive multi-layer examination for computer network security remediation comprising:

retrieving first metadata using a first identifier associated with a first node, the first metadata comprising at least one of a source (IP) address and/or hostname, source port, destination (IP) address and/or hostname, destination port, protocol, application, username and/or other credentials used to gain access to computing resources on a network, and number of bytes in a communication;

identifying one or more first communications originating from or directed to the first node using the first metadata;

ascertaining a first characteristic of each of the one or more first communications using the first metadata;

selecting a respective first scanlet of a plurality of scanlets, the respective first scanlet using the first characteristic of a respective first communication of the one or more first communications;

applying the respective first scanlet to the respective first communication;

receiving a first risk score for each of the one or more first communications responsive to the applying of the respective first scanlet;

determining the first risk score associated with one of the one or more first communications exceeds a first predetermined threshold;

indicating the first node and a second node in communication with the first node via the one of the one or more first communications are malicious;

retrieving second metadata using a second identifier associated with the second node, the second metadata comprising at least one of a source (IP) address and/or hostname, source port, destination (IP) address and/or hostname, destination port, protocol, application, username and/or other credentials used to gain access to computing resources on a network, and number of bytes in a communication;

identifying one or more second communications originating from or directed to the second node using the second metadata;

ascertaining a second characteristic of each of the one or more second communications using the second metadata;

selecting a respective second scanlet of the plurality of scanlets, the respective second scanlet using the second characteristic of a respective second communication of the one or more second communications;

applying the respective second scanlet to the respective second communication;

receiving a second risk score for each of the one or more second communications responsive to the applying of the respective second scanlet;

determining the second risk score associated with one of the one or more second communications exceeds the first predetermined threshold;

indicating a third node in communication with the second node via the one of the one or more second communications is malicious;

providing the indicated malicious nodes and communications originating from or directed to the indicated malicious nodes, such that progress of a security breach or intrusion through the indicated malicious nodes and communications is indicated;

remediating the security breach;

assigning a node risk score to an additional second node in which additional second risk scores, for additional second communications originating from or directed to the additional second node, do not exceed the first predetermined threshold, the node risk score being an average of the additional second risk scores; and

determining the node risk score exceeds a second predetermined threshold and indicating the additional second node is malicious.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Jul 18, 2025
From: GRYPHO5, LLC
To: EVP CREDIT SPV I LP
Reel/Frame 072053/0141 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2025
From: VARMOUR NETWORKS, INC.
To: GRYPHO5, LLC
Reel/Frame 070287/0007 →
SECURITY INTEREST Recorded Feb 22, 2024
From: VARMOUR NETWORKS, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 066530/0399 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2017
From: WAGER, RYAN; YAROCHKIN, FYODOR; DAHLGREN, ZACH
To: VARMOUR NETWORKS, INC.
Reel/Frame 043002/0441 →
Continuity (3)
Continuation 15090523 · Apr 4, 2016
Provisional Application 62289053 · Jan 29, 2016
Related Publication 20170223038A1 · Aug 3, 2017