IP Library Granted Patent US 11,184,369
Granted Patent B2
US 11,184,369 · App. 16/164,727 · Granted Nov 23, 2021

Malicious relay and jump-system detection using behavioral indicators of actors

Inventors: Himanshu Mhatre (Mountain View, CA); Nicolas Beauchesne (Miami Beach, FL)
Assignee: Vectra Networks, Inc.
H04L63/1416H04L63/1425H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,184,369
App. No.
16/164,727
Granted
Nov 23, 2021
Kind
B2
Abstract

Disclosed is an improved method, system, and computer program product for detecting hosts and connections between hosts that are being used as relays by an actor to gain control of hosts in a network. It can further identify periods of time within the connection when the relay activities occurred. In some embodiments, the invention can also chain successive relays to identify the true source and true target of the relay.

Claims (48)

1. A method for identifying malicious network communications comprising:

receiving network traffic of a network;

extracting a set of metadata from the network traffic, the set of metadata representing network traffic between respective pairs of nodes of a plurality of pairs of nodes; and

detecting a common node acting as a relay on the network, the common node being a common to a source node and a destination node, detecting the common node acting as a relay by at least:

generating a source time series vector representing network traffic between the source node and the common node based on the set of metadata and a destination time series vector representing network traffic between the common node and the destination node based on the set of metadata,

generating a plurality of similarity scores by comparing the source time series vector and the destination time series vector, wherein the similarity scores correspond to a similarity of network behavior across legs of a potential relay arrangement, and

generating an alarm when a similarity score of the plurality of similarity scores is beyond a threshold, the alarm indicating that the common node is part of a relay arrangement.

2. The method of claim 1 , wherein a first similarity score of the plurality of similarity scores is generated based on a source time series vector and a destination time series vector before any temporal offset is applied to the source time series vector or the destination time series vector and a second similarity score of the plurality of similarity scores is generated after applying a temporal offset to the source time series vector or the destination time series vector.

3. The method of claim 1 , wherein the network traffic between the source node and the common node consists of network traffic from the source node and to the common node, and the network traffic between the common node and the destination node consists of network traffic from the common node and to the destination node.

4. The method of claim 1 , wherein the set of metadata is organized into different sessions, the source time series vector corresponds to a first session, and the destination time series vector corresponds to a second session.

5. The method of claim 1 , further comprising:

detecting a second common node acting as a second relay on the network, the second common node being common to a second source node and a second destination node, detecting the second common node acting as a relay by at least:

generating a second source time series vector representing network traffic between the second source node and the second common node based on the set of metadata and a second destination time series vector representing network traffic between the common node and the destination node based on the set of metadata, and

generating a second plurality of similarity scores by comparing the second source time series vector and the second destination time series vector, at least one second similarity score of the second plurality of similarity scores is generated after applying a temporal offset to the second source time series vector or the second destination time series vector, and

generating a second alarm when a second similarity score of the second plurality of similarity scores is beyond a threshold, the second alarm indicating that the second common node is part of a relay arrangement.

6. The method of claim 1 , wherein the source node, the common node, or the destination node is external to the network.

7. The method of claim 1 , wherein the source node, the common node, or the destination node is in a partitioned area of a network, and only a subset of nodes internal to the network have a trust-permission to access the partitioned area of the network.

8. A computer program product embodied on a non-transitory computer readable medium having stored thereon a sequence of instructions which, when executed by a processor causes the processor to execute a set of acts for identifying malicious network communications, the set of acts comprising:

receiving network traffic of a network;

extracting a set of metadata from the network traffic, the set of metadata representing network traffic between respective pairs of nodes of a plurality of pairs of nodes; and

detecting a common node acting as a relay on the network, the common node being a common to a source node and a destination node, detecting the common node acting as a relay by at least:

generating a source time series vector representing network traffic between the source node and the common node based on the set of metadata and a destination time series vector representing network traffic between the common node and the destination node based on the set of metadata,

generating a plurality of similarity scores by comparing the source time series vector and the destination time series vector, wherein the similarity scores correspond to a similarity of network behavior across legs of a potential relay arrangement, and

generating an alarm when a similarity score of the plurality of similarity scores is beyond a threshold, the alarm indicating that the common node is part of a relay arrangement.

9. The computer program product of claim 8 , wherein a first similarity score of the plurality of similarity scores is generated based on a source time series vector and a destination time series vector before any temporal offset is applied to the source time series vector or the destination time series vector and a second similarity score of the plurality of similarity scores is generated after applying a temporal offset to the source time series vector or the destination time series vector.

10. The computer program product of claim 8 , wherein the network traffic between the source node and the common node consists of network traffic from the source node and to the common node, and the network traffic between the common node and the destination node consists of network traffic from the common node and to the destination node.

11. The computer program product of claim 8 , wherein the set of metadata is organized into different sessions, the source time series vector corresponds to a first session, and the destination time series vector corresponds to a second session.

12. The computer program product of claim 8 , further comprising:

detecting a second common node acting as a second relay on the network, the second common node being common to a second source node and a second destination node, detecting the second common node acting as a relay by at least:

generating a second source time series vector representing network traffic between the second source node and the second common node based on the set of metadata and a second destination time series vector representing network traffic between the common node and the destination node based on the set of metadata, and

generating a second plurality of similarity scores by comparing the second source time series vector and the second destination time series vector, at least one second similarity score of the second plurality of similarity scores is generated after applying a temporal offset to the second source time series vector or the second destination time series vector, and

generating a second alarm when a second similarity score of the second plurality of similarity scores is beyond a threshold, the second alarm indicating that the second common node is part of a relay arrangement.

13. The computer program product of claim 8 , wherein the source node, the common node, or the destination node is external to the network.

14. The computer program product of claim 8 , wherein the source node, the common node, or the destination node is in a partitioned area of a network, and only a subset of nodes internal to the network have a trust-permission to access the partitioned area of the network.

15. A system for detecting threats on a network, comprising:

a computer processor to execute a set of program code instructions;

a memory to hold the set of program code instructions, in which the set of program code instructions comprises program code to perform:

receiving network traffic of a network;

extracting a set of metadata from the network traffic, the set of metadata representing network traffic between respective pairs of nodes of a plurality of pairs of nodes; and

detecting a common node acting as a relay on the network, the common node being a common to a source node and a destination node, detecting the common node acting as a relay by at least:

generating a source time series vector representing network traffic between the source node and the common node based on the set of metadata and a destination time series vector representing network traffic between the common node and the destination node based on the set of metadata,

generating a plurality of similarity scores by comparing the source time series vector and the destination time series vector, wherein the similarity scores correspond to a similarity of network behavior across legs of a potential relay arrangement, and

generating an alarm when a similarity score of the plurality of similarity scores is beyond a threshold, the alarm indicating that the common node is part of a relay arrangement.

16. The system of claim 15 , wherein a first similarity score of the plurality of similarity scores is generated based on a source time series vector and a destination time series vector before any temporal offset is applied to the source time series vector or the destination time series vector and a second similarity score of the plurality of similarity scores is generated after applying a temporal offset to the source time series vector or the destination time series vector.

17. The system of claim 15 , wherein the network traffic between the source node and the common node consists of network traffic from the source node and to the common node, and the network traffic between the common node and the destination node consists of network traffic from the common node and to the destination node.

18. The system of claim 15 , wherein the set of metadata is organized into different sessions, the source time series vector corresponds to a first session, and the destination time series vector corresponds to a second session.

19. The system of claim 15 , wherein the source node, the common node, or the destination node is external to the network.

20. The system of claim 15 , wherein the source node, the common node, or the destination node is in a partitioned area of a network, and only a subset of nodes internal to the network have a trust-permission to access the partitioned area of the network.

Assignments (6)
SECURITY INTEREST Recorded Oct 29, 2024
From: VECTRA AI, INC.
To: AB PRIVATE CREDIT INVESTORS LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 069061/0588 →
CHANGE OF NAME Recorded Sep 23, 2024
From: VECTRA NETWORKS, INC.
To: VECTRA AI, INC.
Reel/Frame 069022/0514 →
RELEASE OF SECURITY INTEREST Recorded Mar 19, 2021
From: SILVER LAKE WATERMAN FUND, L.P., AS AGENT
To: VECTRA AI, INC.
Reel/Frame 055656/0351 →
CHANGE OF NAME Recorded Nov 4, 2019
From: VECTRA NETWORKS, INC.
To: VECTRA AI, INC.
Reel/Frame 050925/0991 →
SECURITY INTEREST Recorded Mar 13, 2019
From: VECTRA AI, INC.
To: SILVER LAKE WATERMAN FUND, L.P., AS AGENT
Reel/Frame 048591/0071 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2018
From: MHATRE, HIMANSHU; BEAUCHESNE, NICOLAS
To: VECTRA NETWORKS, INC.
Reel/Frame 047223/0737 →
Continuity (2)
Provisional Application 62585420 · Nov 13, 2017
Related Publication 20190149560A1 · May 16, 2019