IP Library Granted Patent US 11,153,338
Granted Patent B2
US 11,153,338 · App. 16/429,738 · Granted Oct 19, 2021

Preventing network attacks

Inventors: John Richard Feezell (Pikeville, TN); Cesar Augusto Rodriguez Bravo (Alajuela, CR); Wayne Francis Tackabury (West Tisbury, MA); Edgar Adolfo Zamora Duran (Heredia, CR)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
H04L63/1425H04L63/126H04L63/1416H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,338
App. No.
16/429,738
Granted
Oct 19, 2021
Kind
B2
Abstract

Embodiments are disclosed for preventing network attacks. The techniques include generating a usage profile for a computing device that accesses a network. The techniques also include determining a plurality of actual use real-time indicators for a network connection on the network. The techniques further include determining a plurality of expected use real-time indicators for the network connection. Additionally, the techniques include calculating a risk assessment value for the network connection based on the actual use real-time indicators and the expected use real-time indicators. Further, the techniques include performing a security action for the network connection based on the calculated risk assessment value.

Claims (46)

1. A computer-implemented method comprising: generating a usage profile for a computing device that accesses a network; determining a plurality of actual use real-time indicators for a network connection on the network; determining a plurality of expected use real-time indicators for the network connection; calculating a risk assessment value for the network connection by:

comparing the actual use real-time indicators to the expected use real-time indicators; and

increasing the risk assessment value when one of the actual use real-time indicators represents a greater use than a corresponding one of the expected use real-time indicators; and

performing a security action for the network connection based on the calculated risk assessment value by:

sending an informative alert to a user of the computing device based on the risk assessment value comprising a relatively low level of network attack risk; and

sending a warning alert to the user of the computing device based on the risk assessment value comprising a relatively elevated level of the network attack risk; and

dropping the network connection based on the risk assessment value comprising a relatively high value of the network attack risk.

2. The method of claim 1 , wherein the usage profile comprises a connection profile and an associated baseline, wherein the connection profile comprises:

a location of the user of the computing device;

an indicator that the user is participating in an event; and

an indicator whether a plurality of currently open network connections are from known connection sources.

3. The method of claim 2 , wherein the baseline comprises:

an average upload bandwidth rate; and

an average download bandwidth rate.

4. A computer program product comprising program instructions stored on a non-transitory computer readable storage medium, wherein the computer readable storage medium is not a transitory signal per se, the program instructions executable by a processor to cause the processor to perform a method comprising:

generating a usage profile for a computing device that accesses a network:

determining a plurality of actual use real-time indicators for a network connection on the network;

determining a plurality of expected use real-time indicators for the network connection;

calculating a risk assessment value for the network connection by: comparing the actual use real-time indicators to the expected use real-time indicators; and

increasing the risk assessment value when one of the actual use real-time indicators represents a greater use than a corresponding one of the expected use real-time indicators; and

performing a security action for the network connection based on the calculated risk assessment value by sending a warning alert to a user of the computing device based on the risk assessment value comprising a relatively low level of the network attack risk; and

dropping the network connection based on the risk assessment value comprising a relatively high value of network attack risk.

5. The computer program product of claim 4 , wherein performing the security action further comprises: sending an informative alert to the user of the computing device based on the risk assessment value comprising a relatively elevated level of the network attack risk.

6. The computer program product of claim 4 , wherein the usage profile comprises a connection profile and an associated baseline, wherein the connection profile comprises:

a location of a user of the computing device;

an indicator that the user is participating in an event; and

an indicator whether a plurality of currently open network connections are from known connection sources.

7. The computer program product of claim 6 , wherein the baseline comprises:

an average upload bandwidth rate; and

an average download bandwidth rate.

8. A system comprising: a computer processing circuit; and a non-transitory computer-readable storage medium storing instructions, which, when executed by the computer processing circuit, are configured to cause the computer processing circuit to perform a method comprising: generating a usage profile for a computing device that accesses a network;

determining a plurality of actual use real-time indicators for a network connection on the network;

determining a plurality of expected use real-time indicators for the network connection;

calculating a risk assessment value for the network connection by:

comparing the actual use real-time indicators to the expected use real-time indicators; and

increasing the risk assessment value when one of the actual use real-time indicators represents a greater use than a corresponding one of the expected use real-time indicators; and

performing a security action for the network connection based on the calculated risk assessment value by sending a warning alert to a user of the computing device based on the risk assessment value comprising a relatively low level of the network attack risk; and

shutting down a port for the network connection based on the risk assessment value comprising a relatively high value of network attack risk.

9. The system of claim 8 , wherein performing the security action comprises: sending an informative alert to a user of the computing device based on the risk assessment value based on the risk assessment value comprising a relatively low level of network attack risk.

10. The system of claim 8 , wherein the usage profile comprises a connection profile and an associated baseline, wherein the connection profile comprises:

a location of a user of the computing device;

an indicator that the user is participating in an event; and

an indicator whether a plurality of currently open network connections are from known connection sources.

11. The system of claim 10 , wherein the baseline comprises:

an average upload bandwidth rate; and

an average download bandwidth rate.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 18, 2021
From: INTERNATIONAL BUSINESS MACHINES CORPORATION
To: KYNDRYL, INC.
Reel/Frame 058213/0912 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2019
From: FEEZELL, JOHN RICHARD; RODRIGUEZ BRAVO, CESAR AUGUSTO; TACKABURY, WAYNE FRANCIS; ZAMORA DURAN, EDGAR ADOLFO
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 049349/0211 →