IP Library Granted Patent US 11,245,602
Granted Patent B2
US 11,245,602 · App. 16/579,455 · Granted Feb 8, 2022

Correlating network traffic to their OS processes using packet capture libraries and kernel monitoring mechanisms

Inventor: Gal Kaplan (Tel Aviv, IL)
Assignee: Cybereason Inc.
H04L43/067H04L43/062H04L45/74H04L61/1511
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,245,602
App. No.
16/579,455
Granted
Feb 8, 2022
Kind
B2
Abstract

A method of monitoring and reporting of packets including their attribution to their origin processes from a user space application without installing proprietary drivers, rather using only infrastructures and capabilities supplied by the operating system (OS). The method relies on correlation between packets received from a packet capture library and a kernel monitoring mechanism that supplies an event with the process ID which is executed on the same time frame for transmitting or receiving of that traffic. The attribution between the event and the packet is based on the 4-tuple (or other exemplar) that exists on both the event and the packet where the “4-tuple” is a set of: source address, source port, destination address, destination port.

Claims (38)

1. A method for discovering the origin of network traffic on a computer running an operating system (OS) comprising:

monitoring, by a first tool of the operating system, a port of the computer for domain name system (DNS) communications;

upon detecting a DNS communication, capturing, via the first tool, at least packet headers of transmitted or received packets of the DNS communication, said first tool reporting a first exemplar for each packet captured;

monitoring, by a second tool of the operating system, a kernel of the operating system for kernel events;

upon detecting a kernel event, identifying, via the second tool, a second exemplar for each packet transmitted or received by the kernel event and a process identification (PID) of the kernel event transmitting or receiving each packet;

comparing captured first exemplars from the DNS communication to second exemplars from the kernel event;

determining that the DNS communication and the kernel event occurred within a predetermined time window; and

based on the determining, reporting the originating PID of the DNS communication when said exemplars match within the predetermined time window.

2. The method of claim 1 wherein each of said first exemplar and said second exemplar is a 4-tuple containing source address, source port, destination address and destination port.

3. The method of claim 1 wherein the predetermined time window is approximately one second.

4. The method of claim 1 wherein the first tool is libpcap.

5. The method of claim 1 wherein the second tool is KProbes.

6. The method of claim 1 wherein the first tool is Winpcap or NDISCapture.

7. The method of claim 1 wherein the second tool is EventViewer.

8. A method for discovering the origin of network traffic on a computer running an operating system (OS) comprising:

monitoring, by a first tool of the operating system, a port of the computer for domain name system (DNS) communications;

upon detecting a DNS communication, capturing packet data and an identifying 4-tuple for each packet captured;

monitoring, by a second tool of the operating system, a kernel of the operating system for kernel events;

upon detecting a kernel event, capturing, by the second tool, an identifying 4-tuple for each kernel event a process identification (PID) of the kernel event;

comparing captured 4-tuples from captured packets to 4-tuples from kernel events that occur within a predetermined time window; and

reporting the originating PID of the DNS request when said 4-tuples match within the predetermined time window.

9. The method of claim 8 wherein the port is Port 53.

10. The method of claim 8 wherein the predetermined time window is approximately one second.

11. The method of claim 8 wherein the first tool is libpcap.

12. The method of claim 8 wherein the second tool is a KProbe.

13. The method of claim 8 wherein the first tool is Winpcap or NDISCapture.

14. The method of claim 8 wherein the second tool is EventViewer.

15. A method of discovering an origin of network traffic via an operating system of a computer comprising:

capturing a packet of data from a port of the computer;

upon capturing the packet, determining a first exemplar identifying the captured packet;

detecting a kernel packet transmit event by monitoring a kernel of the computer;

upon detecting the kernel packet transmit event, determining a second exemplar identifying the kernel packet transmit event;

correlating the captured packet with the kernel packet transmit event in a predetermined time interval by matching the first and second exemplars.

16. The method of claim 15 wherein the correlation occurs when the captured packet and the kernel packet transmit event include the same 4-tuple occurring within the predetermined time interval.

17. The method of claim 16 wherein the predetermined time window is approximately one second.

18. The method of claim 15 wherein the origin of the network traffic implicates a particular process.

19. The method of claim 15 wherein the network traffic is a DNS communication.

20. The method of claim 15 wherein capture of the packet and the kernel packet transmit event are effected by using infrastructures and capabilities supplied by the operating system (OS).

Assignments (10)
SECURITY INTEREST Recorded Apr 7, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 075377/0304 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 059732/0513) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0892 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 054517/0199) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0912 →
RELEASE OF SECURITY INTEREST (REEL/FRAME 065316/0551 ) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A.
To: CYBEREASON INC.
Reel/Frame 073781/0852 →
SUPPLEMENT NO. 2 TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 23, 2023
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 065316/0551 →
RELEASE OF SECURITY INTEREST Recorded Jun 26, 2023
From: SOFTBANK CORP.
To: CYBEREASON INC.
Reel/Frame 064108/0725 →
SECURITY INTEREST Recorded May 5, 2023
From: CYBEREASON INC.
To: SOFTBANK CORP.
Reel/Frame 063550/0415 →
SECURITY INTEREST Recorded Apr 26, 2022
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059732/0513 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2021
From: KAPLAN, GAL
To: CYBEREASON INC.
Reel/Frame 055124/0893 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 25, 2020
From: CYBEREASON INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 054517/0199 →