IP Library Granted Patent US 11,496,377
Granted Patent B2
US 11,496,377 · App. 16/846,149 · Granted Nov 8, 2022

Anomaly detection through header field entropy

Inventors: Navindra Yadav (Cupertino, CA); Mohammadreza Alizadeh Attar (Cambridge, MA); Shashidhar Gandham (Fremont, CA); Jackson Ngoc Ki Pang (Sunnyvale, CA); Roberto Fernando Spadaro (Milpitas, CA)
Assignee: CISCO TECHNOLOGY, INC.
H04L43/045G06F3/0482G06F3/04842G06F3/04847G06F9/45558G06F16/122G06F16/137G06F16/162G06F16/17G06F16/173G06F16/174G06F16/1744G06F16/1748G06F16/235G06F16/2322G06F16/2365G06F16/248G06F16/24578G06F16/285G06F16/288G06F16/29G06F16/9535G06F21/53G06F21/552G06F21/566G06N20/00G06N99/00G06T11/206H04J3/0661H04J3/14H04L1/242H04L9/0866H04L9/3239H04L9/3242H04L41/046H04L41/0668H04L41/0803H04L41/0806H04L41/0816H04L41/0893H04L41/12H04L41/16H04L41/22H04L43/02H04L43/026H04L43/04H04L43/062H04L43/08H04L43/0805H04L43/0811H04L43/0829H04L43/0841H04L43/0858H04L43/0864H04L43/0876H04L43/0882H04L43/0888H04L43/10H04L43/106H04L43/12H04L43/16H04L45/306H04L45/38H04L45/46H04L45/507H04L45/66H04L45/74H04L47/11H04L47/20H04L47/2441H04L47/2483H04L47/28H04L47/31H04L47/32H04L61/5007H04L63/0227H04L63/0263H04L63/06H04L63/0876H04L63/145H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/1458H04L63/1466H04L63/16H04L63/20H04L67/01H04L67/10H04L67/1001H04L67/12H04L67/51H04L67/75H04L69/16H04L69/22H04W72/08H04W84/18G06F2009/4557G06F2009/45587G06F2009/45591G06F2009/45595G06F2221/033G06F2221/2101G06F2221/2105G06F2221/2111G06F2221/2115G06F2221/2145H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,496,377
App. No.
16/846,149
Granted
Nov 8, 2022
Kind
B2
Abstract

An approach for detecting anomalous flows in a network using header field entropy. This can be useful in detecting anomalous or malicious traffic that may attempt to “hide” or inject itself into legitimate flows. A malicious endpoint might attempt to send a control message in underutilized header fields or might try to inject illegitimate data into a legitimate flow. These illegitimate flows will likely demonstrate header field entropy that is higher than legitimate flows. Detecting anomalous flows using header field entropy can help detect malicious endpoints.

Claims (40)

1. A computer-implemented method comprising:

detecting, via one or more sensors, a plurality of flows;

determining a plurality of entropies associated with the plurality of flows wherein the entropies are associated with header data of packets of the plurality of flows;

determining, based on previous flows within a previous time period, an amount of traffic indicating non-malicious traffic in the previous flows;

determining whether an entropy of the plurality of entropies is greater than the amount of traffic indicating non-malicious traffic;

in response to the entropy of the plurality of entropies being greater than the amount of traffic indicating non-malicious traffic, determining an associated flow of the plurality of flows is anomalous; and

in response to the entropy of the plurality of entropies being less than or equal to the amount, determining the associated flow of the plurality of flows is normal.

2. The computer-implemented method of claim 1 , further comprising:

provide a buffer when the amount is greater than a second entropy of the plurality of entropies.

3. The computer-implemented method of claim 1 , wherein, the plurality of flows includes a portion of flows detected via a first sensor of the one or more sensors installed on a first endpoint, the first endpoint is a destination for the portion of flows, the detecting of the plurality of flows includes detecting, via a second sensor of the one or more sensors associated with a second endpoint, the portion of flows, and the second endpoint is a source for the portion of flows.

4. The computer-implemented method of claim 1 , wherein, at least one of the plurality of entropies is associated with at least one of a plurality of header fields, the plurality of header fields have various entropy values, and the at least one of the plurality of header fields is a packet identification field of Internet Protocol version 4 standard.

5. The computer-implemented method of claim 1 , wherein at least one of the plurality of entropies includes associated with at least one of a plurality of header fields, the plurality of header fields have various entropy values, and the at least one of the plurality of header fields is a time to live field and/or a sequence identifier field.

6. The computer-implemented method of claim 1 , wherein the determining of the plurality of entropies includes determining an expected sequence identifier field.

7. The computer-implemented method of claim 6 , wherein the determining of the plurality of entropies includes determining a difference between the expected sequence identifier field and a detected sequence identifier field.

8. A non-transitory computer-readable medium having computer readable instructions that, when executed by a processor of a computer, cause the computer to:

detect, via one or more sensors, a plurality of flows;

determine a plurality of entropies associated with the plurality of flows wherein the entropies are associated with header data of packets of the plurality of flows;

determine, based on previous flows within a previous time period, an amount of traffic indicating non-malicious traffic in the previous flows;

determine whether an entropy of the plurality of entropies is greater than the amount of traffic indicating non-malicious traffic;

in response to the entropy of the plurality of entropies being greater than the amount of traffic indicating non-malicious traffic, determine the one of the plurality of flows is anomalous; and

in response to the entropy of the plurality of entropies is less than or equal to the amount, determine the one of the plurality of flows is normal.

9. The non-transitory computer-readable medium of claim 8 , wherein the instructions further cause the computer to: provide a buffer when the amount is greater than a second entropy of the plurality of entropies.

10. The non-transitory computer-readable medium of claim 8 , wherein, the plurality of flows includes a portion of flows detected via a first sensor of the one or more sensors installed on a first endpoint, the first endpoint is a destination for the portion of flows, detecting the plurality of flows includes detecting, via a second sensor of the one or more sensors associated with a second endpoint, the portion of flows, and the second endpoint is a source for the portion of flows.

11. The non-transitory computer-readable medium of claim 8 , wherein, at least one of the plurality of entropies is associated with at least one of a plurality of header fields, the plurality of header fields have various entropy values, and the at least one of the plurality of header fields is a packet identification field of Internet Protocol version 4 standard.

12. The non-transitory computer-readable medium of claim 8 , wherein, at least one of the plurality of entropies is associated with at least one of a plurality of header fields, the plurality of header fields have various entropy values, and the at least one of the plurality of header fields is a time to live field and/or a sequence identifier field.

13. The non-transitory computer-readable medium of claim 8 , wherein determining the plurality of entropies includes determining an expected sequence identifier field.

14. The non-transitory computer-readable medium of claim 13 , wherein determining the plurality of entropies includes determining a difference between the expected sequence identifier field and a detected sequence identifier field.

15. A system comprising:

a processor; a memory including instructions that when executed by the processor, cause the system to:

detect, via one or more sensors, a plurality of flows;

determine a plurality of entropies associated with the plurality of flows wherein the entropies are associated with header data of packets of the plurality of flows;

determine, based on previous flows within a previous time period, an amount of traffic indicating non-malicious traffic in the previous flows;

determine whether an entropy of the plurality of entropies is greater than the amount of traffic indicating non-malicious traffic;

in response to the entropy of the plurality of entropies is greater than the amount of traffic indicating non-malicious traffic, determine the one of the plurality of flows is anomalous; and

in response to the entropy of the plurality of entropies is less than or equal to the amount, determine the one of the plurality of flows is normal.

16. The system of claim 15 , wherein the instructions further cause the system to: provide a buffer when the amount is greater than a second entropy of the plurality of entropies.

17. The system of claim 15 , wherein, the plurality of flows includes a portion of flows detected via a first sensor of the one or more sensors installed on a first endpoint, the first endpoint is a destination for the portion of flows, detecting the plurality of flows includes detecting, via a second sensor of the one or more sensors associated with a second endpoint, the portion of flows, and the second endpoint is a source for the portion of flows.

18. The system of claim 15 , wherein, at least one of the plurality of entropies is associated with at least one of a plurality of header fields, the plurality of header fields have various entropy values, and the at least one of the plurality of header fields is a packet identification field of Internet Protocol version 4 standard.

19. The system of claim 15 , wherein, at least one of the plurality of entropies is associated with at least one of a plurality of header fields, the plurality of header fields have various entropy values, and the at least one of the plurality of header fields is a time to live field and/or a sequence identifier field.

20. The system of claim 15 , wherein, determining the plurality of entropies includes determining an expected sequence identifier field, and determining the plurality of entropies includes determining a difference between the expected sequence identifier field and a detected sequence identifier field.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2020
From: YADAV, NAVINDRA; ALIZADEH ATTAR, MOHAMMADREZA; GANDHAM, SHASHIDHAR; PANG, JACKSON NGOC KI; SPADARO, ROBERTO FERNANDO
To: CISCO TECHNOLOGY, INC.
Reel/Frame 052373/0301 →
Continuity (3)
Continuation 15173489 · Jun 3, 2016
Provisional Application 62171899 · Jun 5, 2015
Related Publication 20200313986A1 · Oct 1, 2020