IP Library › Granted Patent US 11,483,342
Granted Patent B2
US 11,483,342 · App. 16/887,650 · Granted Oct 25, 2022

Utilizing web application firewall and machine learning to detect command and control

Inventors: Mohammed Adel Alfraih (Dhahran, SA); Khalid A. Hazmi (Dhahran, SA); Ziad I. Omair (Dhahran, SA); Sultan Saadaldean Alsharif (Dhahran, SA)
Assignee: SAUDI ARABIAN OIL COMPANY
H04L63/1466G06N20/00H04L41/16H04L63/0236H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,483,342
App. No.
16/887,650
Granted
Oct 25, 2022
Kind
B2
Abstract

A method for detecting Command and Control (C&C) toward a web application in a network includes: obtaining, using a Web Application Firewall (WAF) of the network, network traffic between the web application and a server outside the network; transmitting the network traffic from the WAF to a machine learning model; determining, using the machine learning model, whether the network traffic includes a command signature; in response to determining that the network traffic includes a command signature, generating a notification; and determining, based on the notification, whether the server is a C&C.

Claims (54)

1. A method for detecting Command and Control (C&C) toward a web application in a network, comprising:

obtaining, using a Web Application Firewall (WAF) of the network, network traffic between the web application and a server, where the server is outside the network, and wherein the network traffic is decrypted and reformatted by the WAF;

transmitting the network traffic from the WAF to a machine learning model;

determining, using the machine learning model, whether the network traffic comprises a command signature;

in response to determining that the network traffic comprises a command signature, generating a notification; and

determining, upon receiving the notification, whether the server is a C&C by analyzing, by a security personnel, the network traffic,

wherein the decrypted and reformatted network traffic, as determined by the WAF, comprises the features: whether the port scanning activity is suspicious; whether the network traffic includes a data exfiltration command; whether the network traffic includes a memory manipulation command; whether the network traffic includes a crypto vulnerability exploit command; whether the network traffic includes a command shell command; and whether the network traffic includes a reverse HTTP shell command.

2. The method according to claim 1 ,

wherein the machine learning model comprises a Random Forest (RF) classifier, and

wherein the RF classifier comprises a plurality of decision trees.

3. The method according to claim 2 , further comprising training the machine learning model, wherein training the machine learning model comprises:

obtaining, an original dataset that comprises a plurality of network traffic samples; and

generating, from the original dataset, a plurality of bootstrapped datasets,

wherein each of the plurality of decision trees corresponds to one of the plurality of bootstrapped datasets, and

wherein each of the plurality of decision trees is trained using its corresponding bootstrapped dataset.

4. The method according to claim 3 , wherein the plurality of network traffic samples comprises a normal network traffic sample that does not have any command signature.

5. The method according to claim 2 , wherein whether the network traffic comprises a command signature is determined based on the votes of the plurality of decision trees.

6. The method according to claim 1 , further comprising:

in response to determining that the network traffic comprises a command signature, assigning an identifier to the network traffic.

7. The method according to claim 6 , wherein the notification comprises the identifier.

8. The method according to claim 1 , wherein the network is a local area network.

9. A computer system storing instructions executable by a computer processor, the instructions comprising functionality for:

receiving network traffic from a Web Application Firewall (WAF) which intercepts communications between a web application in a network and a server, where the server is outside the network, and wherein the network traffic comprises intercepted communications which have been decrypted and reformatted by the WAF; and

determining, with a machine learning model that receives the network traffic from the WAF, whether the network traffic comprises a command signature;

wherein, in response to determining that the network traffic comprises a command signature, the machine learning model generates a notification,

wherein, the notification and associated network traffic are received and analyzed by a security personnel to determine whether the server is a C&C,

wherein the decrypted and reformatted network traffic, as determined by the WAF, comprises the features: whether the port scanning activity is suspicious; whether the network traffic includes a data exfiltration command; whether the network traffic includes a memory manipulation command; whether the network traffic includes a crypto vulnerability exploit command; whether the network traffic includes a command shell command; and whether the network traffic includes a reverse HTTP shell command.

10. The computer system according to claim 9 ,

wherein the machine learning model comprises a Random Forest (RF) classifier, and

wherein the RF classifier comprises a plurality of decision trees.

11. The computer system according to claim 10 , further comprising training the machine learning model, wherein training the machine learning model comprises:

obtaining an original dataset that comprises a plurality of network traffic samples,

generating, from the original dataset, a plurality of bootstrapped datasets,

wherein each of the plurality of decision trees corresponds to one of the plurality of bootstrapped datasets, and

wherein each of the plurality of decision trees is trained using its corresponding bootstrapped dataset.

12. The computer system according to claim 11 , wherein the plurality of network traffic samples comprises a normal network traffic sample that does not have any command signature.

13. The computer system according to claim 10 , wherein whether the network traffic comprises a command signature is determined based on the votes of the plurality of decision trees.

14. The computer system according to claim 9 ,

wherein, in response to determining that the network traffic comprises a command signature, the machine learning model assigns an identifier to the network traffic.

15. The computer system according to claim 14 , wherein the notification comprises the identifier.

16. The computer system according to claim 9 , wherein the network is a local area network.

17. A system, comprising:

a web application in a network,

a Web Application Firewall (WAF), wherein the WAF obtains network traffic between the web application and a server, where the server is outside the network, and wherein the network traffic is decrypted and reformatted by the WAF,

a machine learning model,

a security personnel, and

a computer comprising:

one or more computer processors, and

a computer readable medium storing instructions executable by a computer processor, the instructions comprising functionality for:

receiving the network traffic from the WAF,

determining, with the machine learning model, whether the network traffic comprises a command signature, and

generating, in response to determining that the network traffic comprises a command signature, a notification,

wherein, upon receiving the notification, the security personnel analyzes the associated network traffic to determine if the server is a C&C,

wherein the decrypted and reformatted network traffic, as determined by the WAF, comprises the features: whether the port scanning activity is suspicious; whether the network traffic includes a data exfiltration command; whether the network traffic includes a memory manipulation command; whether the network traffic includes a crypto vulnerability exploit command; whether the network traffic includes a command shell command; and whether the network traffic includes a reverse HTTP shell command.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2020
From: ALFRAIH, MOHAMMED ADEL; HAZMI, KHALID A.; OMAIR, ZIAD I.; ALSHARIF, SULTAN SAADALDEAN
To: SAUDI ARABIAN OIL COMPANY
Reel/Frame 053804/0801 →
Continuity (1)
Related Publication 20210377295A1 · Dec 2, 2021
Cited By (1)
US 12,483,573