IP Library Granted Patent US 12,542,789
Granted Patent B2
US 12,542,789 · App. 17/700,579 · Granted Feb 3, 2026

Malicious port scan detection using port profiles

Inventors: Yinnon Meshi (Kibbutz Revivim, IL); Idan Amit (Ramat Gan, IL); Jonathan Allon (Haifa, IL); Aviad Meyer (Hod-Hasharon, IL)
Assignee: Palo Alto Networks, Inc.
H04L63/1416H04L63/1475
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,789
App. No.
17/700,579
Granted
Feb 3, 2026
Kind
B2
Abstract

Methods, apparatus and computer software products implement embodiments of the present invention that include defining, for a given software category, respective, disjoint sets of communication ports that are used by each of a plurality of software systems in the given software category, including at least first and second disjoint sets. A set of port scans are identified in data traffic transmitted between multiple nodes that communicate over a network, each of the port scans including an access, in the data traffic, of a plurality of the communication ports on a given destination node by a given source node during a predefined time period. Upon detecting a port scan by one of the nodes including accesses of at least one of the communication ports in the first set and at least one of the communication ports in the second set, a preventive action is initiated.

Claims (35)

1 . A method, comprising:

defining, for a given software category, first and second, mutually disjoint sets of logical communication port numbers that are used by different, respective first and second software systems in the given software category;

identifying port scans in data traffic transmitted between multiple nodes that communicate over a network, each of the port scans comprising accesses, in the data traffic, of a plurality of the logical communication port numbers on n a given destination node by a given source node during a predefined time period;

classifying a given port scan as suspicious upon detecting that in the given port scan the given source node has accessed on the given destination node both at least one of the logical communication port numbers in the first set and at least one of the logical communication port numbers in the second set; and

initiating a protective action upon classifying the given port scan as suspicious.

2 . The method according to claim 1 , wherein identifying the port scans comprises detecting a failed connection between the given source node and a given logical port number in the first set on the given destination node.

3 . The method according to claim 1 , wherein identifying the port scans comprises detecting accesses of at least a specified number of the logical communication port numbers in the first set, wherein the specified number is greater than one.

4 . The method according to claim 1 , wherein identifying the port scans comprises detecting at least a specified number of the logical communication port numbers in each of the first and the second sets, wherein the specified number is greater than one.

5 . The method according to claim 1 , wherein the first set consists of logical communication port numbers used by a first operating system, and the second set consists of logical communication port numbers used by a second operating system, different from the first operating system.

6 . The method according to claim 1 , wherein the first set consists of logical communication port numbers used by a first database server, and the second set consists of logical communication port numbers used by a second database server, different from the first database server.

7 . The method according to claim 1 , wherein the first set consists of logical communication port numbers used by a first email server, and the second set consists of logical communication port numbers used by a second email server, different from the first email server.

8 . The method according to claim 1 , wherein the first set consists of logical communication port numbers used by a first remote session application, and the second set consists of logical communication port numbers used by a second remote session application, different from the first remote session application.

9 . The method according to claim 1 , wherein initiating the preventive action comprises generating an alert for the given source node in the detected port scan.

10 . The method according to claim 1 , wherein initiating the preventive action comprises restricting access of the given source node in the detected port scan to the network.

11 . An apparatus, comprising:

a network interface device coupled to a data network comprising multiple nodes that communicate via the network; and

at least one processor configured:

to receive a definition of first and second, mutually disjoint sets of logical communication port numbers that are used by different, respective first and second software systems in the given software category,

to identify port scans in data traffic transmitted between multiple nodes that communicate over a network, each of the port scans comprising accesses, in the data traffic, of a plurality logical communication port numbers on a given destination node by a given source node during a predefined time period,

to classify a given port scan as suspicious upon detecting that in the given port scan the given source node has accessed on the given destination node both at least one of the logical communication port numbers in the first set and at least one of the logical communication port numbers in the second set, and

to initiate a protective action upon classifying the given port scan as suspicious.

12 . The apparatus according to claim 11 , wherein the at least one processor is configured to detect a failed connection between the given source node and a given logical port number in the first set on the given destination node.

13 . The apparatus according to claim 11 , wherein identifying the port scans comprises detecting accesses of at least a specified number of the logical communication port numbers in the first set, wherein the specified number is greater than one.

14 . The apparatus according to claim 11 , wherein identifying the port scans comprises detecting at least a specified number of the logical communication port numbers in each of the first and the second sets, wherein the specified number is greater than one.

15 . The apparatus according to claim 11 , wherein the first set consists of logical communication port numbers used by a first operating system, and the second set consists of logical communication port numbers used by a second operating system, different from the first operating system.

16 . The apparatus according to claim 11 , wherein the first set consists of logical communication port numbers used by a first database server, and the second set consists of logical communication port numbers used by a second database server, different from the first database server.

17 . The apparatus according to claim 11 , wherein the first set consists of logical communication port numbers used by a first email server, and the second set consists of logical communication port numbers used by a second email server, different from the first email server.

18 . The apparatus according to claim 11 , wherein the first set consists of logical communication port numbers used by a first remote session application, and the second set consists of logical communication port numbers used by a second remote session application, different from the first remote session application.

19 . The apparatus according to claim 11 , wherein the preventive action comprises generating an alert for the given source node in the detected port scan.

20 . The apparatus according to claim 11 , wherein the preventive action comprises restricting access of the given source node in the detected port scan to the network.

21 . A computer software product, the product comprising a non-transitory computer-readable medium, in which program instructions are stored, which instructions, when read by a computer, cause the computer:

to receive a definition of first and second, mutually disjoint sets of logical communication port numbers that are used by different, respective first and second software systems in the given software category;

to identify port scans in data traffic transmitted between multiple nodes that communicate over a network, each of the port scans comprising accesses, in the data traffic, of a plurality of the logical communication port numbers on a given destination node by a given source node during a predefined time period; and

to classify a given port scan as suspicious upon detecting that in the given port scan the given source node has accessed on the given destination node both at least one of the logical communication port numbers in the first set and at least one of the logical communication port numbers in the second set; and

to initiate a protective action upon classifying the given port scan as suspicious.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
To: PALO ALTO NETWORKS INC.
Reel/Frame 068823/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 22, 2022
From: MESHI, YINNON; AMIT, IDAN; ALLON, JONATHAN; MEYER, AVIAD
To: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
Reel/Frame 059469/0409 →
Continuity (2)
Continuation 16261634 · Jan 30, 2019
Related Publication 20220217162A1 · Jul 7, 2022
References Cited (178)
US 7003790B1 · Inoue et al. · 2006 [cited by applicant]
US 7007301B2 · Crosbie et al. · 2006 [cited by applicant]
US 7684568B2 · Yonge, III et al. · 2010 [cited by applicant]
US 8516586B1 · Jensen et al. · 2013 [cited by applicant]
US 8578345B1 · Kennedy et al. · 2013 [cited by applicant]
US 9319421B2 · Ferragut et al. · 2016 [cited by applicant]
US 9531736B1 · Torres et al. · 2016 [cited by applicant]
US 9690606B1 · Ha et al. · 2017 [cited by applicant]
US 9690933B1 · Singh et al. · 2017 [cited by applicant]
US 9773112B1 · Rathor et al. · 2017 [cited by applicant]
US 10181032B1 · Sadaghiani et al. · 2019 [cited by applicant]
US 10360367B1 · Mossoba et al. · 2019 [cited by applicant]
US 10587642B1 · Herman-Saffar et al. · 2020 [cited by applicant]
US 10706144B1 · Moritz et al. · 2020 [cited by applicant]
US 10728262B1 · Vaswani et al. · 2020 [cited by applicant]
US 10904277B1 · Mehr · 2021 [cited by applicant]
US 11100199B2 · Subramaniam · 2021 [cited by applicant]
US 11501261B1 · Schemers et al. · 2022 [cited by applicant]
US 12045610B1 · Myers et al. · 2024 [cited by applicant]
US 12380389B2 · Schmidt et al. · 2025 [cited by applicant]
US 20050015624A1 · Ginter et al. · 2005 [cited by applicant]
US 20050069130A1 · Kobayashi · 2005 [cited by applicant]
US 20050071330A1 · Douceur et al. · 2005 [cited by applicant]
US 20050123138A1 · Abe et al. · 2005 [cited by applicant]
US 20050183120A1 · Jain et al. · 2005 [cited by applicant]
US 20050262556A1 · Waisman et al. · 2005 [cited by applicant]
US 20060190803A1 · Kawasaki et al. · 2006 [cited by applicant]
US 20070011319A1 · McClure · 2007 [cited by examiner]
US 20070073519A1 · Long · 2007 [cited by applicant]
US 20070116277A1 · Ro et al. · 2007 [cited by applicant]
US 20070124474A1 · Margulis · 2007 [cited by applicant]
US 20070201691A1 · Kumagaya · 2007 [cited by applicant]
US 20070201693A1 · Ohno · 2007 [cited by applicant]
US 20080013725A1 · Kobayashi · 2008 [cited by applicant]
US 20080244097A1 · Candelore et al. · 2008 [cited by applicant]
US 20080301567A1 · Martin et al. · 2008 [cited by applicant]
US 20100014594A1 · Beheydt et al. · 2010 [cited by applicant]
US 20100146292A1 · Shi et al. · 2010 [cited by applicant]
US 20100146293A1 · Shi et al. · 2010 [cited by applicant]
US 20100146501A1 · Wyatt et al. · 2010 [cited by applicant]
US 20100272257A1 · Beals · 2010 [cited by applicant]
US 20110135090A1 · Chan et al. · 2011 [cited by applicant]
US 20110138463A1 · Kim et al. · 2011 [cited by applicant]
US 20110271343A1 · Kim et al. · 2011 [cited by applicant]
US 20110317770A1 · Lehtiniemi et al. · 2011 [cited by applicant]
US 20120308008A1 · Kondareddy et al. · 2012 [cited by applicant]
US 20130061045A1 · Kiefer et al. · 2013 [cited by applicant]
US 20140010367A1 · Wang · 2014 [cited by applicant]
US 20140201776A1 · Minemura et al. · 2014 [cited by applicant]
US 20150026810A1 · Friedrichs et al. · 2015 [cited by applicant]
US 20150032884A1 · Greifender et al. · 2015 [cited by applicant]
US 20150156270A1 · Teraoka et al. · 2015 [cited by applicant]
US 20150180883A1 · Aktas et al. · 2015 [cited by applicant]
US 20150207694A1 · Inches · 2015 [cited by examiner]
US 20150295903A1 · Yi et al. · 2015 [cited by applicant]
US 20150324188A1 · Raje et al. · 2015 [cited by applicant]
US 20150356451A1 · Gupta et al. · 2015 [cited by applicant]
US 20160028758A1 · Ellis et al. · 2016 [cited by applicant]
US 20160119292A1 · Kaseda et al. · 2016 [cited by applicant]
US 20160142746A1 · Schuberth · 2016 [cited by applicant]
US 20160359895A1 · Chiu et al. · 2016 [cited by applicant]
US 20170007128A1 · Takano et al. · 2017 [cited by applicant]
US 20170171229A1 · Arzi et al. · 2017 [cited by applicant]
US 20170171231A1 · Reybok et al. · 2017 [cited by applicant]
US 20170289178A1 · Roundy et al. · 2017 [cited by applicant]
US 20170294112A1 · Kushnir · 2017 [cited by applicant]
US 20170295190A1 · Brown · 2017 [cited by applicant]
US 20170374090A1 · McGrew et al. · 2017 [cited by applicant]
US 20180007013A1 · Wang · 2018 [cited by applicant]
US 20180048662A1 · Jang et al. · 2018 [cited by applicant]
US 20180077189A1 · Doppke et al. · 2018 [cited by applicant]
US 20180124077A1 · Carver et al. · 2018 [cited by applicant]
US 20180288081A1 · Yermakov · 2018 [cited by applicant]
US 20180365416A1 · Monastyrsky et al. · 2018 [cited by applicant]
US 20180373820A1 · Knezevic · 2018 [cited by examiner]
US 20190036978A1 · Shulman-Peleg et al. · 2019 [cited by applicant]
US 20190044965A1 · Pilkington et al. · 2019 [cited by applicant]
US 20190068620A1 · Avrahami et al. · 2019 [cited by applicant]
US 20190075344A1 · Brown · 2019 [cited by applicant]
US 20190098025A1 · Lim · 2019 [cited by applicant]
US 20190207966A1 · Vashisht et al. · 2019 [cited by applicant]
US 20190268361A1 · Blewett et al. · 2019 [cited by applicant]
US 20190297097A1 · Gong et al. · 2019 [cited by applicant]
US 20200033144A1 · Du et al. · 2020 [cited by applicant]
US 20200065483A1 · Mu et al. · 2020 [cited by applicant]
US 20200082296A1 · Fly et al. · 2020 [cited by applicant]
US 20200136889A1 · Chen et al. · 2020 [cited by applicant]
US 20200162252A1 · Davis et al. · 2020 [cited by applicant]
US 20200162494A1 · Rostami-Hesarsorkh · 2020 [cited by applicant]
US 20200167491A1 · Grabois et al. · 2020 [cited by applicant]
US 20200193019A1 · Tietz et al. · 2020 [cited by applicant]
US 20200274894A1 · Argoeti et al. · 2020 [cited by applicant]
US 20200285737A1 · Kraus et al. · 2020 [cited by applicant]
US 20200293917A1 · Wang et al. · 2020 [cited by applicant]
US 20200327221A1 · Street · 2020 [cited by applicant]
US 20200327225A1 · Nguyen et al. · 2020 [cited by applicant]
US 20200342230A1 · Tsai et al. · 2020 [cited by applicant]
US 20200374301A1 · Manevich et al. · 2020 [cited by applicant]
US 20210004458A1 · Edwards et al. · 2021 [cited by applicant]
US 20210176261A1 · Yavo et al. · 2021 [cited by applicant]
US 20210182387A1 · Zhu et al. · 2021 [cited by applicant]
US 20210209228A1 · Maor et al. · 2021 [cited by applicant]
US 20210224676A1 · Arzani et al. · 2021 [cited by applicant]
US 20210248503A1 · Hickey et al. · 2021 [cited by applicant]
US 20210264028A1 · Genc et al. · 2021 [cited by applicant]
US 20210266339A1 · Moshitzky et al. · 2021 [cited by applicant]
US 20210286877A1 · Vijayvargiya et al. · 2021 [cited by applicant]
US 20210304204A1 · Ramesh et al. · 2021 [cited by applicant]
US 20220086178A1 · Jayamohan et al. · 2022 [cited by applicant]
US 20220129551A1 · Collier et al. · 2022 [cited by applicant]
US 20220138856A1 · Ahlstrom et al. · 2022 [cited by applicant]
US 20220217166A1 · Ladnai et al. · 2022 [cited by applicant]
US 20230007023A1 · Andrabi et al. · 2023 [cited by applicant]
US 20230026385A1 · Zhang et al. · 2023 [cited by applicant]
US 20230075355A1 · Twigg et al. · 2023 [cited by applicant]
US 20230114821A1 · Thomas et al. · 2023 [cited by applicant]
US 20230117120A1 · Johnson · 2023 [cited by applicant]
US 20230129144A1 · Neil et al. · 2023 [cited by applicant]
US 20230164039A1 · Vadlamani · 2023 [cited by applicant]
US 20230229771A1 · Sameer et al. · 2023 [cited by applicant]
US 20230247048A1 · Samosseiko et al. · 2023 [cited by applicant]
US 20230403294A1 · Bazalgette et al. · 2023 [cited by applicant]
US 20240095350A1 · Withnell et al. · 2024 [cited by applicant]
US 20240126910A1 · Johnson et al. · 2024 [cited by applicant]
US 20240289461A1 · Ko et al. · 2024 [cited by applicant]
US 20240303529A1 · Rane et al. · 2024 [cited by applicant]
US 20240338489A1 · Zhu et al. · 2024 [cited by applicant]
US 20240378423A1 · Gunnai et al. · 2024 [cited by applicant]
US 20240380766A1 · Shachar et al. · 2024 [cited by applicant]
US 20240386015A1 · Crabtree et al. · 2024 [cited by applicant]
US 20240414178A1 · Neuvirth-Telem et al. · 2024 [cited by applicant]
US 20250094585A1 · Wuest et al. · 2025 [cited by applicant]
US 20250173431A1 · Divakaran et al. · 2025 [cited by applicant]
US 20250181718A1 · Saqib et al. · 2025 [cited by applicant]
US 20250217479A1 · Palanki · 2025 [cited by applicant]
US 20250247402A1 · Singla · 2025 [cited by applicant]
US 20250260712A1 · Hong et al. · 2025 [cited by applicant]
CA 3041875A1 · 2019 [cited by applicant]
CN 103561048A · 2014 [cited by applicant]
CN 114640507A · 2022 [cited by applicant]
CN 115396324A · 2022 [cited by applicant]
CN 116074031A · 2023 [cited by applicant]
CN Application # Office Action dated Nov. 30, 2022. [cited by applicant]
U.S. Appl. No. 17/175,720 Office Action dated Nov. 7, 2022. [cited by applicant]
U.S. Appl. No. 17/506,713 Office Action dated Nov. 8, 2022. [cited by applicant]
Brownlee et al., “Traffic Flow Measurement: Architecture,” Request for Comments 2722, Network Working Group, pp. 1-48, Oct. 1999. [cited by applicant]
Xu, “Correlation Analysis of Intrusion Alerts,” Dissertation in Computer Science submitted to the Graduate Faculty, North Carolina State University, pp. 1-206, year 2006. [cited by applicant]
U.S. Appl. No. 17/038,285 Office Action dated Mar. 21, 2022. [cited by applicant]
International Application # PCT/IB2022/059544 Search Report dated Jan. 20, 2023. [cited by applicant]
International Application # PCT/IB2022/060920 Search Report dated Feb. 7, 2023. [cited by applicant]
EP Application # 19832439.4 Office Action dated Mar. 1, 2023. [cited by applicant]
U.S. Appl. No. 17/175,720 Office Action dated Mar. 20, 2023. [cited by applicant]
International Application # PCT/IB2022/061926 Search Report dated Mar. 27, 2023. [cited by applicant]
U.S. Appl. No. 17/464,716 Office Action dated Apr. 14, 2023. [cited by applicant]
U.S. Appl. No. 17/464,709 Office Action dated Apr. 14, 2023. [cited by applicant]
U.S. Appl. No. 17/571,558 Office Action dated Jun. 26, 2023. [cited by applicant]
U.S. Appl. No. 17/505,673 Office Action dated Sep. 25, 2023. [cited by applicant]
AU Application # 2021351215 Office Action dated Nov. 28, 2023. [cited by applicant]
U.S. Appl. No. 17/676,275 Office Action dated Feb. 29, 2024. [cited by applicant]
AU Application # 2022370400 Office Action dated Jun. 12, 2024. [cited by applicant]
International Application # PCT/IB2024/052646 Search Report dated Jun. 14, 2024. [cited by applicant]
U.S. Appl. No. 17/676,275 Office Action dated Sep. 6, 2024. [cited by applicant]
U.S. Appl. No. 18/361,850 Office Action dated May 3, 2025. [cited by applicant]
U.S. Appl. No. 17/676,275 Office Action dated Jun. 16, 2025. [cited by applicant]
U.S. Appl. No. 18/357,121 Office Action dated May 2, 2025. [cited by applicant]
Final Office Action for U.S. Appl. No. 18/357,121, dated Oct. 23, 2025. [cited by applicant]
Notice of References Cited for U.S. Appl. No. 18/357,121, dated Oct. 23, 2025. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/661,626, dated Oct. 1, 2025. [cited by applicant]
Notice of References Cited for U.S. Appl. No. 18/661,626, dated Oct. 1, 2025. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/783,523, dated Oct. 21, 2025. [cited by applicant]
Notice of References Cited for U.S. Appl. No. 18/783,523, dated Oct. 21, 2025. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/731,420, dated Oct. 2, 2025. [cited by applicant]
Notice of References Cited for U.S. Appl. No. 18/731,420, dated Oct. 2, 2025. [cited by applicant]
Final Office Action for U.S. Appl. No. 18/361,850, dated Sep. 30, 2025. [cited by applicant]
Notice of References Cited for U.S. Appl. No. 18/361,850, dated Sep. 30, 2025. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/322,231, dated Sep. 30, 2025. [cited by applicant]
Second Office Action, Chinese Application No. 202310649426.9, dated Sep. 16, 2025. [cited by applicant]
Notice of References Cited for U.S. Appl. No. 18/322,231, dated Sep. 30, 2025. [cited by applicant]