IP Library Granted Patent US 12,506,729
Granted Patent B2
US 12,506,729 · App. 17/844,097 · Granted Dec 23, 2025

Detecting credentials abuse of cloud compute services

Inventors: Dror Alon (Beer Yaakov, IL); Niv Sela (Tel Aviv-Jaffa, IL); Or Kliger (Tel Aviv, IL); Guy Arazi (Rosh Haayin, IL)
Assignee: Palo Alto Networks, Inc.
H04L63/083H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,729
App. No.
17/844,097
Granted
Dec 23, 2025
Kind
B2
Abstract

Methods, storage systems and computer program products implement embodiments of the present invention that include identifying a first autonomous system number (ASN) for a service hosted by a networked entity, and retrieving, from a log file, an entry corresponding to an access by a networked entity to the service and including an Internet Protocol (IP) address of the networked entity and an access token authorizing access to the service. A second ASN for the IP address is identified, and the second ASN is compared to the first ASN. Finally, an alert is generated for the access upon detecting the first ASN differing from the second ASN.

Claims (24)

1 . A method, comprising, by a processor:

detecting an access by a networked entity to a service associated with a first autonomous system number (ASN) using an access token that is assigned to entities associated with the first ASN and authorizes access to the service, the networked entity having an Internet Protocol (IP) address;

determining whether the networked entity is authorized to use the access token by:

identifying a second ASN for the IP address, and

comparing the second ASN to the first ASN, wherein if the second ASN differs from the first ASN the networked entity is not authorized to use the access token; and

generating an alert upon determining that the networked entity is not authorized to use the access token.

2 . The method according to claim 1 , and further comprising identifying a first organization associated with the first ASN, and a second organization associated with the second ASN.

3 . The method according to claim 2 , wherein the generated alert comprises a first alert upon determining that the first organization matches the second organization, wherein the generated alert comprises a second alert upon determining that the first organization does not match the second organization, and wherein the second alert indicates a greater threat than the first alert.

4 . An apparatus, comprising:

a network interface controller (NIC); and

one or more processors configured:

to detect an access by a networked entity to a service associated with a first autonomous system number (ASN) using an access token that is assigned to entities associated with the first ASN and authorizes access to the service, the networked entity having an Internet Protocol (IP) address,

to determine whether the networked entity is authorized to use the access token by:

identifying a second ASN for the IP address, and

comparing the second ASN to the first ASN, wherein if the second ASN differs from the first ASN the networked entity is not authorized to use the access token; and

to generate an alert upon determining that the networked entity is not authorized to use the access token.

5 . The apparatus according to claim 4 , wherein a given processor is further configured to identify a first organization associated with the first ASN, and a second organization associated with the second ASN.

6 . The apparatus according to claim 5 , wherein the generated alert comprises a first alert upon a given processor determining that the first organization matches the second organization, wherein the generated alert comprises a second alert upon the given processor determining that the first organization does not match the second organization, and wherein the second alert indicates a greater threat than the first alert.

7 . A computer software product, the product comprising a non-transitory computer-readable medium, in which program instructions are stored, which instructions, when read by a computer, cause the computer:

to detect an access by a networked entity to a service associated with a first autonomous system number (ASN) using an access token that is assigned to entities associated with the first ASN and authorizes access to the service, the networked entity having an Internet Protocol (IP) address,

to determine whether the networked entity is authorized to use the access token by:

identifying a second ASN for the IP address, and

comparing the second ASN to the first ASN, wherein if the second ASN differs from the first ASN the networked entity is not authorized to use the access token; and

to generate an alert upon determining that the networked entity is not authorized to use the access token.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
To: PALO ALTO NETWORKS INC.
Reel/Frame 068823/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2022
From: ALON, DROR; SELA, NIV; KLIGER, OR; ARAZI, GUY
To: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
Reel/Frame 060245/0909 →
Continuity (1)
Related Publication 20230412588A1 · Dec 21, 2023
References Cited (175)
US 8146146B1 · Coviello · 2012 [cited by examiner]
US 8245304B1 · Chen et al. · 2012 [cited by applicant]
US 8285830B1 · Stout · 2012 [cited by examiner]
US 8316440B1 · Hsieh · 2012 [cited by examiner]
US 8555388B1 · Wang et al. · 2013 [cited by applicant]
US 8561188B1 · Wang et al. · 2013 [cited by applicant]
US 8677487B2 · Balupari et al. · 2014 [cited by applicant]
US 8713674B1 · Geide · 2014 [cited by examiner]
US 8826434B2 · Merza · 2014 [cited by applicant]
US 8893286B1 · Oliver · 2014 [cited by applicant]
US 8955114B2 · Dolan-Gavitt et al. · 2015 [cited by applicant]
US 8966625B1 · Zuk et al. · 2015 [cited by applicant]
US 9038178B1 · Lin et al. · 2015 [cited by applicant]
US 9130982B2 · Gottlieb et al. · 2015 [cited by applicant]
US 9147071B2 · Sallam · 2015 [cited by applicant]
US 9154516B1 · Vaystikh et al. · 2015 [cited by applicant]
US 9215239B1 · Wang et al. · 2015 [cited by applicant]
US 9342691B2 · Maestas · 2016 [cited by applicant]
US 9378361B1 · Yen et al. · 2016 [cited by applicant]
US 9386028B2 · Altman · 2016 [cited by applicant]
US 9462008B2 · Bartos et al. · 2016 [cited by applicant]
US 9998484B1 · Buyukkayhan et al. · 2018 [cited by applicant]
US 10148690B2 · Shen et al. · 2018 [cited by applicant]
US 10257295B1 · Alpert et al. · 2019 [cited by applicant]
US 10425436B2 · Firstenberg et al. · 2019 [cited by applicant]
US 10574681B2 · Meshi et al. · 2020 [cited by applicant]
US 10587647B1 · Khalid et al. · 2020 [cited by applicant]
US 10601866B2 · Bartik et al. · 2020 [cited by applicant]
US 10623446B1 · Stoler · 2020 [cited by examiner]
US 11457040B1 · Sole · 2022 [cited by examiner]
US 11516232B1 · Sumpter · 2022 [cited by examiner]
US 20030105980A1 · Challener et al. · 2003 [cited by applicant]
US 20030110379A1 · Ylonen et al. · 2003 [cited by applicant]
US 20060200487A1 · Adelman · 2006 [cited by examiner]
US 20070064617A1 · Reves · 2007 [cited by applicant]
US 20070143852A1 · Keanini et al. · 2007 [cited by applicant]
US 20080034425A1 · Overcash et al. · 2008 [cited by applicant]
US 20080060054A1 · Srivastava · 2008 [cited by examiner]
US 20080082662A1 · Dandliker et al. · 2008 [cited by applicant]
US 20080256622A1 · Neystadt et al. · 2008 [cited by applicant]
US 20090119397A1 · Neerdaels · 2009 [cited by applicant]
US 20100042622A1 · Matkowsky · 2010 [cited by examiner]
US 20100235915A1 · Memon · 2010 [cited by examiner]
US 20110016525A1 · Jeong et al. · 2011 [cited by applicant]
US 20110066624A1 · Turakhia · 2011 [cited by applicant]
US 20110185429A1 · Sallam · 2011 [cited by applicant]
US 20110239300A1 · Klein et al. · 2011 [cited by applicant]
US 20110283357A1 · Pandrangi et al. · 2011 [cited by applicant]
US 20110302656A1 · El-Moussa · 2011 [cited by applicant]
US 20120158626A1 · Zhu et al. · 2012 [cited by applicant]
US 20130007233A1 · Lv et al. · 2013 [cited by applicant]
US 20130031625A1 · Lim · 2013 [cited by applicant]
US 20140007238A1 · Magee et al. · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140181973A1 · Lee et al. · 2014 [cited by applicant]
US 20150128263A1 · Raugas et al. · 2015 [cited by applicant]
US 20150149530A1 · Maret · 2015 [cited by examiner]
US 20150170072A1 · Grant et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150195299A1 · Zoldi · 2015 [cited by examiner]
US 20150358344A1 · Mumcuoglu et al. · 2015 [cited by applicant]
US 20150365437A1 · Bell, Jr. et al. · 2015 [cited by applicant]
US 20150373039A1 · Wang · 2015 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20160042287A1 · Eldardiry et al. · 2016 [cited by applicant]
US 20160057165A1 · Thakar et al. · 2016 [cited by applicant]
US 20160099852A1 · Cook et al. · 2016 [cited by applicant]
US 20160104203A1 · Roosenraad et al. · 2016 [cited by applicant]
US 20160134651A1 · Hu et al. · 2016 [cited by applicant]
US 20160150004A1 · Hentunen · 2016 [cited by examiner]
US 20160156655A1 · Lotem et al. · 2016 [cited by applicant]
US 20160234167A1 · Engel et al. · 2016 [cited by applicant]
US 20160294773A1 · Yu et al. · 2016 [cited by applicant]
US 20160352772A1 · O'Connor · 2016 [cited by applicant]
US 20160366159A1 · Chiba · 2016 [cited by examiner]
US 20170026398A1 · Mumcuoglu et al. · 2017 [cited by applicant]
US 20170041333A1 · Mahjoub · 2017 [cited by examiner]
US 20170063885A1 · Wardman · 2017 [cited by examiner]
US 20170098086A1 · Hoernecke et al. · 2017 [cited by applicant]
US 20170111338A1 · Malatesha · 2017 [cited by examiner]
US 20170123875A1 · Craik et al. · 2017 [cited by applicant]
US 20170126718A1 · Baradaran et al. · 2017 [cited by applicant]
US 20170149807A1 · Schilling et al. · 2017 [cited by applicant]
US 20170244745A1 · Key et al. · 2017 [cited by applicant]
US 20170323548A1 · Glatfelter et al. · 2017 [cited by applicant]
US 20180013778A1 · Lim et al. · 2018 [cited by applicant]
US 20180054449A1 · Nandha et al. · 2018 [cited by applicant]
US 20180063174A1 · Grill · 2018 [cited by examiner]
US 20180069884A1 · Firstenberg · 2018 [cited by examiner]
US 20180139224A1 · Amell et al. · 2018 [cited by applicant]
US 20180285567A1 · Raman · 2018 [cited by applicant]
US 20180288073A1 · Hopper · 2018 [cited by applicant]
US 20180351930A1 · Kim et al. · 2018 [cited by applicant]
US 20190007440A1 · Lavi et al. · 2019 [cited by applicant]
US 20190058724A1 · Kraning et al. · 2019 [cited by applicant]
US 20190068575A1 · Vongsouvanh · 2019 [cited by examiner]
US 20190068624A1 · Compton · 2019 [cited by examiner]
US 20190068638A1 · Bartik et al. · 2019 [cited by applicant]
US 20190081952A1 · Wood · 2019 [cited by applicant]
US 20190190931A1 · Levin et al. · 2019 [cited by applicant]
US 20190250911A1 · Lospinuso et al. · 2019 [cited by applicant]
US 20190297097A1 · Gong et al. · 2019 [cited by applicant]
US 20190319977A1 · Gottschlich et al. · 2019 [cited by applicant]
US 20190319981A1 · Meshi et al. · 2019 [cited by applicant]
US 20190372934A1 · Yehudai et al. · 2019 [cited by applicant]
US 20190387005A1 · Zawoad et al. · 2019 [cited by applicant]
US 20200007548A1 · Sanghavi et al. · 2020 [cited by applicant]
US 20200014714A1 · Mortensen et al. · 2020 [cited by applicant]
US 20200067913A1 · Kapoor · 2020 [cited by examiner]
US 20200177625A1 · Rouvinen · 2020 [cited by applicant]
US 20200213333A1 · Deutschmann et al. · 2020 [cited by applicant]
US 20200233791A1 · Manzano et al. · 2020 [cited by applicant]
US 20200244658A1 · Meshi et al. · 2020 [cited by applicant]
US 20200364354A1 · Schwartz · 2020 [cited by examiner]
US 20200412717A1 · Puertas Calvo · 2020 [cited by examiner]
US 20210014198A1 · Amoudi et al. · 2021 [cited by applicant]
US 20210136037A1 · Balasubramaniam · 2021 [cited by applicant]
US 20210258325A1 · Meyer et al. · 2021 [cited by applicant]
US 20210266331A1 · Meshi et al. · 2021 [cited by applicant]
US 20210289371A1 · Bagwell · 2021 [cited by applicant]
US 20220006819A1 · Allon et al. · 2022 [cited by applicant]
US 20220070216A1 · Kohavi · 2022 [cited by applicant]
US 20220342976A1 · Stoyanov · 2022 [cited by examiner]
US 20220353284A1 · Vörös · 2022 [cited by examiner]
US 20220385694A1 · Zverkov et al. · 2022 [cited by applicant]
US 20230086281A1 · Kaidi · 2023 [cited by examiner]
US 20230093904A1 · Konda · 2023 [cited by examiner]
US 20230118679A1 · Mayer et al. · 2023 [cited by applicant]
US 20230403265A1 · Gaffney · 2023 [cited by examiner]
US 20240015176A1 · Egbert et al. · 2024 [cited by applicant]
CN 114077741A · 2022 [cited by applicant]
JP 2008243034A · 2008 [cited by applicant]
WO 2012167056A2 · 2012 [cited by applicant]
WO 2020148934A1 · 2020 [cited by applicant]
Palo Alto Networks, “CORTEX XSOAR—Phishing Investigation—Generic v2,” pp. 1-6, year 2020, as downloaded from https://web.archive.org/web/20200927223050/https://xsoar.pan.dev/docs/reference/playbooks/phishing-investigati… [cited by applicant]
Github, cburgmer/rasterizeHTML.js, pp. 1-2, Jan. 19, 2020, as downloaded from https://web.archive.org/web/20200219074432/https://github.com/cburgmer/rasterizeHTML.js. [cited by applicant]
REFSNES Data, “W3Schools,—HTML <form> Tag,” pp. 1-10, years 1999-2023, as downloaded from https://www.w3schools.com/tags/tag_form.asp. [cited by applicant]
REFSNES Data, “W3Schools,—HTML <input> Tag,” pp. 1-11, years 1999-2023, as downloaded from https://www.w3schools.com/tags/tag_input.asp. [cited by applicant]
Microsoft 365, “Exchange—Work Smarter with Business-Class Email and Calendaring,” pp. 1-4, Aug. 15, 2020, as downloaded from https://web.archive.org/web/20200815211502/https://www.microsoft.com/en-ww/microsoft-365/excha… [cited by applicant]
Wikipedia, “Selenium (Software),” pp. 1-5, last edited Dec. 3, 2019, as downloaded from https://web.archive.org/web/20191218132058/https://en.wikipedia.org/wiki/Selenium_(software). [cited by applicant]
Wikipedia, “Whois,” pp. 1-16, last edited Dec. 23, 2019, as downloaded from https://web.archive.org/web/20200112181104/https://en.wikipedia.org/wiki/WHOIS. [cited by applicant]
“British National Corpus,” Oxford Text Archive, IT Services, University of Oxford, p. 1-1, year 2015, as downloaded from https://web.archive.org/web/20200128044646/http://www.natcorp.ox.ac.uk/. [cited by applicant]
International Applicaton PCT/IB2023/056071 Search Report dated Sep. 22, 2023. [cited by applicant]
Alon, “Compromised Cloud Compute Credentials: Case Studies from the Wild,” Unit 42, Palo Alto Networks, Inc., bages 1-14, Dec. 8, 2022, as downloaded from as downloaded from https://unit42.paloaltonetworks.com/compromis… [cited by applicant]
JP Application # 2024504256 Office Action dated Jul. 2, 2024. [cited by applicant]
U.S. Appl. No. 16/798,466 Office Action dated Jan. 19, 2023. [cited by applicant]
Wei et al., “Identifying New Spam Domains by Hosting IPS: Improving Domain Blacklisting”, Dept. of Computer and Information Sciences, University of Alabama at Birmingham, pp. 1-8, Jan. 2010. [cited by applicant]
IANA., “Autonomous System (AS) Numbers”, 1 page, Jul. 29, 2016. [cited by applicant]
Gross et al., “FIRE: FInding Rogue nEtworks”, Annual Conference on Computer Security Applications, pp. 1-10, Dec. 7-11, 2009. [cited by applicant]
Frosch., “Mining DNS-related Data for Suspicious Features”, Ruhr Universitat Bochum, Master's Thesis, pp. 1-88, Dec. 23, 2011. [cited by applicant]
Bilge et at., “DISCLOSURE: Detecting Botnet Command and Control Servers Through Large-Scale NetFlow Analysis”, Annual Conference on Computer Security Applications, pp. 1-10, Dec. 3-7, 2012. [cited by applicant]
Blum., “Combining Labeled and Unlabeled Data with Co-Training”, Carnegie Mellon University, Research Showcase @ CMU, Computer Science Department, pp. 1-11, Jul. 1998. [cited by applicant]
Felegyhazi et al., “On the Potential of Proactive Domain Blacklisting”, LEET'10 Proceedings of the 3rd USENIX Conference on Large-scale exploits and emergent threats, pp. 1-8, San Jose, USA, Apr. 27, 2010. [cited by applicant]
Konte et al., “ASwatch: An AS Reputation System to Expose Bulletproof Hosting ASes”, SIGCOMM , pp. 625-638, Aug. 17-21, 2015. [cited by applicant]
Markowitz, N., “Bullet Proof Hosting: A Theoretical Model”, Security Week, pp. 1-5 ,Jun. 29, 2010, downloaded from http://www.infosecisland.com/blogview/4487-Bullet-Proof-Hosting-A-Theoretical-Model.html. [cited by applicant]
Markowitz, N., “Patterns of Use and Abuse with IP Addresses”, Security Week, pp. 1-4, Jul. 10, 2010, downloaded from http://infosecisland.com/blogview/5068-Patterns-of-Use-and-Abuse-with-IP-Addresses.html. [cited by applicant]
Goncharov, M., “Criminal Hideouts for Lease: Bulletproof Hosting Services”, Forward-Looking Threat Research (FTR) Team, A TrendLabsSM Research Paper, pp. 1-28, Jul. 3, 2015. [cited by applicant]
BILGE at al., “EXPOSURE: Finding Malicious Domains Using Passive DNS Analysis ”, NDSS Symposium, pp. 1-17 Feb. 6-9, 2011. [cited by applicant]
Xu et al., “We know it before you do: Predicting Malicious Domains”, Virus Bulletin Conference, pp. 73-33, Sep. 2014. [cited by applicant]
Palo Alto Networks, “Cortex XDR”, p. 1-7, year 2020. [cited by applicant]
U.S. Appl. No. 16/798,466 Office Action dated May 11, 2022. [cited by applicant]
“GeoIP Databases & Services: Industry Leading IP Intelligence,” MaxMind, Inc., pp. 1-3, updated Jan. 14, 2022, as downloaded from https://www.maxmind.com/en/geoip2-services-and-databases. [cited by applicant]
U.S. Appl. No. 16/789,442 Office Action dated Aug. 18, 2022. [cited by applicant]
U.S. Appl. No. 16/798,466 Office Action dated Aug. 25, 2022. [cited by applicant]
Mandiant, “Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims with SUNBURST Backdoor”, pp. 1-16, Dec. 13, 2020 downloaded from https://www.mandiant.com/resources/blog/evasive… [cited by applicant]
U.S. Appl. No. 17/857,196 Office Action dated Dec. 7, 2023. [cited by applicant]
U.S. Appl. No. 18/353,115 Office Action dated May 1, 2024. [cited by applicant]
JP Application # 2024504256 Office Action dated Oct. 8, 2024. [cited by applicant]
US Application # U.S. Appl. No. 17/844,097 Office Action dated Nov. 19, 2024. [cited by applicant]
U.S. Appl. No. 18/591,004 Office Action dated Dec. 3, 2024. [cited by applicant]
JP Application # 2024504256 Office Action dated Jan. 28, 2025. [cited by applicant]
Alsariera et al., “AI Meta-learners and Extra-trees Algorithm for the Detection of Phishing Websites,” IEEE Access, pp. 142532-145242, Aug. 14, 2020. [cited by applicant]
U.S. Appl. No. 18/295,857 Office Action Mar. 17, 2025. [cited by applicant]
U.S. Appl. No. 18/591,004 Office Action dated Apr. 7, 2025. [cited by applicant]
Final U.S. Office Action U.S. Appl. No. 18/475,266, dated Aug. 15, 2025. [cited by applicant]