IP Library › Granted Patent US 12,273,363
Granted Patent B2
US 12,273,363 · App. 18/047,891 · Granted Apr 8, 2025

System and method for detecting a malicious command and control channel using a simple mail transfer protocol

Inventors: Ammar Abdulateef Almulhim (Dammam, SA); Ghadah Hatem Alshehri (Dammam, SA)
Assignee: SAUDI ARABIAN OIL COMPANY
H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,273,363
App. No.
18/047,891
Granted
Apr 8, 2025
Kind
B2
Abstract

In an example, simple mail traffic protocol (SMTP) traffic can be extracted from network traffic of a network. The SMTP traffic can be processed using a bot detector employing a machine learning model trained to determine whether the SMTP traffic contains a malicious SMTP session. Alert data can be provided in response to detecting the malicious SMTP session.

Claims (45)

1. A computer-implemented method comprising:

extracting simple mail traffic protocol (SMTP) traffic from network traffic of a network;

processing the SMTP traffic using a bot detector employing a machine learning model trained to determine whether the SMTP traffic contains a malicious SMTP session, wherein training the machine learning model is based on at least:

a list of internet protocol (IP) addresses that are associated with one or more command and control servers;

known completion times for a given handshake based on previously captured network traffic; and

determining that a completion time for establishing a handshake during the malicious SMTP session exceeds a setup time threshold or is outside a setup time range to identify potential bot traffic; and

outputting alert data in response to detecting the malicious SMTP session, wherein the alert data identifies:

an IP address for a host on the network that includes a bot; and

one or more packets associated with the handshake between the bot and the command and control server.

2. The computer-implemented method of claim 1 , wherein the processing comprises determining, using the machine learning model, whether the SMTP traffic contains messages with data content that does not conform to a known email standard.

3. The computer-implemented method of claim 2 , wherein the alert data identifies one or more packets of the SMTP traffic corresponding to bot traffic.

4. The computer-implemented method of claim 1 , wherein the processing comprises determining, using the machine learning model, whether the SMTP traffic contains a sequence and/or syntax of SMTP commands associated with the malicious SMTP session.

5. The computer-implemented method of claim 4 , wherein the alert data identifies one or more packets of the SMTP traffic corresponding to bot traffic.

6. The computer-implemented method of claim 1 , wherein the extracting comprises one of:

identifying one or more SMTP commands and/or corresponding SMTP arguments in the network traffic and flagging associated packets to provide the SMTP traffic; and

implementing port filtering on the network traffic based on an SMTP port to identify packets associated with the respective SMTP port to provide the SMTP traffic.

7. The computer-implemented method claim 1 , further comprising:

identifying, using a learning algorithm, a subset of sequence and/or syntax of SMTP commands from previously captured network traffic;

training the machine learning model based on the subset of sequence and/or syntax of SMTP commands; and

determining, using the machine learning model, whether the SMTP traffic contains a sequence and/or syntax of SMTP commands associated with the malicious SMTP session.

8. The computer-implemented method of claim 7 , further comprising:

training the machine learning model based on a subset of messages with data content that conforms to a known email standard from the previously captured network traffic; and

determining, using the machine learning model, whether the SMTP traffic contains messages with data content that does not conform to the known email standard.

9. The computer-implemented method of claim 8 , wherein the known email standard is an Internet Message Format (IMF) standard.

10. The computer-implemented method of claim 9 , further comprising:

determining, using the machine learning model, that an IP of the command and control server matches a respective one of the IP addresses, the alert data identifying the host that includes the bot.

11. The computer-implemented method of claim 10 , further comprising:

training the machine learning model further based on known time to live (TTL) values from the previously captured network traffic; and

determining that a TLL value from a packet of the SMTP traffic exceeds a threshold or is not within a TLL value range to identify potential bot traffic, the alert data identifying the packet with the TLL value that exceeds the threshold or is not within the TLL value range.

12. A system comprising:

memory to store machine-readable instructions and data comprising a machine learning model;

one or more processors to access the memory and execute the machine-readable instructions,

the machine-readable instructions comprising:

a network traffic filter programmed to process network traffic to extract simple mail transfer protocol (SMTP) traffic;

a traffic analyzer programmed to:

determine, using the machine learning model, whether the SMTP traffic contains messages with data content that does not conform to a known email standard or contain a sequence and/or syntax of SMTP commands associated with an SMTP session between a bot and a command and control server, wherein the machine learning model is trained based on at least:

a list of internet protocol (IP) addresses that are associated with the one or more command and control servers; and

known completion times for a given handshake based on previously captured network traffic;

determine that a completion time for establishing a handshake during the SMTP session exceeds a setup time threshold or is outside a setup time range to identify potential bot traffic; and

output alert data in response to detecting the SMTP session between the bot and the command and control server, wherein the alert data identifies:

an IP address for a host on the network that includes the bot; and

one or more packets associated with the handshake between the bot and the command and control server.

13. The system of claim 12 , wherein the alert data identifies one or more packets of the SMTP traffic corresponding to bot traffic.

14. The system of claim 13 , wherein the known email standard is an Internet Message Format (IMF) standard.

15. The system of claim 12 , wherein the traffic analyzer is further programmed to determine, using the machine learning model, that an IP of the command and control server matches a respective one of the IP addresses, the alert data identifying the host that includes the bot.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2022
From: ALMULHIM, AMMAR ABDULATEEF; ALSHEHRI, GHADAH HATEM
To: SAUDI ARABIAN OIL COMPANY
Reel/Frame 061473/0089 →
Continuity (2)
Related Publication 20240137371A1 · Apr 25, 2024
Related Publication 20240236116A9 · Jul 11, 2024
References Cited (13)
US 8677487B2 · Balupari et al. · 2014 [cited by applicant]
US 9363282B1 · Yu · 2016 [cited by examiner]
US 10681062B2 · Carver et al. · 2020 [cited by applicant]
US 20030200272A1 · Campise · 2003 [cited by examiner]
US 20070277238A1 · Margalit · 2007 [cited by examiner]
US 20170285584A1 · Nakagawa et al. · 2017 [cited by applicant]
US 20190166144A1 · Mirsky · 2019 [cited by examiner]
US 20210250364A1 · Webster · 2021 [cited by examiner]
US 20230319065A1 · Mears · 2023 [cited by examiner]
M. Warmer, “Detection of Web Based Command & Control Channels,” University of Twente, 2011. [cited by applicant]
Alauthman, M. “Botnet Spam E-Mail Detection Using Deep Recurrent Neural Network.” International Journal of Emerging Trends in Engineering Research 8.5 1979-1986. [cited by applicant]
P. Barthakur, M. Dahal And M. Ghose, “An Efficient Machine Learning Based Classification Scheme for Detecting Distributed Command & Control Traffic of P2P Botnets,” I.J.Modern Education and Computer Science, 2013, 10, 9… [cited by applicant]
Bazydlo, P., Lasota, K., and Kozakiewicz, A., “Botnet fingerprinting method based on anomaly detection in SMTP conversations”, 2017. [cited by applicant]