IP Library Granted Patent US 12,621,313
Granted Patent B2
US 12,621,313 · App. 18/308,437 · Granted May 5, 2026

Detection of malicious beaconing in virtual private networks

Inventors: Sandeep Chandana (Fremont, CA); Aditya Kumar (Pune, IN); Ameya Mahesh Sanzgiri (Fremont, CA)
Assignee: Snowflake Inc.
H04L63/1416H04L41/16H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,313
App. No.
18/308,437
Filed
Apr 27, 2023
Granted
May 5, 2026
Kind
B2
Examiner
VU, VIET D
Art Unit
2455
USPC
726/22
Abstract

A computer-implemented method includes accessing virtual private cloud flow logs of network traffic data originating from a virtual private cloud, generating filtered flow logs by filtering the virtual private cloud flow logs, extracting features based on a plurality of attributes from the filtered flow logs, training one or more machine learning models based on the features, applying the one or more machine learning models to the network traffic data to identify potential beacons, generating an alert notification that identifies the potential beacons, and communicating the alert notification to an alerting system.

Claims (62)

1 . A computer-implemented method comprising:

accessing virtual private cloud flow logs of network traffic data originating from a virtual private cloud;

generating filtered flow logs by filtering the virtual private cloud flow logs;

extracting features based on a plurality of attributes from the filtered flow logs;

training one or more machine learning models based on the features, the training of the one or more machine learning models comprising at least one of:

training a virtual private cloud machine learning model for each virtual private cloud of a plurality of virtual private clouds;

training an account machine learning model for each account of the virtual private cloud; or

training a resource machine learning model for each resource of an account of the virtual private cloud;

applying the one or more machine learning models to the network traffic data to identify potential beacons;

generating an alert notification that identifies the potential beacons; and

communicating the alert notification to an alerting system.

2 . The computer-implemented method of claim 1 , further comprising:

scoring and ranking the potential beacons based on past occurrences and time decay weight.

3 . The computer-implemented method of claim 2 , wherein the scoring and ranking of the potential beacons are based on one or more of: frequency, regularity, duration, size, content, encryption status, destination domain reputation, or source device behavior.

4 . The computer-implemented method of claim 1 , further comprising:

receiving user feedback in response to communicating the alert notification to the alerting system; and

re-training the one or more machine learning models based on the user feedback.

5 . The computer-implemented method of claim 1 , further comprising:

receiving user feedback in response to communicating the alert notification to the alerting system;

identifying a first machine learning model of the one or more machine learning models based on the alert notification and the user feedback; and

re-training the first machine learning model based on the user feedback.

6 . The computer-implemented method of claim 1 , further comprising:

causing a display of the alert notification with a graphical user interface that allows a user to filter, sort, search, or export alerts.

7 . The computer-implemented method of claim 1 , wherein the network traffic data identifies a combination of source IP addresses, destination IP addresses, ports, protocols, payloads, timestamps, and intervals.

8 . The computer-implemented method of claim 1 , wherein the plurality of attributes includes a combination of a communication duration, time between communications, transferred data size, and a number of packets.

9 . The computer-implemented method of claim 1 , wherein the one or more machine learning models comprises at least one of isolating anomalies from n-dimensional space, Macbeth vector search, enclosing inliers, or auto-encoder.

10 . The computer-implemented method of claim 1 , wherein the one or more machine learning models are trained on labeled network traffic data that includes known examples of malicious and benign beacons.

11 . The computer-implemented method of claim 1 , the one or more machine learning models include one or more of: classification models, clustering models, anomaly detection models, or regression models.

12 . The computer-implemented method of claim 1 , wherein the virtual private cloud flow logs include a plurality of flow logs, each flow log corresponding to a virtual private cloud account.

13 . The computer-implemented method of claim 12 , wherein the virtual private cloud account operates a plurality of services.

14 . The computer-implemented method of claim 13 , wherein each machine learning models of the one or more machine learning models correspond to a service from the plurality of services.

15 . The computer-implemented method of claim 1 , wherein the alert notification comprises information about a source device, a destination host, beacon characteristics, and recommended actions.

16 . A computing apparatus comprising:

a processor; and

a memory storing instructions that, when executed by the processor, configure the apparatus to perform operations comprising:

accessing virtual private cloud flow logs of network traffic data originating from a virtual private cloud;

generating filtered flow logs by filtering the virtual private cloud flow logs;

extracting features based on a plurality of attributes from the filtered flow logs;

training one or more machine learning models based on the features, the training of the one or more machine learning models comprising at least one of:

training a virtual private cloud machine learning model for each virtual private cloud of a plurality of virtual private clouds;

training an account machine learning model for each account of the virtual private cloud; or

training a resource machine learning model for each resource of an account of the virtual private cloud;

applying the one or more machine learning models to the network traffic data to identify potential beacons;

generating an alert notification that identifies the potential beacons; and

communicating the alert notification to an alerting system.

17 . The computing apparatus of claim 16 , wherein the operations further comprise:

scoring and ranking the potential beacons based on past occurrences and time decay weight.

18 . A non-transitory computer-readable storage medium, the computer-readable storage medium including instructions that when executed by a computer, cause the computer to perform operations comprising:

accessing virtual private cloud flow logs of network traffic data originating from a virtual private cloud;

generating filtered flow logs by filtering the virtual private cloud flow logs;

extracting features based on a plurality of attributes from the filtered flow logs;

training one or more machine learning models based on the features, the training of the one or more machine learning models comprising at least one of:

training a virtual private cloud machine learning model for each virtual private cloud of a plurality of virtual private clouds;

training an account machine learning model for each account of the virtual private cloud; or

training a resource machine learning model for each resource of an account of the virtual private cloud;

applying the one or more machine learning models to the network traffic data to identify potential beacons;

generating an alert notification that identifies the potential beacons; and

communicating the alert notification to an alerting system.

19 . The non-transitory computer-readable storage medium of claim 18 , wherein the operations further comprise scoring and ranking the potential beacons based on past occurrences and time decay weight.

20 . The non-transitory computer-readable storage medium of claim 18 , wherein the operations further comprise:

receiving user feedback in response to communicating the alert notification to the alerting system; and

re-training the one or more machine learning models based on the user feedback.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2023
From: CHANDANA, SANDEEP; KUMAR, ADITYA; SANZGIRI, AMEYA MAHESH
To: SNOWFLAKE INC.
Reel/Frame 064667/0580 →
Continuity (1)
Related Publication 20240364712A1 · Oct 31, 2024
References Cited (4)
US 11716338B2 · Elyashiv · 2023 [cited by examiner]
US 20190114417A1 · Subbarayan · 2019 [cited by examiner]
US 20220067146A1 · Cai · 2022 [cited by examiner]
US 20240244070A1 · Mohapatra · 2024 [cited by examiner]