IP Library Patent Application 18361850
Patent Application
App. No. 18/361,850

Network alert enrichment

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/361,850
Abstract

A method, including collecting, during a time period from multiple computers, reports of events, each of the events including communication activity performed by a process having a respective ID and executing on one of the computers. Respective sets of features including characteristics of the activity are generated from the reports, and a model is trained for identifying, based on the features of one or more of the events, the ID of one of the processes performing the one or more of the events. An alert indicating malicious activity and referencing one or more reports of additional communication events performed by a given computer is received from a network management device, and the model is applied to the one or more reports so as to identify, on the given computer, a given ID of a given process responsible for the alert. Finally, a protective action is initiated for the given process.

Claims (42)

1 . A method, comprising:

collecting, during a time period from security agents executing on respective host computers, reports of communication events, each of the communication events comprising communication activity performed by a process having a respective process identifier (ID) and executing on one of the host computers;

generating, from each of the collected reports, a set of features comprising characteristics of the communication activity and the respective process ID;

training, by a processor, a model for identifying, based on the features of one or more of the events, the process ID of one of the processes performing the one or more of the events;

receiving, from a network management device subsequent to the time period, an alert indicating malicious activity and referencing one or more reports of additional communication events performed by a given host computer;

applying the model to the one or more reports of additional communication events so as to identify, on the given host computer, a given process ID of a given process responsible for the alert; and

initiating a protective action with respect to at least the given process executing on the given host computer.

2 . The method according to claim 1 , wherein the network management device comprises a firewall.

3 . The method according to claim 1 , wherein generating a given feature comprises extracting a given feature from a given collected report.

4 . The method according to claim 3 , wherein generating a given feature comprises normalizing the extracted given feature.

5 . The method according to claim 3 , wherein generating a given feature comprises computing the given feature based on one or more of the extracted features.

6 . The method according to claim 3 , wherein a given feature comprises a domain.

7 . The method according to claim 3 , wherein a given feature comprises an Internet Protocol (IP) address.

8 . The method according to claim 7 , wherein a given feature indicates whether or not the IP address comprises an Autonomous System Number (ASN).

9 . The method according to claim 3 , wherein a given feature comprises a JA3 fingerprint.

10 . The method according to claim 3 , wherein a given feature comprises a JA3S fingerprint.

11 . The method according to claim 3 , wherein a given feature comprises a Server Name Indication (SNI) hostname.

12 . The method according to claim 3 , wherein a given feature comprises the given process identifier.

13 . The method according to claim 3 , wherein a given feature comprises a logical port number.

14 . The method according to claim 3 , wherein a given feature comprises the process ID.

15 . The method according to claim 3 , wherein a given feature comprises one or more network protocols used in the communication activity.

16 . The method according to claim 1 , wherein applying the model comprises generating additional features from the one or more additional communication events, and applying the model to the additional features.

17 . The method according to claim 1 , wherein the host computers comprise first host computers, and wherein the given host computer comprises an additional host computer different from any of the first host computers.

18 . The method according to claim 1 , wherein initiating the protective with respect to a given process comprises isolating the given process.

19 . The method according to claim 1 , wherein initiating the protective with respect to a given process comprises presenting, on a display, details of the given process.

20 . The method according to claim 1 , wherein receiving the alert comprises receiving a given report for a specific communication event.

21 . An apparatus, comprising:

a memory configured to store a model; and

a processor configured:

to collect, during a time period from security agents executing on respective host computers, reports of communication events, each of the communication events comprising communication activity performed by a process having a respective process ID and executing on one of the host computers,

to generate, from each of the collected reports, a set of features comprising characteristics of the communication activity and the respective process ID,

to train the model to identify, based on the features of one or more of the events, the process ID of one of the processes performing the one or more of the events,

to receive, from a network management device subsequent to the time period, an alert indicating malicious activity and referencing one or more reports of additional communication events performed by a given host computer,

to apply the model to the one or more reports of additional communication events so as to identify, on the given host computer, a given process ID of a given process responsible for the alert, and

to initiate a protective action with respect to at least the given process executing on the given host computer.

22 . A computer software product for protecting a computing device, which includes a processor and a memory and is coupled to a storage device storing a set of one or more files, the computer software product comprising a non-transitory computer-readable medium, in which program instructions are stored, which instructions, when read by a computer, cause the computer:

to collect, during a time period from security agents executing on respective host computers, reports of communication events, each of the communication events comprising communication activity performed by a process having a respective process ID and executing on one of the host computers;

to generate, from each of the collected reports, a set of features comprising characteristics of the communication activity and the respective process ID;

to train a model for identifying, based on the features of one or more of the events, the process ID of one of the processes performing the one or more of the events;

to receive, from a network management device subsequent to the time period, an alert indicating malicious activity and referencing one or more reports of additional communication events performed by a given host computer;

to apply the model to the one or more reports of additional communication events so as to identify, on the given host computer, a given process ID of a given process responsible for the alert; and

to initiate a protective action with respect to at least the given process executing on the given host computer.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
To: PALO ALTO NETWORKS INC.
Reel/Frame 068823/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2023
From: LEVY, EREZ; DADON, YAROM; YAROM, YUVAL; NIV, TOMER; REDLUS, TOM; ISAKOV, JONATHAN SHAI
To: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
Reel/Frame 064429/0010 →