IP Library Granted Patent US 12,348,547
Granted Patent B2
US 12,348,547 · App. 18/591,004 · Granted Jul 1, 2025

Supply chain attack detection

Inventors: Yuval Zan (Givatayim, IL); Erez Levy (Ganey Tikva, IL); Dor Agron (Ramat Hasharon, IL); Yarom Dadon (Tel Aviv, IL); Chen Evgi (Lod, IL)
Assignee: Palo Alto Networks Israel Services Ltd
H04L63/1425H04L41/0681
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,547
App. No.
18/591,004
Granted
Jul 1, 2025
Kind
B2
Abstract

Methods, storage systems and computer program products implement embodiments of the present invention that include identifying multiple host computers executing respective instances of a specific software application, each given instance on each given host computer including a set of program instructions loaded, by the host computer, from a respective storage device. Information on actions performed by the executing instances is collected from the host computers, and features are computed based on the information collected from the multiple host computers. The collected information for a given instance is compared to the features so as to classify the given instance as benign or suspicious, and an alert is generated for the given instance only upon classifying the given instance as suspicious.

Claims (60)

1. A method, comprising:

identifying multiple host computers deployed in respective sources and executing respective instances of a specific software application, each given instance on each given host computer comprising a set of program instructions loaded, by the host computer, from a respective storage device;

collecting, from the host computers, information on actions performed by the executing instances;

computing features based on the information collected from the multiple host computers, the features including one or more global features, which are not specific to any of the sources, and one or more local features, which are specific to respective ones of the sources, wherein at least one of the features combines multiple ones of the local features specific to respective ones of the sources;

comparing, by a processor, the collected information for a given instance to the features so as to classify the given instance as benign or suspicious; and

generating an alert for the given instance only upon classifying the given instance as suspicious.

2. The method according to claim 1 , wherein the information comprises action types and entities.

3. The method according to claim 1 , wherein the host computers execute multiple software applications having respective names, and further comprising normalizing the names, wherein the instances of the specific software application comprise the instances of the software application having identical normalized names.

4. The method according to claim 1 , wherein collecting the information for a given action performed by a given instance on a given host computer comprises detecting, by an endpoint agent executing on the host computer, the given action performed by the given instance, extracting, by the endpoint agent, the information for the given action, conveying by the endpoint agent the extracted information, and receiving, by the processor, the conveyed information.

5. An apparatus, comprising:

a network interface controller (NIC); and

one or more hardware processors configured:

to identify multiple host computers deployed in respective sources and executing respective instances of a specific software application, each given instance on each given host computer comprising a set of program instructions loaded, by the host computer, from a respective storage device,

to collect, from the host computers via the NIC, information on actions performed by the executing instances,

to compute features based on the information collected from the multiple host computers, the features including one or more global features, which are not specific to any of the sources, and one or more local features, which are specific to respective ones of the sources, wherein at least one of the features combines multiple ones of the local features specific to respective ones of the sources,

to compare the collected information for a given instance to the features so as to classify the given instance as benign or suspicious, and

to generate an alert for the given instance only upon classifying the given instance as suspicious.

6. A computer software product, the product comprising a non-transitory computer-readable medium, in which program instructions are stored, which instructions, when read by a processor, cause the processor:

to identify multiple host computers deployed in respective sources and executing respective instances of a specific software application, each given instance on each given host computer comprising a set of program instructions loaded, by the host computer, from a respective storage device;

to collect, from the host computers, information on actions performed by the executing instances;

to compute features based on the information collected from the multiple host computers, the features including one or more global features, which are not specific to any of the sources, and one or more local features, which are specific to respective ones of the sources, wherein at least one of the features combines multiple ones of the local features specific to respective ones of the sources;

to compare the collected information for a given instance to the features so as to classify the given instance as benign or suspicious; and

to generate an alert for the given instance only upon classifying the given instance as suspicious.

7. The product according to claim 6 , wherein the information comprises action types and entities.

8. The product according to claim 6 , wherein the host computers execute multiple software applications having respective names, and the instructions cause the processor to normalize the names, wherein the instances of the specific software application comprise the instances of the software application having identical normalized names.

9. The product according to claim 6 , wherein collecting the information for a given action performed by a given instance on a given host computer comprises detecting, by an endpoint agent executing on the host computer, the given action performed by the given instance, extracting, by the endpoint agent, the information for the given action, conveying by the endpoint agent the extracted information, and receiving, by the processor, the conveyed information.

10. The method according to claim 1 , wherein the sources include different respective local data networks.

11. The method according to claim 1 , wherein the sources include different respective organizations.

12. A method, comprising:

identifying multiple host computers deployed in respective sources and executing respective instances of a specific software application, each given instance on each given host computer comprising a set of program instructions loaded, by the host computer, from a respective storage device;

collecting, from the host computers, information on actions performed by the executing instances, wherein the actions have respective action types;

computing features based on the information collected from the multiple host computers, the features including one or more global features, which are not specific to any of the sources, and one or more local features, which are specific to respective ones of the sources, wherein the features include, for at least one of the action types, a count of those of the instances that performed the action type or of the sources in which at least one of the instances performed the action type;

comparing, by a processor, the collected information for a given instance to the features so as to classify the given instance as benign or suspicious; and

generating an alert for the given instance only upon classifying the given instance as suspicious.

13. The product according to claim 6 , wherein the sources include different respective local data networks.

14. The product according to claim 6 , wherein the sources include different respective organizations.

15. A computer software product comprising a non-transitory computer-readable medium in which program instructions are stored, which instructions, when read by a processor, cause the processor:

to identify multiple host computers deployed in respective sources and executing respective instances of a specific software application, each given instance on each given host computer comprising a set of program instructions loaded, by the host computer, from a respective storage device;

to collect, from the host computers, information on actions performed by the executing instances, wherein the actions have respective action types;

to compute features based on the information collected from the multiple host computers, the features including one or more global features, which are not specific to any of the sources, and one or more local features, which are specific to respective ones of the sources, wherein the features include, for at least one of the action types, a count of those of the instances that performed the action type or of those of the sources in which at least one of the instances performed the action type;

to compare the collected information for a given instance to the features so as to classify the given instance as benign or suspicious; and

to generate an alert for the given instance only upon classifying the given instance as suspicious.

16. A method, comprising:

identifying multiple host computers executing respective instances of a specific software application, each given instance on each given host computer comprising a set of program instructions loaded, by the host computer, from a respective storage device;

collecting, from the host computers, information on actions performed by the executing instances;

computing features based on the information collected from the multiple host computers;

comparing, by a processor, the collected information for a given instance to the features so as to classify the given instance as benign or suspicious; and

generating an alert for the given instance only upon classifying the given instance as suspicious,

wherein the host computers execute multiple software applications having respective names, wherein the method further comprises normalizing the names, and wherein the instances of the specific software application comprise the instances of the software application having identical normalized names.

17. A computer software product, the product comprising a non-transitory computer-readable medium, in which program instructions are stored, which instructions, when read by a processor, cause the processor:

to identify multiple host computers executing respective instances of a specific software application, each given instance on each given host computer comprising a set of program instructions loaded, by the host computer, from a respective storage device;

to collect, from the host computers, information on actions performed by the executing instances;

to compute features based on the information collected from the multiple host computers;

to compare the collected information for a given instance to the features so as to classify the given instance as benign or suspicious; and

to generate an alert for the given instance only upon classifying the given instance as suspicious,

wherein the host computers execute multiple software applications having respective names, wherein the instructions cause the processor to normalize the names, and wherein the instances of the specific software application comprise the instances of the software application having identical normalized names.

18. The method according to claim 12 , wherein the sources include different respective local data networks.

19. The method according to claim 12 , wherein the sources include different respective organizations.

20. The product according to claim 15 , wherein the sources include different respective local data networks.

21. The product according to claim 15 , wherein the sources include different respective organizations.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2024
From: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
To: PALO ALTO NETWORKS INC.
Reel/Frame 068823/0886 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 3, 2024
From: ZAN, YUVAL; LEVY, EREZ; AGRON, DOR; DADON, YAROM; EVGI, CHEN
To: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
Reel/Frame 066628/0039 →
Continuity (2)
Continuation 17857196 · Jul 5, 2022
Related Publication 20240205254A1 · Jun 20, 2024
References Cited (63)
US 8146146B1 · Coviello et al. · 2012 [cited by applicant]
US 8285830B1 · Stout et al. · 2012 [cited by applicant]
US 8316440B1 · Hsieh et al. · 2012 [cited by applicant]
US 8713674B1 · Geide · 2014 [cited by applicant]
US 8893286B1 · Oliver · 2014 [cited by applicant]
US 8955114B2 · Dolan-Gavitt · 2015 [cited by examiner]
US 10587647B1 · Khalid · 2020 [cited by examiner]
US 10623446B1 · Stoler · 2020 [cited by applicant]
US 11457040B1 · Sole et al. · 2022 [cited by applicant]
US 11516232B1 · Sumpter et al. · 2022 [cited by applicant]
US 11968222B2 · Zan et al. · 2024 [cited by applicant]
US 20030105980A1 · Challener et al. · 2003 [cited by applicant]
US 20060200487A1 · Adelman et al. · 2006 [cited by applicant]
US 20080034425A1 · Overcash et al. · 2008 [cited by applicant]
US 20080060054A1 · Srivastava · 2008 [cited by applicant]
US 20100042622A1 · Matkowsky · 2010 [cited by applicant]
US 20100235915A1 · Memon et al. · 2010 [cited by applicant]
US 20110066624A1 · Turakhia · 2011 [cited by applicant]
US 20110185429A1 · Sallam · 2011 [cited by examiner]
US 20150149530A1 · Maret et al. · 2015 [cited by applicant]
US 20150195299A1 · Zoldi et al. · 2015 [cited by applicant]
US 20150365437A1 · Bell, Jr. · 2015 [cited by examiner]
US 20170123875A1 · Craik · 2017 [cited by examiner]
US 20170149807A1 · Schilling · 2017 [cited by examiner]
US 20170244745A1 · Key et al. · 2017 [cited by applicant]
US 20180054449A1 · Nandha Premnath · 2018 [cited by examiner]
US 20180063174A1 · Grill et al. · 2018 [cited by applicant]
US 20180069884A1 · Firstenberg et al. · 2018 [cited by applicant]
US 20180285567A1 · Raman · 2018 [cited by examiner]
US 20190058724A1 · Kraning et al. · 2019 [cited by applicant]
US 20190068575A1 · Vongsouvanh et al. · 2019 [cited by applicant]
US 20190068624A1 · Compton · 2019 [cited by applicant]
US 20190068638A1 · Bartik et al. · 2019 [cited by applicant]
US 20190297097A1 · Gong et al. · 2019 [cited by applicant]
US 20190319977A1 · Gottschlich et al. · 2019 [cited by applicant]
US 20190372934A1 · Yehudai · 2019 [cited by examiner]
US 20200067913A1 · Kapoor et al. · 2020 [cited by applicant]
US 20200233791A1 · Manzano · 2020 [cited by examiner]
US 20200364354A1 · Schwartz et al. · 2020 [cited by applicant]
US 20200412717A1 · Puertas Calvo et al. · 2020 [cited by applicant]
US 20220070216A1 · Kohavi · 2022 [cited by applicant]
US 20220342976A1 · Stoyanov et al. · 2022 [cited by applicant]
US 20220353284A1 · Vörös et al. · 2022 [cited by applicant]
US 20220385694A1 · Zverkov et al. · 2022 [cited by applicant]
US 20230086281A1 · Kaidi · 2023 [cited by applicant]
US 20230118679A1 · Mayer et al. · 2023 [cited by applicant]
US 20230403265A1 · Gaffney et al. · 2023 [cited by applicant]
US 20240015176A1 · Egbert et al. · 2024 [cited by applicant]
CN 114077741A · 2022 [cited by applicant]
JP 2008243034A · 2008 [cited by applicant]
WO 2012167056A2 · 2012 [cited by applicant]
WO 2020148934A1 · 2020 [cited by applicant]
U.S. Appl. No. 18/353,115 Office Action dated May 1, 2024. [cited by applicant]
EP Application # 23738144.7 Office Action dated May 17, 2024. [cited by applicant]
Guez et al., U.S. Appl. No. 18/295,857, filed Apr. 5, 2023. [cited by applicant]
Elazar et al., U.S. Appl. No. 18/475,266, filed Sep. 27, 2023. [cited by applicant]
JP Application # 2024504256 Office Action dated Jul. 2, 2024. [cited by applicant]
JP Application # 2024504256 Office Action dated Oct. 8, 2024. [cited by applicant]
U.S. Appl. No. 17/844,097 Office Action dated Nov. 19, 2024. [cited by applicant]
U.S. Appl. No. 18/591,004 Office Action dated Dec. 3, 2024. [cited by applicant]
JP Application # 2024504256 Office Action dated Jan. 28, 2025. [cited by applicant]
Alsariera et al., “AI Meta-learners and Extra-trees Algorithm for the Detection of Phishing Websites,” IEEE Access, pp. 142532-145242, Aug. 14, 2020. [cited by applicant]
U.S. Appl. No. 18/295,857 Office Action Mar. 17, 2025. [cited by applicant]