IP Library Granted Patent US 9,467,462
Granted Patent B2
US 9,467,462 · App. 11/227,763 · Granted Oct 11, 2016

Traffic anomaly analysis for the detection of aberrant network code

Inventor: Joseph P. Reves (Colorado Springs, CO)
Assignee: Hewlett Packard Enterprise Development LP
H04L63/1425H04L63/14H04L63/145H04L63/1408H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,467,462
App. No.
11/227,763
Filed
Sep 15, 2005
Granted
Oct 11, 2016
Kind
B2
Art Unit
2463
USPC
370/352
Abstract

A method for detecting nodes in an enterprise network infected with aberrant code is presented in which traffic conversation information representative of traffic conversation in the enterprise network over an analysis period is obtained. Analysis of the obtained traffic conversation information identifies suspected infected nodes in the enterprise network that exhibit behavior outside of the normal behavior associated with the one or more traffic conversation factors. Anomaly analysis may be performed on traffic conversation information associated with the suspected infected nodes to identify any existing infected nodes in the enterprise network.

Claims (34)

1. A method, comprising:

obtaining a first plurality of values representative of data transported via respective ones of a plurality of traffic conversations within an enterprise network during an analysis period;

computing, via a processor, a statistical attribute of the first plurality of values;

computing, via the processor, a threshold based on the computed statistical attribute;

comparing the first plurality of values to the computed threshold to identify a subset of nodes of the enterprise network suspected of including aberrant code; and

identifying from the subset of nodes a first node as including the aberrant code based on a second plurality of values characterizing destinations contacted by respective ones of the subset of nodes.

2. The method of claim 1 , wherein the threshold represents at least one of a number of attempted contacts, a number of frames per conversation, or a variation in conversation size.

3. The method of claim 1 , further comprising analyzing a portion of the first plurality of values associated with the first node to confirm presence of the aberrant code on the first node.

4. The method of claim 1 , wherein the second plurality of values represents at least one of a first number of attempted contacts with destination hosts in an adjacent address space, a second number of attempted contacts with bogons, or a third number of attempted contacts with destination hosts having unresolvable destination names.

5. An article of manufacture comprising a tangible computer-readable storage medium excluding propagating signals and storing machine-accessible instructions that, when executed, cause a machine to at least:

obtain a first plurality of values representative of data transported via respective ones of a plurality of traffic conversations within an enterprise network during an analysis period;

compute a statistical attribute of the first plurality of values;

compute a threshold based on the computed statistical attribute;

compare the first plurality of values to the computed threshold to identify a subset of nodes of the enterprise network suspected of including aberrant code; and

identify from the subset of nodes a first node as including the aberrant code based on a second plurality of values characterizing destinations contacted by the first node.

6. The article of manufacture of claim 5 , wherein the threshold represents at least one of a number of attempted contacts, a number of frames per conversation, or a variation in conversation size.

7. The article of manufacture of claim 5 , wherein the second plurality of values represent at least one of a first number of attempted contacts with destination hosts in an adjacent address space, a second number of attempted contacts with bogons, or a third number of attempted contacts with destination hosts having unresolvable destination names.

8. An apparatus, comprising:

a data collector to obtain a first plurality of values representative of data transported via respective ones of a plurality of traffic conversations within an enterprise network during an analysis period;

a statistical analyzer to compute a statistical attribute of the first plurality of values;

a source profiler to compute a threshold based on the computed statistical attribute, and compare the first plurality of values to the computed threshold to identify a subset of nodes of the enterprise network suspected of including aberrant code; and

a destination analyzer to identify from the subset of nodes a first node as including the aberrant code based on a second plurality of values characterizing destinations contacted by respective ones of the subset of nodes, wherein at least one of the data collector, the statistical analyzer, the source profiler or the destination analyzer is implemented with hardware.

9. The apparatus of claim 8 , further comprising an anomaly analyzer to analyze a portion of the first plurality of values associated with the first node to confirm presence of the aberrant code on the first node.

10. The apparatus of claim 8 , wherein each of the second plurality of values represents at least one of a first number of attempted contacts with destination hosts in an adjacent address space, a second number of attempted contacts with bogons, or a third number of attempted contacts with destination hosts having unresolvable destination names.

11. The method of claim 1 , wherein the statistical attribute comprises at least one of a mean or a standard deviation of the first plurality of values.

12. The article of manufacture of claim 5 , wherein the statistical attribute comprises at least one of a mean or a standard deviation of the first plurality of values.

13. The apparatus of claim 8 , wherein the statistical attribute comprises at least one of a mean or a standard deviation of the first plurality of values.

14. The apparatus of claim 8 , wherein the threshold represents at least one of a number of attempted contacts, a number of frames per conversation or a variation in conversation size.

15. The method of claim 4 , further comprising:

setting a weight associated with the first node to an initial amount;

increasing the weight by a first amount when the second number is non-zero;

increasing the weight by a second amount when the first number exceeds a second threshold; and

increasing the weight by a third amount when the third number exceeds a third threshold.

16. The method of claim 1 , further comprising identifying the first node as having the largest associated one of the second plurality of values.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 9, 2015
From: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 037079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2005
From: REVES, JOSEPH P.
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 017002/0404 →
Continuity (1)
Related Publication 20070064617A1 · Mar 22, 2007