IP Library › Granted Patent US 10,264,007
Granted Patent B2
US 10,264,007 · App. 15/956,933 · Granted Apr 16, 2019

Malware beaconing detection methods

Inventor: Brian Fehrman (Sturgis, SD)
Assignee: NETSEC CONCEPTS, LLC
H04L63/1425H04L63/02H04L63/0254H04W12/08H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,264,007
App. No.
15/956,933
Granted
Apr 16, 2019
Kind
B2
Abstract

A method for detecting malware beaconing in a network, the method includes capturing network traffic over a network connection at a network connected device, representing the network traffic over the network connection as a set of tuples wherein each of the tuples includes at least a source Internet Protocol address, a destination Internet Protocol address, and a destination port, associating timestamps with each of the set of tuples, and analyzing the tuples using the timestamps based on frequency of connections to determine malware beaconing on the network, wherein the analyzing is performed by a computing device.

Claims (30)

1. A method for detecting malware beaconing in a network, the method comprising:

capturing network traffic over a network connection at a network connected device;

representing the network traffic over the network connection as a set of tuples wherein each of the tuples defines an Open Systems Interconnection (OSI) layer 4 communications session and includes at least a source Internet Protocol address, a destination Internet Protocol address, and a destination port;

associating timestamps with each of the set of tuples;

performing a frequency analysis of the tuples using the timestamps based on frequency of connections to determine malware beaconing on the network, wherein the performing the frequency is analysis is performed by a computing device; and

displaying to a user one or more connections identified as malware beaconing.

2. The method of claim 1 wherein the performing the frequency analysis of the set of tuples comprises performing a Fourier analysis.

3. The method of claim 2 wherein the Fourier analysis is a discrete Fourier transform.

4. The method of claim 1 wherein the performing the frequency analysis comprises inserting each of the connections into a time bucket based on the corresponding timestamp and inserting each duration between consecutive connections into duration buckets.

5. The method of claim 4 wherein each time bucket is stored in a time bucket hash map.

6. The method of claim 5 wherein each of the duration buckets is stored in a duration hash map.

7. The method of claim 4 wherein the performing the frequency analysis further comprises determining a smallest range of consecutive duration buckets containing T percent of all connections, wherein T is a threshold value.

8. The method of claim 7 wherein T is at least 80 percent.

9. The method of claim 8 wherein T is less than or equal to 90 percent.

10. The method of claim 7 wherein the performing the frequency analysis further comprises determining values for a low end and a high end of the smallest range of consecutive duration buckets containing T percent of all the connections.

11. The method of claim 7 wherein the performing the frequency analysis further comprises determining a difference in time between the consecutive duration buckets.

12. The method of claim 7 wherein the performing the frequency analysis further comprises determining a spread as a difference between first and last timestamps.

13. The method of claim 7 wherein the performing the frequency analysis further comprises determining at least one of range values, range, spread, fill, and size.

14. The method of claim 1 wherein the performing the frequency analysis further comprises obtaining at least one statistical measure associated with the network traffic.

15. The method of claim 1 further comprising reconfiguring a firewall to prevent network connections to the destination address and the destination port associated with the malware beaconing.

16. The method of claim 1 further comprising identifying software containing the malware.

17. The method of claim 16 further comprising removing the malware from the network.

18. The method of claim 1 wherein the network includes a firewall having a stateful mechanism.

19. The method of claim 11 wherein the performing the frequency analysis is based in part on data size of the network traffic.

20. A method for detecting malware beaconing in a network, the method comprising:

capturing network traffic over a network connection at a network connected device;

representing the network traffic over the network connection as a set of tuples wherein each of the tuples defines an Open Systems Interconnection (OSI) layer 4 communications session and includes at least a source Internet Protocol address, a destination Internet Protocol address, and a destination port;

associating timestamps with each of the set of tuples;

identifying malware beaconing on the network by analyzing the tuples using the timestamps based on frequency of connections, wherein the analyzing is performed by a computing device; and

alerting a user of the presence of malware beaconing when a measure of data size of the network traffic exceeds a threshold associated with malware beaconing.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2018
From: FEHRMAN, BRIAN
To: NETSEC CONCEPTS, LLC
Reel/Frame 045948/0205 →
Continuity (2)
Continuation 14981635 · Dec 28, 2015
Related Publication 20180241765A1 · Aug 23, 2018
Cited By (1)
US 12,225,024