IP Library Granted Patent US 11,277,422
Granted Patent B2
US 11,277,422 · App. 15/909,962 · Granted Mar 15, 2022

Detecting malicious network addresses within a local network

Inventors: Leonid Kuperman (Tarzana, CA); Yuri Frayman (Miami, FL); Einaras von Gravrock (Redondo Beach, CA); Gabor Takacs (Gyor, HU)
Assignee: Cujo LLC
H04L63/1425G06F15/76G06F21/53G06F21/554G06N20/00H04L41/145H04L63/0236H04L63/102H04L63/1433H04L63/1466H04L41/16H04L43/026H04L43/062
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,277,422
App. No.
15/909,962
Granted
Mar 15, 2022
Kind
B2
Abstract

The behavior analysis engine can also detect malicious network addresses that are sent to networked devices in the local network. The network traffic hub identifies network communications that are transmitted through the local network that contain network addresses. The network traffic hub transmits (or sends) the network address to the behavior analysis engine and the behavior analysis engine extracts network address features from the network address. The behavior analysis engine then applies an execution model to the execution features to determine a confidence score for the network address that represents the execution model's certainty that the network address is malicious. The behavior analysis engine uses the confidence score to provide instructions to the network traffic hub as to whether to allow the networked device to receive the network address.

Claims (47)

1. A method comprising:

receiving, at a behavior analysis engine, a network address from a network traffic hub in a local network, the network address being associated with a network communication sent by a source device and being addressed to a networked device in the local network, the network traffic hub, at a first point in time, inhibiting the network communication from being forwarded to the networked device;

extracting network address features from the network address, the network address features describing characteristics of the network address and comprising one or more of: a presence of special characters within the network address, an age of a domain of the network address, and a presence of an HTTPS certificate corresponding to the network address;

applying a network address model to the network address features, the network address model to determine whether the network address is malicious based on network address features of the network address; and

transmitting, at a subsequent second point in time, processing instructions to the network traffic hub based on a determination of whether the network address is malicious, the processing instructions comprising instructions to one of 1) block the network communication from being forwarded to the networked device and 2) forward the network communication to the networked device.

2. The method of claim 1 , further comprising:

receiving, by the behavior analysis engine, the network communication associated with the network address; and

extracting the network address from the network communication.

3. The method of claim 1 , wherein the network address model comprises a machine-learned model.

4. The method of claim 3 , wherein the network address model is trained based on network address features of a set of known-malicious network addresses.

5. The method of claim 3 , wherein the network address model is trained based on network address features of a set of known-non-malicious network addresses.

6. The method of claim 5 , wherein the set of known-non-malicious network addresses comprises network addresses for a set of websites that receive heavy Internet traffic.

7. The method of claim 1 , wherein applying the network address model to the network address features comprises: generating a confidence score based on the network address features, the confidence score representing a confidence of the network address model that the network address is malicious.

8. The method of claim 1 , further comprising:

determining that the network address is malicious; and

wherein the processing instructions comprise instructions to block the network communication from being forwarded to the networked device.

9. The method of claim 1 , further comprising:

determining that the network address is not malicious; and

wherein the processing instructions comprise instructions to forward the network communication to the networked device.

10. A non-transitory computer-readable medium comprising instructions that, when executed by a processor, cause the processor to:

receive, at a behavior analysis engine, a network address from a network traffic hub in a local network, the network address being associated with a network communication sent by a source device and being addressed to a networked device in the local network, the network traffic hub, at a first point in time, inhibiting the network communication from being forwarded to the networked device;

extract network address features from the network address, the network address features describing characteristics of the network address and comprising one or more of: a presence of special characters within the network address, an age of a domain of the network address, and a presence of an HTTPS certificate corresponding to the network address;

apply a network address model to the network address features, the network address model to determine whether the network address is malicious based on network address features of the network address; and

transmit, at a subsequent second point in time, processing instructions to the network traffic hub based on a determination of whether the network address is malicious, the processing instructions comprising instructions to one of 1) block the network communication from being forwarded to the networked device and 2) forward the network communication to the networked device.

11. The non-transitory computer-readable medium of claim 10 , further comprising instructions that cause the processor to:

receive, by the behavior analysis engine, the network communication associated with the network address; and

extract the network address from the network communication.

12. The non-transitory computer-readable medium of claim 10 , wherein the network address model comprises a machine-learned model.

13. The non-transitory computer-readable medium of claim 12 , wherein the network address model is trained based on network address features of a set of known-malicious network addresses.

14. The non-transitory computer-readable medium of claim 12 , wherein the network address model is trained based on network address features of a set of known-non-malicious network addresses.

15. The non-transitory computer-readable medium of claim 14 , wherein the set of known-non-malicious network addresses comprises network addresses for a set of websites that receive heavy Internet traffic.

16. The non-transitory computer-readable medium of claim 10 , wherein the instructions for applying the network address model to the network address features further cause the processor to generate a confidence score based on the network address features, the confidence score representing a confidence of the network address model that the network address is malicious.

17. The non-transitory computer-readable medium of claim 16 , wherein the instructions further cause the processor to compare the confidence score to a threshold confidence score.

18. The non-transitory computer-readable medium of claim 10 , further comprising instructions that cause the processor to:

determine that the network address is malicious; and

wherein the processing instructions comprise instructions to block the network communication from being forwarded to the networked device.

19. The non-transitory computer-readable medium of claim 10 , further comprising instructions that cause the processor to:

determine that the network address is not malicious; and

wherein the processing instructions comprise instructions to forward the network communication to the networked device.

20. A computing device comprising:

a memory; and

a processor device configured to:

receive, at a behavior analysis engine, a network address from a network traffic hub in a local network, the network address being associated with a network communication sent by a source device and being addressed to a networked device in the local network, the network traffic hub, at a first point in time, inhibiting the network communication from being forwarded to the networked device;

extract network address features from the network address, the network address features describing characteristics of the network address and comprising one or more of:

a presence of special characters within the network address, an age of a domain of the network address, and a presence of an HTTPS certificate corresponding to the network address;

apply a network address model to the network address features, the network address model to determine whether the network address is malicious based on network address features of the network address; and

transmit, at a subsequent second point in time, processing instructions to the network traffic hub based on a determination of whether the network address is malicious, the processing instructions comprising instructions to one of 1) block the network communication from being forwarded to the networked device and 2) forward the network communication to the networked device.

Assignments (2)
SECURITY INTEREST Recorded Jun 20, 2019
From: CUJO LLC
To: CHARTER COMMUNICATONS HOLDING COMPANY, LLC
Reel/Frame 049537/0319 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2018
From: KUPERMAN, LEONID; FRAYMAN, YURI; VON GRAVROCK, EINARAS; TAKACS, GABOR
To: CUJO LLC
Reel/Frame 045993/0035 →
Continuity (4)
Provisional Application 62477363 · Mar 27, 2017
Provisional Application 62477391 · Mar 27, 2017
Provisional Application 62465304 · Mar 1, 2017
Related Publication 20180255022A1 · Sep 6, 2018