IP Library Granted Patent US 11,601,457
Granted Patent B2
US 11,601,457 · App. 17/003,033 · Granted Mar 7, 2023

Network traffic correlation engine

Inventors: Jonathan Sheedy (Poynton, GB); Steven E. Sinks (Scottsdale, AZ)
Assignee: Bank of America Corporation
H04L63/1425H04L41/0686
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,601,457
App. No.
17/003,033
Granted
Mar 7, 2023
Kind
B2
Abstract

A network traffic correlation engine monitors inbound and/or outbound connection information received from on each host computer system on a network. Each host device on the network store data logs corresponding to information corresponding to communications sent by the device and received by the device. The network traffic correlation engine correlates connections between different hosts throughout the network. If the network traffic correlation engine identified unmatched outbound and inbound connections, the network traffic correlation engine generates an alert to initiate further investigation and may also provide a mapping of the communications showing a possible start device for the connection and/or a type of access that the connections may now be providing.

Claims (38)

1. A method comprising:

monitoring, by a network traffic correlation engine, network communications information aggregated from each host of a plurality of hosts on an enterprise network, wherein the network communications information comprises inbound and outbound connection information received from each host on the enterprise network;

identifying, by the network traffic correlation engine, whether a correlation exists between a first outbound communication sent from a first host device to a second host device and a second inbound communication received by the second host device from the first host device;

determining, based on whether a correlation exists between the first communication and the second communication, whether an anomalous communication condition exists with respect to one or both of the first outbound communication or the second inbound communication; and

triggering, based on the correlation, an alert identifying that the anomalous communication condition is present between the first host device and the second host device, wherein the anomalous condition comprises an indication of host to host communication.

2. The method of claim 1 , comprising:

aggregating information from a plurality of network communication services and data logs, wherein the information corresponds to a plurality of network communication connections to and from the first host device and the second host device.

3. The method of claim 2 comprising,

matching messages received by the first host device to messages sent by the second host device based on the aggregated information to detect the anomalous communication on the network.

4. The method of claim 1 , wherein triggering the alert comprises providing an indication of the alert on a user interface device at a central location on the network.

5. The method of claim 1 , wherein the anomalous condition comprises an indication that logging of sent messages was disabled.

6. The method of claim 1 , wherein the monitoring of network communications information aggregated from a plurality of hosts on an enterprise network comprises aggregating information received from a plurality of host intrusion detection systems each associated with a different host device.

7. A computing device, comprising:

a processor; and

memory storing instructions that, when executed by the processor, cause the computing device to:

monitor, by a network traffic correlation engine, network communications information aggregated from a plurality of hosts on an enterprise network, wherein the network communications information comprises inbound and outbound connection information received from each host on the enterprise network;

identify, by the network traffic correlation engine, whether a correlation exists between a first communication sent from a first host device via the enterprise network to a second host device and a second communication received via the enterprise network by the second host device;

determine, based on whether a correlation exists between the first communication and the second communication, whether an anomalous communication condition exists; and

trigger, based on the correlation, an alert identifying that the anomalous communication condition is present between the first host device and the second host device.

8. The computing device of claim 7 , wherein the instructions, when executed, cause the computing device to:

aggregate information from a plurality of network communication services and data logs, wherein the information corresponds to a plurality of network communication connections to and from the first host device and the second host device.

9. The computing device of claim 8 , wherein the instructions, when executed cause the computing device to:

match messages received by the first host device to messages sent by the second host device based on the aggregated information to detect an anomalous communication on the network.

10. The computing device of claim 7 , wherein triggering the alert comprises providing an indication of the alert on a user interface device at a central location on the network.

11. The computing device of claim 7 , wherein the anomalous condition comprises an indication that logging of sent messages was disabled.

12. The computing device of claim 7 , wherein monitoring of network communications information aggregated from a plurality of hosts on an enterprise network comprises aggregating information received from a plurality of host intrusion detection systems each associated with a different host device.

13. One or more non-transitory computer-readable media storing instructions that, when executed by a host computing device comprising a processor, memory, and a communication interface, cause the host computing device to:

monitor, by a network traffic correlation engine, network communications information aggregated from a plurality of hosts on an enterprise network, wherein the network communications information comprises inbound and outbound connection information received from each host on the enterprise network;

identify, by the network traffic correlation engine, whether a correlation exists between a first communication sent via the enterprise network from a first host device to a different host device and a second communication received via the enterprise network by a second host device;

determine, based on whether a correlation exists between the first communication and the second communication, whether an anomalous communication condition exists; and

trigger, based on the correlation, an alert identifying that the anomalous communication condition is present between the first host device and the second host device.

14. The one or more non-transitory computer-readable media of claim 13 , wherein the instructions, when executed by the processor, cause the host computing device to:

aggregate information from a plurality of network communication services and data logs, wherein the information corresponds to a plurality of network communication connections to and from the first host device and the second host device.

15. The one or more non-transitory computer-readable media of claim 14 , wherein the instructions, when executed by the processor, cause the host computing device to:

match messages received by the first host device to messages sent by the second host device based on the aggregated information to detect an anomalous communication on the network.

16. The one or more non-transitory computer-readable media of claim 13 , wherein triggering the alert comprises providing an indication of the alert on a user interface device at a central location on the network.

17. The one or more non-transitory computer-readable media of claim 13 , wherein the anomalous condition comprises an indication that logging of sent messages was disabled.

18. The one or more non-transitory computer-readable media of claim 13 , wherein monitoring of network communications information aggregated from a plurality of hosts on an enterprise network comprises aggregating information received from a plurality of host intrusion detection systems each associated with a different host device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2020
From: SHEEDY, JONATHAN; SINKS, STEVEN E.
To: BANK OF AMERICA CORPORATION
Reel/Frame 053602/0691 →
Continuity (1)
Related Publication 20220070188A1 · Mar 3, 2022
Cited By (1)
US 12,267,348