IP Library › Granted Patent US 11,741,225
Granted Patent B2
US 11,741,225 · App. 17/105,851 · Granted Aug 29, 2023

Zero day attack detection

Inventor: Joseph Soryal (Ridgewood, NY)
Assignee: AT&T Intellectual Property I, L.P.
G06F21/554G06F21/577G06N20/00G06F9/45533G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,741,225
App. No.
17/105,851
Granted
Aug 29, 2023
Kind
B2
Abstract

The concepts and technologies disclosed herein are directed to zero day attack detection. A system can monitor, by a sequence manager, a sequence of transaction requests. The sequence manager can determine whether a transaction request in the sequence is anomalous. In response to determining that the transaction request is anomalous, and before the allowing the system to process the transaction request, the sequence manager can provide the sequence of transaction requests to a sequence emulator. The sequence emulator can attempt to verify an output of the sequence of transaction requests. The sequence manager can receive a notification from the sequence emulator. The notification can indicate whether the output of the sequence of transaction requests can be verified. In response, the sequence manager can instruct the system to deny (if the output cannot be verified) or allow (if the output can be verified) processing of the sequence of transaction requests.

Claims (51)

1. A method comprising:

monitoring, by a sequence manager executed by a processor of a system, a sequence of transaction requests received by the system, wherein the sequence of transaction requests includes a path from a root transaction to a destination transaction;

determining, by the sequence manager, that a transaction request in the sequence of transaction requests is anomalous, wherein determining that the transaction request in the sequence of transaction requests is anomalous includes determining that an area associated with the path from the root transaction to the destination transaction deviates from a baseline area corresponding to verified transaction requests associated with the root transaction and the destination transaction; and

in response to determining that the transaction request is anomalous,

quarantining, by the sequence manager, the transaction request to prevent the system from processing the transaction request, and

while the transaction request is quarantined and prevented from being processed by the system, providing, by the sequence manager, the sequence of transaction requests to a sequence emulator, wherein the sequence emulator attempts to verify an output of the sequence of transaction requests.

2. The method of claim 1 , further comprising:

receiving, by the sequence manager, a notification from the sequence emulator that the output of the sequence of transaction requests cannot be verified; and

in response to the notification, instructing, by the sequence manager, the system to deny processing of the sequence of transaction requests.

3. The method of claim 2 , further comprising updating, by the sequence manager, a database to include the sequence of transaction requests with a label indicating that the sequence of transaction requests is associated with a vulnerability.

4. The method of claim 1 , further comprising:

receiving, by the sequence manager, a notification from the sequence emulator that the output of the sequence of transaction requests can be verified; and

in response to the notification, instructing, by the sequence manager, the system to allow processing of the sequence of transaction requests.

5. The method of claim 4 , further comprising updating, by the sequence manager, a database to include the sequence of transaction requests with a label indicating that the sequence of transaction requests is not associated with a vulnerability.

6. The method of claim 1 , wherein the sequence of transaction requests comprises a plurality of software transaction requests or a plurality of firmware transaction requests.

7. The method of claim 1 , wherein the sequence of transaction requests comprises a plurality of hardware transaction requests.

8. The method of claim 1 , wherein monitoring, by the sequence manager, the sequence of transaction requests comprises monitoring, by the sequence manager, the sequence of transaction requests via a probe, wherein the probe comprises a hardware probe or a software probe.

9. A system comprising:

a processor; and

a memory having instructions comprising a sequence manager stored thereon that, when executed by the processor, cause the sequence manager to perform operations comprising

monitoring a sequence of transaction requests received by the system, wherein the sequence of transaction requests includes a path from a root transaction to a destination transaction,

determining that a transaction request in the sequence of transaction requests is anomalous, wherein determining that the transaction request in the sequence of transaction requests is anomalous includes determining that an area associated with the path from the root transaction to the destination transaction deviates from a baseline area corresponding to verified transaction requests associated with the root transaction and the destination transaction, and

in response to determining that the transaction request is anomalous,

quarantining the transaction request to prevent the system from processing the transaction request, and

while the transaction request is quarantined and prevented from being processed by the system, providing the sequence of transaction requests to a sequence emulator, wherein the sequence emulator attempts to verify an output of the sequence of transaction requests.

10. The system of claim 9 , wherein the operations further comprise:

receiving a notification from the sequence emulator that the output of the sequence of transaction requests cannot be verified; and

in response to the notification, instructing the system to deny processing of the sequence of transaction requests.

11. The system of claim 10 , wherein the operations further comprise updating a database to include the sequence of transaction requests with a label indicating that the sequence of transaction requests is associated with a vulnerability.

12. The system of claim 9 , wherein the operations further comprise:

receiving a notification from the sequence emulator that the output of the sequence of transaction requests can be verified; and

in response to the notification, instructing the system to allow processing of the sequence of transaction requests.

13. The system of claim 12 , wherein the operations further comprise updating a database to include the sequence of transaction requests with a label indicating that the sequence of transaction requests is not associated with a vulnerability.

14. The system of claim 9 , wherein the sequence of transaction requests comprises a plurality of software transaction requests, a plurality of hardware transaction requests, or a plurality of firmware transaction requests.

15. The system of claim 9 , wherein the sequence of transaction requests comprises a plurality of hardware transaction requests.

16. The system of claim 9 , wherein monitoring the sequence of transaction requests comprises monitoring the sequence of transaction requests via a probe, wherein the probe comprises a hardware probe or a software probe.

17. A computer-readable storage medium having computer-executable instructions comprising a sequence manager stored thereon that, when executed by a processor of a system, cause the sequence manager to perform operations comprising:

monitoring a sequence of transaction requests received by the system, wherein the sequence of transaction requests includes a path from a root transaction to a destination transaction;

determining that a transaction request in the sequence of transaction requests is anomalous, wherein determining that the transaction request in the sequence of transaction requests is anomalous includes determining that an area associated with the path from the root transaction to the destination transaction deviates from a baseline area corresponding to verified transaction requests associated with the root transaction and the destination transaction; and

in response to determining that the transaction request is anomalous,

quarantining the transaction request to prevent the system from processing the transaction request, and

while the transaction request is quarantined and prevented from being processed by the system, providing the sequence of transaction requests to a sequence emulator, wherein the sequence emulator attempts to verify an output of the sequence of transaction requests.

18. The computer-readable storage medium of claim 17 , wherein the operations further comprise:

receiving a notification from the sequence emulator that the output of the sequence of transaction requests cannot be verified;

in response to the notification, instructing the system to deny processing of the sequence of transaction requests; and

updating a database to include the sequence of transaction requests with a label indicating that the sequence of transaction requests is associated with a vulnerability.

19. The computer-readable storage medium of claim 17 , wherein the operations further comprise:

receiving a notification from the sequence emulator that the output of the sequence of transaction requests can be verified;

in response to the notification, instructing the system to allow processing of the sequence of transaction requests; and

updating a database to include the sequence of transaction requests with a label indicating that the sequence of transaction requests is not associated with a vulnerability.

20. The computer-readable storage medium of claim 17 , wherein monitoring the sequence of transaction requests comprises monitoring the sequence of transaction requests via a probe, wherein the probe comprises a hardware probe or a software probe.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2020
From: SORYAL, JOSEPH
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 054478/0625 →
Continuity (1)
Related Publication 20220171849A1 · Jun 2, 2022