IP Library › Granted Patent US 12,058,156
Granted Patent B2
US 12,058,156 · App. 17/706,642 · Granted Aug 6, 2024

System and method for detecting and mitigating port scanning attacks

Inventor: Lior Fite (Zurit, IL)
Assignee: EDGEHAWK SECURITY LTD.
H04L63/1425H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,058,156
App. No.
17/706,642
Granted
Aug 6, 2024
Kind
B2
Abstract

A method for securing data over a communication network, the method comprising detecting communication data transferred via a router in the communication network, applying an anomaly detection process on the detected communication data to identify malicious data sent via the router, generating a list of candidate Internet Protocol (IP) addresses having a probability of sending malicious data via the router, sending the list of candidates to the router, receiving additional telemetry about data received from the IP addresses included in the list of candidates, narrowing down the list of candidates to a list of verified attackers, generating one or more attack signatures configured to identify the port scanning traffic from the IP addresses included in the list of candidates, sending the one or more attack signatures to the router.

Claims (50)

1. A method for securing data over a communication network, the method comprising:

detecting communication data transferred via a router in the communication network;

applying an anomaly detection process on the detected communication data to identify malicious data sent via the router;

generating a list of candidate Internet Protocol (IP) addresses having a probability of sending malicious data via the router;

sending the list of candidates to the router;

receiving additional telemetry about data received from the IP addresses included in the list of candidates;

narrowing down the list of candidates to a list of verified attackers;

generating one or more attack signatures configured to identify the port scanning traffic from the IP addresses included in the list of candidates; and

sending the one or more attack signatures to the router,

wherein the anomaly detection process comprises measuring an amount of echo requests sent from source IP to a plurality of destination IP addresses.

2. The method of claim 1 , wherein the additional telemetry comprises a set of parameters including source IP address/port number, destination IP address/port number and a communication protocol used to transfer the data via the router.

3. The method of claim 1 , wherein providing the additional telemetry comprises increasing a sampling rate of packets sent from the IP addresses included in the list of candidates.

4. The method of claim 1 , further comprising monitoring a counter representing a number of times a specific IP address appears in the list of candidates sending malicious data via the router.

5. The method of claim 1 , wherein the anomaly detection process comprises detecting an amount of synchronizing acknowledgement messages sent via the router from a specific source IP address.

6. The method of claim 1 , wherein the malicious data is sent as part of a port scanning attack.

7. The method of claim 1 , wherein the malicious data is sent from an IP address operating behind a Network Address Translation (NAT) system, the method further comprising:

detecting information related to packets sent from the NAT system that include legitimate traffic; and

generating a packet signature that identify only a port scanning traffic and program the router ACL with these signatures to stop the transfer of data from the IP addresses defined as attacking addresses.

8. The method of claim 1 , wherein sending the list of candidates to the router via a software-defined network protocol capable of configuring the router.

9. The method of claim 8 , wherein the software-defined network protocol is Netconf.

10. A method for securing data over a communication network, the method comprising:

detecting communication data transferred via a router in the communication network;

applying an anomaly detection process on the detected communication data to identify malicious data sent via the router;

generating a list of candidate Internet Protocol (IP) addresses having a probability of sending malicious data via the router;

sending the list of candidates to the router;

receiving additional telemetry about data received from the IP addresses included in the list of candidates;

narrowing down the list of candidates to a list of verified attackers;

generating one or more attack signatures configured to identify the port scanning traffic from the IP addresses included in the list of candidates;

sending the one or more attack signatures to the router;

detecting information related to packets sent from the NAT system that include legitimate traffic; and

generating a packet signature that identify only a port scanning traffic and program the router ACL with these signatures to stop the transfer of data from the IP addresses defined as attacking addresses.

11. The method of claim 10 , wherein the additional telemetry comprises a set of parameters including source IP address/port number, destination IP address/port number and a communication protocol used to transfer the data via the router.

12. The method of claim 10 , wherein providing the additional telemetry comprises increasing a sampling rate of packets sent from the IP addresses included in the list of candidates.

13. The method of claim 10 , further comprising monitoring a counter representing a number of times a specific IP address appears in the list of candidates sending malicious data via the router.

14. The method of claim 10 , wherein the anomaly detection process comprises detecting an amount of synchronizing acknowledgement messages sent via the router from a specific source IP address.

15. The method of claim 10 , wherein the anomaly detection process comprises measuring an amount of echo requests sent from source IP to a plurality of destination IP addresses.

16. A method for securing data over a communication network, the method comprising:

detecting communication data transferred via a router in the communication network;

applying an anomaly detection process on the detected communication data to identify malicious data sent via the router;

generating a list of candidate Internet Protocol (IP) addresses having a probability of sending malicious data via the router;

sending the list of candidates to the router;

receiving additional telemetry about data received from the IP addresses included in the list of candidates;

narrowing down the list of candidates to a list of verified attackers;

generating one or more attack signatures configured to identify the port scanning traffic from the IP addresses included in the list of candidates; and

sending the one or more attack signatures to the router,

wherein sending the list of candidates to the router via a software-defined network protocol capable of configuring the router.

17. The method of claim 16 , wherein the software-defined network protocol is Netconf.

18. The method of claim 16 , wherein the additional telemetry comprises a set of parameters including source IP address/port number, destination IP address/port number and a communication protocol used to transfer the data via the router.

19. The method of claim 16 , wherein providing the additional telemetry comprises increasing a sampling rate of packets sent from the IP addresses included in the list of candidates.

20. The method of claim 16 , further comprising monitoring a counter representing a number of times a specific IP address appears in the list of candidates sending malicious data via the router.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: FITE, LIOR
To: EDGEHAWK SECURITY LTD.
Reel/Frame 059867/0328 →
Continuity (1)
Related Publication 20230319078A1 · Oct 5, 2023
Cited By (1)
US 12,574,287