IP Library › Granted Patent US 12,250,244
Granted Patent B2
US 12,250,244 · App. 17/139,661 · Granted Mar 11, 2025

Batch clustering of online attack narratives for botnet detection

Inventors: Ori Nakar (Givat Shemuel, IL); Amit Leibovitz (Givat Shemuel, IL)
Assignee: Imperva, Inc.
H04L63/1458G06F18/22G06F18/23H04L63/0236H04L63/14H04L63/1466H04L63/1475H04L2463/144
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,250,244
App. No.
17/139,661
Granted
Mar 11, 2025
Kind
B2
Abstract

A method includes identifying, from online clustering data, an internet protocol (IP) pair. The method further includes determining, by a processing device during an offline process, that the IP pair is part of a botnet. The method further includes, in response to the determining, appending data associated with the botnet to the online clustering data.

Claims (40)

1. A method comprising:

identifying, from online clustering data comprising a plurality of event clusters, an internet protocol (IP) pair, wherein the IP pair comprises two source IP addresses;

determining, during an offline process of clustering the plurality of event clusters, a distance metric corresponding to a distance between a feature of each of the two source IP addresses;

determining, by a processing device during the offline process, that the IP pair is part of a botnet when the distance metric is less than a predefined threshold;

in response to the determining, appending data associated with the botnet to the online clustering data to generate enhanced clustering data; and

analyzing, using an online clustering algorithm, a new set of incidents based on the enhanced clustering data to detect events occurring over a time frame or events occurring over multiple sites, wherein the new set of incidents are analyzed to classify the new set of incidents based on at least one selected from a group comprising a number of customers involved, a type of attack, and a histogram/distribution of industries, and wherein the new set of incidents are classified as being a targeted attack or a community attack as being an industry-based attack or a spray-and-pray attack.

2. The method of claim 1 , wherein in response to the determining, the method further comprising blocking one or more IP addresses associated with the botnet.

3. The method of claim 1 , further comprising:

extracting the feature from the online clustering data; and

defining a distance function corresponding to the distance metric, the distance function to calculate a distance between the feature of the two source IP addresses, respectively.

4. The method of claim 3 , wherein the feature comprises at least one of: an IP property, a correlation property, a narrative property, or a history property.

5. The method of claim 1 , further comprising determining that the botnet is associated with a multi-site attack.

6. The method of claim 1 , further comprising determining that the botnet is associated with an attack occurring over a duration that exceeds a predefined threshold.

7. The method of claim 1 , further comprising determining that the botnet is associated with an attack occurring over a regular period.

8. A system, comprising:

a memory to store data associated with a botnet; and

a processing device, operatively coupled to the memory, the processing device to:

identify, from online clustering data comprising a plurality of event clusters, an internet protocol (IP) pair, wherein the IP pair comprises two source IP addresses;

determine, during an offline process of clustering the plurality of event clusters, a distance metric corresponding to a distance between a feature of each of the two source IP addresses;

determine, during the offline process, that the IP pair is part of the botnet when the distance metric is less than a predefined threshold;

in response to the determination, append the data associated with the botnet to the online clustering data to generate enhanced clustering data; and

analyze, using an online clustering algorithm, a new set of incidents based on the enhanced clustering data to detect events occurring over a time frame or events occurring over multiple sites, wherein the new set of incidents are analyzed to classify the new set of incidents based on at least one selected from a group comprising a number of customers involved, a type of attack, and a histogram/distribution of industires, and wherein the new set of incidents are classified as being a targeted attack or a community attack as being an industry-based attack or a spray-and-pray attack.

9. The system of claim 8 , wherein in response to the determination, the processing device is further to block one or more IP addresses associated with the botnet.

10. The system of claim 8 , the processing device further to:

extracting the feature from the online clustering data; and

defining a distance function corresponding to the distance metric, the distance function to calculate a distance between the feature of the two source IP addresses, respectively.

11. The system of claim 8 , wherein the feature comprises at least one of: an IP property, a correlation property, a narrative property, or a history property.

12. The system of claim 8 , the processing device further to determine that the botnet is associated with a multi-site attack.

13. The system of claim 8 , the processing device further to determine that the botnet is associated with an attack occurring over a duration that exceeds a predefined threshold.

14. The system of claim 8 , the processing device further to determine that the botnet is associated with an attack occurring over a regular period.

15. A non-transitory computer-readable storage medium, comprising instructions, which when executed by a processing device cause the processing device to:

identify, from online clustering data comprising a plurality of event clusters, an internet protocol (IP) pair, wherein the IP pair coprises two source IP addresses;

determining, during an offline process of clustering the plurality of event clusters, a distance metric corresponding to a distance between a feature of each of the two source IP addresses;

determine, by the processing device during an offline process, that the IP pair is part of a botnet when the distance metric is less than a predefined threshold;

in response to the determination, append data associated with the botnet to the online clustering data to generate enhanced clustering data; and

analyze, using an online clustering algorithm, a new set of incidents based on the enhanced clustering data to detect events occurring over a time frame or events occurring over multiple sites, wherein the new set of incidents are analyzed to classify the new set of incidents based on at least one selected from a group comprising a number of customers involved, a type of attack, and a histogram/distribution of industries, and wherein the new set of incidents are classified as being a targeted attack or a community attack as being an industry-based attack or a spray-and-pray attack.

16. The non-transitory computer-readable storage medium of claim 15 , wherein in response to the determination, the processing device is further to block one or more IP addresses associated with the botnet.

17. The non-transitory computer-readable storage medium of claim 15 , the processing device further to:

extracting the feature from the online clustering data; and

defining a distance function corresponding to the distance metric, the distance function to calculate a distance between the feature of the two source IP addresses, respectively.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 4, 2021
From: NAKAR, ORI; LEIBOVITZ, AMIT
To: IMPERVA, INC.
Reel/Frame 054800/0160 →
Continuity (1)
Related Publication 20220210184A1 · Jun 30, 2022
References Cited (8)
US 8682812B1 · Ranjan · 2014 [cited by examiner]
US 8745731B2 · Achan · 2014 [cited by examiner]
US 9843596B1 · Averbuch · 2017 [cited by examiner]
US 20150319185A1 · Kirti · 2015 [cited by examiner]
US 20160173446A1 · Nantel · 2016 [cited by examiner]
US 20160226904A1 · Bartos · 2016 [cited by examiner]
US 20180332064A1 · Harris · 2018 [cited by examiner]
US 20190372934A1 · Yehudai · 2019 [cited by examiner]