IP Library Granted Patent US 12,267,348
Granted Patent B2
US 12,267,348 · App. 18/542,967 · Granted Apr 1, 2025

Network traffic correlation engine

Inventors: Jonathan Sheedy (Poynton, GB); Steven E. Sinks (Scottsdale, AZ)
Assignee: Bank of America Corporation
H04L63/1425H04L41/0686G06F21/552H04L41/0631H04L43/062H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,348
App. No.
18/542,967
Granted
Apr 1, 2025
Kind
B2
Abstract

A network traffic correlation engine monitors inbound and/or outbound connection information received from on each host computer system on a network. Each host device on the network store data logs corresponding to information corresponding to communications sent by the device and received by the device. The network traffic correlation engine correlates connections between different hosts throughout the network. If the network traffic correlation engine identified unmatched outbound and inbound connections, the network traffic correlation engine generates an alert to initiate further investigation and may also provide a mapping of the communications showing a possible start device for the connection and/or a type of access that the connections may now be providing.

Claims (42)

1. A system comprising:

a first host device communicating on an enterprise network; and

a second host device, comprising:

a processor; and

non-transitory memory storing instructions that, when executed by the processor, cause the second host device to:

aggregate network communications information from the enterprise network, wherein the network communications information comprises inbound and outbound connection information of a plurality of hosts on the enterprise network;

identify whether a correlation exists between a first communication sent from the first host device to the second host device and a second communication received by the second host device;

identify, based on an identified correlation between the first communication and the second communication, whether an anomalous communication condition exists; and

trigger, based on the correlation between the first communication and the second communication, an alert identifying that the anomalous communication condition is present between the first host device and the second host device.

2. The system of claim 1 , wherein the instructions, when executed, cause the second host device to:

aggregate information from a plurality of network communication services and data logs, wherein the information corresponds to a plurality of network communication connections to and from the first host device and the second host device.

3. The system of claim 1 , wherein the instructions, when executed cause the second host device to:

match messages received by the first host device to messages sent by the second host device based on aggregated communication information to detect an anomalous communication on the enterprise network.

4. The system of claim 1 , wherein triggering the alert comprises providing an indication of the alert on a user interface device at a central location on the enterprise network.

5. The system of claim 1 , wherein the anomalous communication condition comprises an indication that logging of sent messages was disabled.

6. The system of claim 1 , wherein monitoring of network communications information aggregated from a plurality of hosts on the enterprise network comprises aggregating information received from a plurality of different host devices comprising a plurality of different host intrusion detection systems.

7. A method comprising:

aggregating, by a network traffic correlation engine, network communications information from a plurality of different host devices on an enterprise network, wherein the network communications information comprises inbound and outbound connection information;

identifying whether a correlation exists between a first outbound communication sent from a first host device of the plurality of different host devices and a second inbound communication received by a second host device of the plurality of different host devices; and

triggering, based on the correlation, an alert identifying that an indication of host to host communication is present between the first host device and the second host device.

8. The method of claim 7 , comprising:

aggregating information from a plurality of network communication services and data logs, wherein the information corresponds to a plurality of network communication connections to and from the first host device and the second host device.

9. The method of claim 7 , comprising,

matching messages received by the first host device to messages sent by the second host device based on aggregated communication information to detect an anomalous communication condition on the enterprise network.

10. The method of claim 7 , wherein triggering the alert comprises providing an indication of the alert on a user interface device at a central location on the enterprise network.

11. The method of claim 7 , wherein the indication of host to host communications comprises an indication that logging of sent messages was disabled.

12. The method of claim 7 , further comprising aggregating information received from a plurality of host intrusion detection systems associated with a plurality of different host devices.

13. The method of claim 7 , further comprising determining, based on whether a correlation exists between a first communication and a second communication, whether an anomalous communication condition exists.

14. A computing device comprising:

a processor; and

one or more non-transitory computer-readable media storing instructions that, when executed by a host computing device comprising a processor, memory, and a communication interface, cause the host computing device to:

aggregate network communications information from a plurality of hosts on an enterprise network, wherein the network communications information comprises inbound and outbound connection information associated with a plurality of hosts on the enterprise network;

identify whether a correlation exists between a first outbound communication sent from a first host device and a second inbound communication received by a second host device; and

trigger, based on the correlation, an alert identifying that an indication of host to host communication is present on the enterprise network.

15. The one or more non-transitory computer-readable media of claim 14 , wherein the instructions, when executed by the processor, cause the host computing device to:

aggregate information from a plurality of network communication services and data logs, wherein the information corresponds to a plurality of network communication connections to and from the first host device and the second host device.

16. The one or more non-transitory computer-readable media of claim 15 , wherein the instructions, when executed by the processor, cause the host computing device to:

match messages received by the first host device to messages sent by the second host device based on the aggregated information to detect an anomalous communication on the enterprise network.

17. The one or more non-transitory computer-readable media of claim 14 , wherein triggering the alert comprises providing an indication of the alert on a user interface device at a central location on the enterprise network.

18. The one or more non-transitory computer-readable media of claim 14 , wherein an anomalous communication condition comprises an indication that logging of sent messages was disabled.

19. The one or more non-transitory computer-readable media of claim 14 , wherein monitoring of network communications information aggregated from a plurality of hosts on the enterprise network comprises aggregating information received from a plurality of host intrusion detection systems associated with different host devices of the plurality of hosts.

20. The one or more non-transitory computer-readable media of claim 15 , wherein the instructions further cause the host computing device to determine, based on whether a correlation exists between a first communication and a second communication, whether an anomalous communication condition exists.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2023
From: SHEEDY, JONATHAN; SINKS, STEVEN E.
To: BANK OF AMERICA CORPORATION
Reel/Frame 065894/0555 →
Continuity (3)
Continuation 18156094 · Jan 18, 2023
Continuation 17003033 · Aug 26, 2020
Related Publication 20240121257A1 · Apr 11, 2024
References Cited (36)
US 6721689B2 · Markle et al. · 2004 [cited by applicant]
US 7152242B2 · Douglas · 2006 [cited by applicant]
US 7447768B2 · Kelly et al. · 2008 [cited by applicant]
US 7934253B2 · Overcash et al. · 2011 [cited by applicant]
US 8589595B2 · Barranco · 2013 [cited by examiner]
US 8694624B2 · Sinha · 2014 [cited by examiner]
US 9003528B2 · Stolfo · 2015 [cited by applicant]
US 9055090B2 · Delatorre et al. · 2015 [cited by applicant]
US 9143518B2 · Sidiroglou et al. · 2015 [cited by applicant]
US 9204293B2 · Imbimbo et al. · 2015 [cited by applicant]
US 9215244B2 · Ayyagari et al. · 2015 [cited by applicant]
US 9392007B2 · Giokas · 2016 [cited by applicant]
US 9397880B1 · Lee et al. · 2016 [cited by applicant]
US 9654478B2 · Stolfo et al. · 2017 [cited by applicant]
US 9762596B2 · Wang et al. · 2017 [cited by applicant]
US 10146939B2 · Stolfo et al. · 2018 [cited by applicant]
US 10152596B2 · Pieczul · 2018 [cited by applicant]
US 10237290B2 · Balakrishnan et al. · 2019 [cited by applicant]
US 10270789B2 · Singh · 2019 [cited by applicant]
US 10291506B2 · Mixer · 2019 [cited by examiner]
US 10362057B1 · Wu · 2019 [cited by applicant]
US 10372906B2 · Pieczul · 2019 [cited by applicant]
US 10417888B2 · Emmanuel et al. · 2019 [cited by applicant]
US 10536482B2 · Gabaev et al. · 2020 [cited by applicant]
US 10560487B2 · Shulman-Peleg et al. · 2020 [cited by applicant]
US 10574512B1 · Mermoud et al. · 2020 [cited by applicant]
US 10798114B2 · Galula et al. · 2020 [cited by applicant]
US 10965516B2 · Fenoglio et al. · 2021 [cited by applicant]
US 11277420B2 · Côtéet al. · 2022 [cited by applicant]
US 11601457B2 · Sheedy · 2023 [cited by examiner]
US 11888882B2 · Sheedy · 2024 [cited by examiner]
US 20150229661A1 · Balabine et al. · 2015 [cited by applicant]
US 20150312273A1 · Pappu · 2015 [cited by examiner]
US 20170289191A1 · Thioux et al. · 2017 [cited by applicant]
US 20190306011A1 · Fenoglio et al. · 2019 [cited by applicant]
US 20210120027A1 · Dean et al. · 2021 [cited by applicant]