IP Library › Granted Patent US 12,445,465
Granted Patent B2
US 12,445,465 · App. 18/208,198 · Granted Oct 14, 2025

Unknown exploit detection using attack traffic analysis and real-time attack event streaming

Inventors: Weihan Jiang (San Jose, CA); Zhibin Zhang (Santa Clara, CA); Kenneth Hsu (Campbell, CA); Xuya Jiang (San Jose, CA); Hui Gao (Sunnyvale, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1416H04L41/16H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,445,465
App. No.
18/208,198
Granted
Oct 14, 2025
Kind
B2
Abstract

Techniques for unknown exploit detection using attack traffic analysis and real-time attack event streaming are disclosed. In some embodiments, a system/process/computer program product for exploit detection using attack traffic analysis and real-time attack event streaming includes receiving a stream that includes a plurality of attack events from a security platform at a cloud security service; generating a cluster of attack events from the stream; and tagging the cluster with an unknown attack pattern for further automated security analysis at the cloud security service, wherein the tagged unknown attack pattern cluster does not match a preexisting signature for a known attack pattern.

Claims (36)

1. A system, comprising:

a processor configured to:

receive a stream that includes a plurality of attack events from a security platform at a cloud security service;

generate a cluster of attack events included in a moving window from the stream;

in response to a determination that an attack event that is not included in the moving window is associated with the cluster of attack events, include the attack event in the cluster of attack events included in the moving window;

chronologically order the cluster of attack events included in the moving window using information from a different log source; and

tag the cluster with an unknown attack pattern for further automated security analysis at the cloud security service, wherein the tagged unknown attack pattern cluster does not match a preexisting signature for a known attack pattern; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein one or more of the plurality of the attack events include potentially malicious threat events.

3. The system of claim 1 , wherein the plurality of the attack events comprises an attack event log stored in a data repository for the cloud security service.

4. The system of claim 1 , wherein the security platform selects a subset of events to stream to the cloud security service.

5. The system of claim 1 , wherein the security platform applies one or more of a plurality of loosely defined signatures to select a subset of events extracted from monitored network traffic associated with an enterprise network to stream to the cloud security service.

6. The system of claim 1 , wherein the processor is further configured to filter out known threat attack patterns based on a match to one or more of a plurality of Intrusion Prevention System (IPS) signatures, wherein the cloud security service only performs the further automated security analysis for tagged clusters that were determined to be unknown attack patterns based on a failure to match any of the plurality of Intrusion Prevention System (IPS) signatures.

7. The system of claim 1 , wherein the processor is further configured to receive another stream that includes a plurality of different attack events from another security platform at the cloud security service.

8. The system of claim 1 , wherein the processor is further configured to automatically generate a verdict using a machine learning model and/or a plurality of heuristics to determine that the unknown attack pattern is associated with malicious activity.

9. The system of claim 8 , wherein the processor is further configured to automatically perform a responsive action in response to a determination that the unknown attack pattern is associated with malicious activity.

10. The system of claim 8 , wherein the processor is further configured to automatically generate an alert in response to a determination that the unknown attack pattern is associated with malicious activity.

11. The system of claim 8 , wherein the processor is further configured to automatically generate a report in response to a determination that the unknown attack pattern is associated with malicious activity.

12. The system of claim 8 , wherein the processor is further configured to automatically generate a new Intrusion Prevention System (IPS) signature in response to a determination that the unknown attack pattern is associated with malicious activity.

13. The system of claim 8 , wherein the verdict is automatically generated in near real-time.

14. A method, comprising:

receiving a stream that includes a plurality of attack events from a security platform at a cloud security service;

generating a cluster of attack events included in a moving window from the stream;

in response to determining that an attack event that is not included in the moving window is associated with the cluster of attack events, including the attack event in the cluster of attack events included in the moving window;

chronologically ordering the cluster of attack events included in the moving window using information from a different log source; and

tagging the cluster with an unknown attack pattern for further automated security analysis at the cloud security service, wherein the tagged unknown attack pattern cluster does not match a preexisting signature for a known attack pattern.

15. The method of claim 14 , wherein one or more of the plurality of the attack events include potentially malicious threat events.

16. The method of claim 14 , wherein the plurality of the attack events comprises an attack event log stored in a data repository for the cloud security service.

17. The method of claim 14 , wherein the security platform selects a subset of events to stream to the cloud security service.

18. The method of claim 14 , wherein the security platform applies one or more of a plurality of loosely defined signatures to select a subset of events extracted from monitored network traffic associated with an enterprise network to stream to the cloud security service.

19. A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

receiving a stream that includes a plurality of attack events from a security platform at a cloud security service;

generating a cluster of attack events included in a moving window from the stream;

in response to determining that an attack event that is not included in the moving window is associated with the cluster of attack events, including the attack event in the cluster of attack events included in the moving window;

chronologically ordering the cluster of attack events included in the moving window using information from a different log source; and

tagging the cluster with an unknown attack pattern for further automated security analysis at the cloud security service, wherein the tagged unknown attack pattern cluster does not match a preexisting signature for a known attack pattern.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2023
From: JIANG, WEIHAN; ZHANG, ZHIBIN; HSU, KENNETH; JIANG, XUYA; GAO, HUI
To: PALO ALTO NETWORKS, INC.
Reel/Frame 064743/0068 →
Continuity (1)
Related Publication 20240414175A1 · Dec 12, 2024
References Cited (17)
US 20050022022A1 · Mendonca · 2005 [cited by examiner]
US 20060253906A1 · Rubin · 2006 [cited by examiner]
US 20070011741A1 · Robert · 2007 [cited by examiner]
US 20070058551A1 · Brusotti · 2007 [cited by examiner]
US 20110016528A1 · Zhou · 2011 [cited by examiner]
US 20140380415A1 · Wang · 2014 [cited by examiner]
US 20160028750A1 · Di Pietro · 2016 [cited by examiner]
US 20160226894A1 · Lee · 2016 [cited by examiner]
US 20160378980A1 · Ijiro · 2016 [cited by examiner]
US 20170214702A1 · Moscovici · 2017 [cited by examiner]
US 20200293653A1 · Huang · 2020 [cited by examiner]
US 20220070223A1 · Deng · 2022 [cited by examiner]
US 20230188560A1 · Doron · 2023 [cited by examiner]
US 20240273203A1 · Raca · 2024 [cited by examiner]
US 20250190553A1 · Herwono · 2025 [cited by examiner]
Chrome Developers, Puppeteer, Jun. 7, 2023. [cited by applicant]
The Apache Software Foundation, Java Multi-Language Pipelines Quickstart, Jun. 1, 2023. [cited by applicant]
Cited By (1)
US 12,676,885