IP Library › Granted Patent US 12,457,225
Granted Patent B1
US 12,457,225 · App. 18/964,871 · Granted Oct 28, 2025

System and method for passive identification and detection of botnets

Inventors: Vladislav Bukin (Hod Hasharon, IL); Tom Mark (Tel Aviv, IL); Evgeny Fedoruk (Tel Aviv, IL); Namik Binyaminov (Or Akiva, IL); Nadav Shaoulian (Tel Aviv, IL); Nadav Spitzer (Jerusalem, IL); Shai Levi (Modiin, IL)
Assignee: Radware, Ltd.
H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,457,225
App. No.
18/964,871
Granted
Oct 28, 2025
Kind
B1
Abstract

A system and method for detecting botnets are provided. The method includes monitoring a network traffic to collect network data for a device; mapping the device to members of at least one stored botnet, wherein the mapping matches a network data of the device to network data of the members of the at least one stored botnet; determining the mapped device as a botnet device of an associated botnet upon matching the network data of the device to a network data of a member of the associated botnet, wherein the associated botnet is the at least one stored botnet; and logging the network data of the mapped device as being part of the at least one stored botnet.

Claims (48)

1. A method for detecting botnets, comprising: monitoring a network traffic to collect network data for

a device, wherein the network traffic is directed to at least one honeypot of a plurality of honeypots, wherein the plurality of honeypots are segregated from protected entities;

mapping the device to members of at least one stored group of botnet devices, wherein the mapping matches a network data of the device to network data of the members of the at least one stored group of botnet devices;

determining the mapped device as a botnet device of an associated botnet upon matching the network data of the device to a network data of a member of the associated botnet, wherein the associated botnet is the at least one stored botnet, wherein the network data includes an estimated startup time of the member;

discovering members of at least one stored group of botnet devices by analyzing respective estimated startup times of the discovered members; and

logging the network data of the mapped device as being part of the associated botnet of the at least one stored grouped set of botnet devices;

and triggering execution of a mitigation action on the associated botnet in response to determination that the number of members of the grouped set of botnet devices exceed a predefined proportion of a total number of expected members of the botnet.

2. The method of claim 1 , further comprising:

grouping the determined botnet device with respect to the associated botnet; and

determining that the group of the associated botnet has at least a predefined proportion of members, wherein the members are botnet devices employed by the associated botnet.

3. The method of claim 2 , further comprising:

declaring a botnet activity upon determining that the group has the at least a predefined proportion of members.

4. The method of claim 1 , wherein the network data is collected from packets exchanged in a 3-way TCP handshake.

5. The method of claim 1 , wherein the monitored network traffic is towards a protected entity.

6. The method of claim 1 , wherein the discovering further comprises:

analyzing network data for a plurality of devices;

clustering the plurality of devices based on the analyzed network data for each of the plurality of devices, wherein a cluster has devices with proximate analyzed network data;

labeling the devices of the cluster with respect to the cluster; and

identifying at least a portion of the labeled devices as the members of the at least one stored botnet, wherein a stored botnet of the at least one stored botnet has devices with a same label.

7. The method of claim 6 , wherein the analyzed network data includes at least one of: a roundtrip time (RTT), and a rise time.

8. The method of claim 6 , wherein network data for the plurality of devices for the analyzing is collected from at least one honeypot.

9. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

monitoring a network traffic to collect network data for a device, wherein the network traffic is directed to at least one honeypot of a plurality of honeypots, wherein the plurality of honeypots are segregated from protected entities;

mapping the device to members of at least one stored group of botnet devices, wherein the mapping matches a network data of the device to network data of the members of the at least one stored group of botnet devices;

determining the mapped device as a botnet device of an associated botnet upon matching the network data of the device to a network data of a member of the associated botnet, wherein the associated botnet is the at least one stored botnet, wherein the network data includes an estimated startup time of the member;

discovering members of at least one stored botnet by analyzing respective estimated startup times of the discovered members of the at least one stored group of botnet devices; and

logging the network data of the mapped device as being part of the associated botnet of the at least one stored group of botnet devices; and

triggering execution of a mitigation action on the associated botnet in response to determination that the number of members of the grouped set of botnet devices exceed a predefined proportion of a total number of expected members of the botnet.

10. A system for detecting botnets, comprising: a processing circuitry; and a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

monitor a network traffic to collect network data for a device, wherein the network traffic is directed to at least one honeypot of a plurality of honeypots, wherein the plurality of honeypots are segregated from protected entities;

map the device to members of at least one stored group of botnet devices, wherein the mapping matches a network data of the device to network data of the members of the at least one stored group of botnet devices;

determine the mapped device as a botnet device of an associated botnet upon matching the network data of the device to a network data of a member of the associated botnet, wherein the associated botnet is the at least one stored botnet, wherein the network data includes an estimated startup time of the member;

discover members of at least one stored group of botnet devices by analyzing respective estimated startup times of the discovered members of the at least one stored group of botnet devices; and

log the network data of the mapped device as being part of the associated botnet of the at least one stored group of botnet devices; and

triggering execution of a mitigation action on the associated botnet in response to determination that the number of members of the grouped set of botnet devices exceed a predefined proportion of a total number of expected members of the botnet.

11. The system of claim 10 , wherein the system is further configured to:

group the determined botnet device with respect to the associated botnet; and

determine that the group of the associated botnet has at least a predefined proportion of members, wherein the members are botnet devices employed by the associated botnet.

12. The system of claim 11 , wherein the system is further configured to:

declare a botnet activity upon determining that the group has the at least a predefined proportion of members.

13. The system of claim 10 , wherein the network data is collected from packets exchanged in a 3-way TCP handshake.

14. The system of claim 10 , wherein the system is further configured to:

analyze network data for a plurality of devices;

cluster the plurality of devices based on the analyzed network data for each of the plurality of devices, wherein a cluster has devices with proximate analyzed network data;

label the devices of the cluster with respect to the cluster; and

identify at least a portion of the labeled devices as the members of the at least one stored botnet, wherein a stored botnet of the at least one stored botnet has devices with a same label.

15. The system of claim 14 , wherein the analyzed network data includes at least one of: a roundtrip time (RTT), and a rise time.

16. The system of claim 14 , wherein network data for the plurality of devices for the analyzing is collected from at least one honeypot.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 2, 2024
From: BUKIN, VLADISLAV; MARK, TOM; FEDORUK, EVGENY; BINYAMINOV, NAMIK; SHAOULIAN, NADAV; SPITZER, NADAV; LEVI, SHAI
To: RADWARE LTD.
Reel/Frame 069448/0854 →
References Cited (14)
US 8555388B1 · Wang · 2013 [cited by examiner]
US 8677479B2 · Neystadt · 2014 [cited by examiner]
US 9444835B2 · Thomas · 2016 [cited by examiner]
US 9773112B1 · Rathor et al. · 2017 [cited by applicant]
US 9930065B2 · Nelms et al. · 2018 [cited by applicant]
US 10721148B2 · Ravid · 2020 [cited by examiner]
US 11843622B1 · Tellez · 2023 [cited by examiner]
US 20100138377A1 · Wright · 2010 [cited by examiner]
US 20170251005A1 · Niv · 2017 [cited by examiner]
US 20170251016A1 · Niv · 2017 [cited by examiner]
US 20180145978A1 · Kim et al. · 2018 [cited by applicant]
US 20180246552A1 · Thompson et al. · 2018 [cited by applicant]
US 20200021647A1 · Shieh · 2020 [cited by examiner]
US 20200366689A1 · Lotia · 2020 [cited by examiner]