IP Library Granted Patent US 12,464,012
Granted Patent B2
US 12,464,012 · App. 17/877,815 · Granted Nov 4, 2025

Cobalt strike beacon https C2 heuristic detection

Inventors: Yanhui Jia (San Jose, CA); Shengming Xu (San Jose, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/145H04L63/0236H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,464,012
App. No.
17/877,815
Filed
Jul 29, 2022
Granted
Nov 4, 2025
Kind
B2
Art Unit
2437
USPC
726/13
Abstract

Techniques for Cobalt Strike Beacon HTTPS C2 heuristic detection are disclosed. In some embodiments, a system/process/computer program product for Cobalt Strike Beacon HTTPS C2 heuristic detection includes monitoring HyperText Transfer Protocol Secure (HTTPS) network traffic at a firewall; prefiltering the monitored HTTPS network traffic at the firewall to select a subset of the HTTPS network traffic to forward to a cloud security service; determining whether the subset of the HTTPS network traffic is associated with Cobalt Strike Beacon HTTPS C2 traffic activity based on a plurality of heuristics; and performing an action in response to detecting the Cobalt Strike Beacon HTTPS C2 traffic activity.

Claims (61)

1 . A system, comprising:

a processor configured to:

monitor HyperText Transfer Protocol Secure (HTTPS) network traffic at a firewall;

prefilter the monitored HTTPS network traffic at the firewall to select a subset of the HTTPS network traffic to forward to a cloud security service;

determine that the subset of the HTTPS network traffic is associated with Cobalt Strike Beacon HTTPS C2 traffic activity based on a plurality of heuristics, comprising to:

determine that a plurality of session timestamps associated with the subset of the HTTPS network traffic has a Gaussian distribution or a normal distribution, wherein the subset of the HTTPS network traffic includes a plurality of sessions, wherein the plurality of sessions includes a first session and a second session; and

in response to a determination that the plurality of session timestamps has the Gaussian distribution or the normal distribution:

determine that a timestamp gap between the first session and the second session is less than or equal to a predefined period of time; and

in response to a determination that the timestamp gap is less than or equal to the predefined period of time:

 determine that a first hash value of a first header of the first session matches a second hash value of a second header of the second session; and

 in response to a determination that the first hash value matches the second hash value:

 determine that a number of fields in the first header is less than or equal to a predetermined threshold number of fields; and

 in response to a determination that the number of fields in the first header is less than or equal to the predetermined threshold number of fields, determine that the subset of the HTTPS network traffic is associated with the Cobalt Strike Beacon HTTPS C2 traffic activity;

 and

perform an action in response to detecting the Cobalt Strike Beacon HTTPS C2 traffic activity; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system of claim 1 , wherein a fast match table of a detection system stores previously detected Cobalt Strike Beacon HTTPS C2 traffic activity.

3 . The system of claim 1 , wherein a fast match table of a detection system stores a 3-tuple of previously detected Cobalt Strike Beacon HTTPS C2 traffic activity, wherein the 3-tuple includes a source IP address, a destination IP address, and a destination port.

4 . The system of claim 1 , wherein data statistics based on an automated heuristic analysis of the subset of the HTTPS network traffic is stored in a data statistics table of a detection system.

5 . The system of claim 1 , wherein the processor is further configured to perform a validation of the detected Cobalt Strike Beacon HTTPS C2 traffic activity.

6 . The system of claim 1 , wherein the processor is further configured to perform a validation of the detected Cobalt Strike Beacon HTTPS C2 traffic activity based on probing of a destination IP address associated with the detected Cobalt Strike Beacon HTTPS C2 traffic activity.

7 . The system of claim 1 , wherein the processor is further configured to perform a validation of the detected Cobalt Strike Beacon HTTPS C2 traffic activity based on probing of a destination IP address associated with the detected Cobalt Strike Beacon HTTPS C2 traffic activity and using a fingerprint data store.

8 . A method, comprising:

monitoring HyperText Transfer Protocol Secure (HTTPS) network traffic at a firewall;

prefiltering the monitored HTTPS network traffic at the firewall to select a subset of the HTTPS network traffic to forward to a cloud security service;

determining that the subset of the HTTPS network traffic is associated with Cobalt Strike Beacon HTTPS C2 traffic activity based on a plurality of heuristics, comprising:

determining that a plurality of session timestamps associated with the subset of the HTTPS network traffic has a Gaussian distribution or a normal distribution, wherein the subset of the HTTPS network traffic includes a plurality of sessions, wherein the plurality of sessions includes a first session and a second session; and

in response to a determination that the plurality of session timestamps has the Gaussian distribution or the normal distribution:

determining that a timestamp gap between the first session and the second session is less than or equal to a predefined period of time; and

in response to a determination that the timestamp gap is less than or equal to the predefined period of time:

determining that a first hash value of a first header of the first session matches a second hash value of a second header of the second session; and

in response to a determination that the first hash value matches the second hash value:

 determining that a number of fields in the first header is less than or equal to a predetermined threshold number of fields; and

 in response to a determination that the number of fields in the first header is less than or equal to the predetermined threshold number of fields, determining that the subset of the HTTPS network traffic is associated with the Cobalt Strike Beacon HTTPS C2 traffic activity;

and

performing an action in response to detecting the Cobalt Strike Beacon HTTPS C2 traffic activity.

9 . The method of claim 8 , wherein a fast match table of a detection system stores previously detected Cobalt Strike Beacon HTTPS C2 traffic activity.

10 . The method of claim 8 , wherein a fast match table of a detection system stores a 3-tuple of previously detected Cobalt Strike Beacon HTTPS C2 traffic activity, wherein the 3-tuple includes a source IP address, a destination IP address, and a destination port.

11 . The method of claim 8 , wherein data statistics based on an automated heuristic analysis of the subset of the HTTPS network traffic is stored in a data statistics table of a detection system.

12 . The method of claim 8 , further comprising performing a validation of the detected Cobalt Strike Beacon HTTPS C2 traffic activity.

13 . The method of claim 8 , further comprising performing a validation of the detected Cobalt Strike Beacon HTTPS C2 traffic activity based on probing of a destination IP address associated with the detected Cobalt Strike Beacon HTTPS C2 traffic activity.

14 . The method of claim 8 , further comprising performing a validation of the detected Cobalt Strike Beacon HTTPS C2 traffic activity based on probing of a destination IP address associated with the detected Cobalt Strike Beacon HTTPS C2 traffic activity and using a fingerprint data store.

15 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

monitoring HyperText Transfer Protocol Secure (HTTPS) network traffic at a firewall;

prefiltering the monitored HTTPS network traffic at the firewall to select a subset of the HTTPS network traffic to forward to a cloud security service;

determining that the subset of the HTTPS network traffic is associated with Cobalt Strike Beacon HTTPS C2 traffic activity based on a plurality of heuristics, comprising:

determining that a plurality of session timestamps associated with the subset of the HTTPS network traffic has a Gaussian distribution or a normal distribution, wherein the subset of the HTTPS network traffic includes a plurality of sessions, wherein the plurality of sessions includes a first session and a second session; and

in response to a determination that the plurality of session timestamps has the Gaussian distribution or the normal distribution:

determining that a timestamp gap between the first session and the second session is less than or equal to a predefined period of time; and

in response to a determination that the timestamp gap is less than or equal to the predefined period of time:

determining that a first hash value of a first header of the first session matches a second hash value of a second header of the second session; and

in response to a determination that the first hash value matches the second hash value:

 determining that a number of fields in the first header is less than or equal to a predetermined threshold number of fields; and

 in response to a determination that the number of fields in the first header is less than or equal to the predetermined threshold number of fields, determining that the subset of the HTTPS network traffic is associated with the Cobalt Strike Beacon HTTPS C2 traffic activity;

and

performing an action in response to detecting the Cobalt Strike Beacon HTTPS C2 traffic activity.

16 . The computer program product of claim 15 , wherein a fast match table of a detection system stores previously detected Cobalt Strike Beacon HTTPS C2 traffic activity.

17 . The computer program product of claim 15 , wherein a fast match table of a detection system stores a 3-tuple of previously detected Cobalt Strike Beacon HTTPS C2 traffic activity, wherein the 3-tuple includes a source IP address, a destination IP address, and a destination port.

18 . The computer program product of claim 15 , further comprising computer instructions for performing a validation of the detected Cobalt Strike Beacon HTTPS C2 traffic activity.

19 . The computer program product of claim 15 , further comprising computer instructions for performing a validation of the detected Cobalt Strike Beacon HTTPS C2 traffic activity based on probing of a destination IP address associated with the detected Cobalt Strike Beacon HTTPS C2 traffic activity.

20 . The computer program product of claim 15 , further comprising computer instructions for performing a validation of the detected Cobalt Strike Beacon HTTPS C2 traffic activity based on probing of a destination IP address associated with the detected Cobalt Strike Beacon HTTPS C2 traffic activity and using a fingerprint data store.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2022
From: JIA, YANHUI; XU, SHENGMING
To: PALO ALTO NETWORKS, INC.
Reel/Frame 061383/0192 →
Continuity (1)
Related Publication 20240039952A1 · Feb 1, 2024
References Cited (33)
US 8578493B1 · Cowan · 2013 [cited by examiner]
US 10715413B2 · Greene · 2020 [cited by examiner]
US 11296967B1 · Rothstein · 2022 [cited by applicant]
US 11936545B1 · Miskovic · 2024 [cited by examiner]
US 20050210294A1 · Amit · 2005 [cited by applicant]
US 20140136834A1 · Sherkin · 2014 [cited by applicant]
US 20150007312A1 · Pidathala · 2015 [cited by examiner]
US 20160149792A1 · Wang · 2016 [cited by applicant]
US 20160156644A1 · Wang · 2016 [cited by applicant]
US 20160315961A1 · Duer · 2016 [cited by applicant]
US 20170187736A1 · Fehrman · 2017 [cited by examiner]
US 20170264626A1 · Xu · 2017 [cited by examiner]
US 20170359220A1 · Weith · 2017 [cited by examiner]
US 20190253389A1 · Verma · 2019 [cited by applicant]
US 20220070223A1 · Deng · 2022 [cited by applicant]
CN 111903107 · 2020 [cited by applicant]
CN 114282223A · 2022 [cited by examiner]
Kumar, Ratnesh, and Kalyani Mali. “A Novel Approach to Edge Detection and Performance Measure . . . ” Journal of Image Processing & Pattern Recognition Progress 8.1: 31-38. (Year: 2021). [cited by examiner]
Nick Mavis, edited by Joe Marshall and Jon Munshaw, The Art and Science of Detecting Cobalt Strike, Sep. 21, 2020 (Sep. 21, 2020), Retrieved from the Internet: URL: https://www.infopoint-security.de/media/Talos_Cobalt_S… [cited by applicant]
Van Der Eijk et al., Analysis of Cobalt Strike Network Traffic Obfuscation in C2 Communication, Jul. 3, 2020 (Jul. 3, 2020), Retrieved from the Internet: URL: https://rp.os3.nl/2019-2020/p29/presentation.pdf. [cited by applicant]
Van Der Eijk et al., Detecting Cobalt Strike Beacons in NetFlow Data, Jul. 3, 2020 (Jul. 3, 2020), XP093085975, Retrieved from the Internet: URL: https://rp.os3.nl/2019-2020/p29/report.pdf. [cited by applicant]
Author Unknown, Statistics How To, Bowley Skewness: Definition, Formula, Alternate Formula, Jul. 19, 2022. [cited by applicant]
Author Unknown, WhatIsMyBrowser.com, Latest user agents for Web Browsers &Operating Systems, Jul. 19, 2022. [cited by applicant]
Cobalt Strike, Software for Adversary Simulations and Red Team Operations, Jul. 25, 2022. [cited by applicant]
Fuentes et al., Modern Ransomware's Double, Extortion Tactics and How to Protect Enterprises Against Them, 2021, pp. 1-96. [cited by applicant]
Karantzas et al., An Empirical Assessment of Endpoint Detection and Response Systems against Advanced Persistent Threats Attack Vectors, Journal of Cybersecurity and Privacy, J. Cybersecur. Priv. 2021, 1, pp. 387-421. [cited by applicant]
Redis, A Vibrant, Open Source Database, Jul. 19, 2022. [cited by applicant]
Shalaginov et al., Malware Beaconing Detection by Mining Large-scale DNS Logs for Targeted Attack dentification, World Academy of Science, Engineering and Technology International Journal of Computer, Electrical, Automa… [cited by applicant]
Wikipedia, Median Absolute Deviation, Jul. 19, 2022. [cited by applicant]
Author Unknown, Bowley Skewness: Definition, Formula, Alternate Formula, Statistics How To, Jul. 19, 2022. [cited by applicant]
Github et al., Malleable-C2-Profiles/youtube_video.profile at master ⋅ xx0hcd/Malleable-C2-Profiles, Jul. 26, 2022. [cited by applicant]
Nakamura et al., Scanning and Host Fingerprinting Methods for Command and Control Server Detection, Master of Science in Software Engineering, Jun. 2021. [cited by applicant]
Mingcai Li, Construction and Application of HTTPS File Server[J]. Digital Technology and Application, 2020, vol. 38, No. 3, pp. 146-147 & 149. [cited by applicant]