IP Library › Granted Patent US 12,592,959
Granted Patent B2
US 12,592,959 · App. 18/340,076 · Granted Mar 31, 2026

Detecting malicious command and control cloud traffic

Inventors: Dagmawi Mulugeta (London, GB); Raymond Joseph Canzanese, Jr. (Philadelphia, PA); Colin Estep (Eagle, ID); Siying Yang (Saratoga, CA); Jenko Hwong (San Mateo, CA); Gustavo Palazolo Eiras (São Paulo, BR); Yongxing Wang (San Ramon, CA)
Assignee: Netskope, Inc.
H04L63/1441H04L63/029H04L63/0884H04L63/18H04L63/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,592,959
App. No.
18/340,076
Granted
Mar 31, 2026
Kind
B2
Abstract

The technology disclosed relates to a method, system, and non-transitory computer-readable media that detects malicious communication between a command and control (C2) cloud resource on a cloud application and malware on an infected host, using a network security system. The network security system reroutes the cloud traffic to the network security system. The incoming requests of the cloud traffic are directed to a cloud application in the plurality of cloud applications, and wherein the cloud application has a plurality of resources. The network security system analyzes the incoming requests, determines that the incoming requests are targeted at one or more malicious resources in the plurality of resources. Also, the network security system prevents transmission of the incoming requests to the malicious resources, by making the malicious resources unavailable for receiving future incoming requests, while keeping other resources in the plurality of resources available for receiving the future incoming requests.

Claims (50)

1 . A computer-implemented method of detecting malicious communication between a command and control (C2) cloud resource on a cloud application and malware on an infected host, including:

a network security system intermediating cloud traffic between a plurality of clients and a plurality of cloud applications over a secure tunnel established between the plurality of clients and the network security system, wherein the secure tunnel reroutes the cloud traffic to the network security system;

the network security system receiving one or more incoming requests from a client in the plurality of clients, wherein the incoming requests are directed to a cloud application in the plurality of cloud applications, and wherein the cloud application has a plurality of resources;

the network security system, based on analyzing the incoming requests, determining that the incoming requests are targeted at one or more malicious resources in the plurality of resources; and

the network security system, based on the determination:

preventing transmission of the incoming requests to the malicious resources,

making the malicious resources unavailable for receiving future incoming requests, and

keeping other resources in the plurality of resources available for receiving the future incoming requests.

2 . The computer-implemented method of claim 1 , wherein the analyzing the incoming requests includes the network security system detecting a beaconing behavior of the incoming requests.

3 . The computer-implemented method of claim 2 , wherein the beaconing behavior is detected based on the incoming requests making frequent checks to a same unified resource locator (URL).

4 . The computer-implemented method of claim 2 , wherein the beaconing behavior is detected based on the incoming requests being issued by previously unexecuted processes on the client.

5 . The computer-implemented method of claim 2 , wherein the beaconing behavior is detected based on the incoming requests attempting to transmit contents that have substantially similar data sizes, wherein the substantially similar data sizes have sizes with a difference of less than 1 KB.

6 . The computer-implemented method of claim 2 , wherein the beaconing behavior is detected based on the incoming requests being iteratively issued using a same Hypertext Transfer Protocol (HTTP) method and receiving failed responses.

7 . The computer-implemented method of claim 1 , wherein the analyzing the incoming requests includes the network security system detecting that the incoming requests are en route to an anomalous entity on the cloud application.

8 . The computer-implemented method of claim 1 , wherein the analyzing the incoming requests includes the network security system detecting that the incoming requests originate from an anomalous agent running on the client.

9 . The computer-implemented method of claim 1 , wherein the analyzing the incoming requests includes the network security system detecting that the incoming requests use an anomalous username to access the cloud application.

10 . The computer-implemented method of claim 1 , wherein the analyzing the incoming requests includes the network security system detecting that the incoming requests use an anomalous authentication method to access the cloud application.

11 . The computer-implemented method of claim 1 , wherein the analyzing the incoming requests includes the network security system detecting a cat's-paw behavior of the client.

12 . The computer-implemented method of claim 1 , wherein the analyzing the incoming requests includes the network security system detecting an anomalous hostname access patterns of the incoming requests.

13 . The computer-implemented method of claim 1 , wherein the analyzing the incoming requests includes the network security system detecting a malicious task sequence execution being attempted by the incoming requests.

14 . A non-transitory, computer-readable storage medium having stored thereon instructions to detect malicious communication between a command and control (C2) cloud resource on a cloud application and malware on an infected host that, upon execution by one or more processors, cause the one or more processors to:

intermediate cloud traffic between a plurality of clients and a plurality of cloud applications over a secure tunnel established between the plurality of clients and a network security system, wherein the secure tunnel reroutes the cloud traffic to the network security system;

receive one or more incoming requests from a client in the plurality of clients, wherein the incoming requests are directed to a cloud application in the plurality of cloud applications, and wherein the cloud application has a plurality of resources;

based on analyzing the one or more incoming requests, determine that the incoming requests are targeted at one or more malicious resources in the plurality of resources; and

based on the determination:

prevent transmission of the incoming requests to the malicious resources,

make the malicious resources unavailable for receiving future incoming requests, and

keep other resources in the plurality of resources available for receiving the future incoming requests.

15 . The non-transitory, computer-readable storage medium of claim 14 , wherein the analyzing the incoming requests includes detecting a beaconing behavior of the incoming requests.

16 . The non-transitory, computer-readable storage medium of claim 15 , wherein the beaconing behavior is detected based on the incoming requests making frequent checks to a same unified resource locator (URL).

17 . The non-transitory, computer-readable storage medium of claim 15 , wherein the beaconing behavior is detected based on the incoming requests being issued by previously unexecuted processes on the client.

18 . The non-transitory, computer-readable storage medium of claim 14 , wherein the analyzing the incoming requests includes:

detecting that the incoming requests use an anomalous username to access the cloud application, or

detecting that the incoming requests use an anomalous authentication method to access the cloud application, or

detecting that the incoming requests are en route to an anomalous entity on the cloud application, or

detecting that the incoming requests originate from an anomalous agent running on the client or the incoming requests use an anomalous username to access the cloud application or a cat's-paw behavior of the client, or

detecting anomalous hostname access patterns of the incoming requests, or

detecting a malicious task sequence execution being attempted by the incoming requests, or

a combination thereof.

19 . A network security system, comprising:

one or more processors; and

a memory having stored thereon instructions to detect malicious communication between a command and control (C2) cloud resource on a cloud application and malware on an infected host that, upon execution by the one or more processors, cause the one or more processors to:

intermediate cloud traffic between a plurality of clients and a plurality of cloud applications over a secure tunnel established between the plurality of clients and the network security system, wherein the secure tunnel reroutes the cloud traffic to the network security system;

receive one or more incoming requests from a client in the plurality of clients, wherein the incoming requests are directed to a cloud application in the plurality of cloud applications, and wherein the cloud application has a plurality of resources;

based on analyzing the one or more incoming requests, determine that the incoming requests are targeted at one or more malicious resources in the plurality of resources; and

based on the determination:

prevent transmission of the incoming requests to the malicious resources,

make the malicious resources unavailable for receiving future incoming requests, and

keep other resources in the plurality of resources available for receiving the future incoming requests.

20 . The network security system of claim 19 , wherein the analyzing the one or more incoming requests includes detecting a beaconing behavior of the incoming requests, wherein the beaconing behavior is detected based on the one or more incoming requests attempting to transmit contents that have substantially similar data sizes or the one or more incoming requests being iteratively issued using a same Hypertext Transfer Protocol (HTTP) method and receiving failed responses.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2024
From: MULUGETA, DAGMAWI; CANZANESE, RAYMOND JOSEPH, JR.; ESTEP, COLIN; YANG, SIYING; HWONG, JENKO; EIRAS, GUSTAVO PALAZOLO; WANG, YONGXING
To: NETSKOPE, INC.
Reel/Frame 066720/0300 →
Continuity (2)
Continuation 17863311 · Jul 12, 2022
Related Publication 20240022594A1 · Jan 18, 2024
References Cited (129)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10395029B1 · Steinberg · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10726127B1 · Steinberg · 2020 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11075933B1 · Fetters et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 11288369B1 · Grzonkowski et al. · 2022 [cited by applicant]
US 11487876B1 · Pryde · 2022 [cited by applicant]
US 11558401B1 · Vashisht et al. · 2023 [cited by applicant]
US 11616799B1 · Canzanese, Jr. et al. · 2023 [cited by applicant]
US 11838300B1 · Vashisht et al. · 2023 [cited by applicant]
US 11886585B1 · Davis · 2024 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-LeMair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080082662A1 · Dandliker · 2008 [cited by examiner]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20150161386A1 · Gupta et al. · 2015 [cited by applicant]
US 20150372980A1 · Eyada · 2015 [cited by applicant]
US 20160134651A1 · Hu et al. · 2016 [cited by applicant]
US 20160277435A1 · Salajegheh et al. · 2016 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160330236A1 · Reddy · 2016 [cited by examiner]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20180069883A1 · Meshi et al. · 2018 [cited by applicant]
US 20180191763A1 · Hillard et al. · 2018 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20220121995A1 · Chari et al. · 2022 [cited by applicant]
US 20220224724A1 · Bazalgette et al. · 2022 [cited by applicant]
US 20220353284A1 · Vörös et al. · 2022 [cited by applicant]
US 20240378288A1 · Hussain et al. · 2024 [cited by applicant]
EP 1063833A2 · 2000 [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
Mccullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-,What are the different email protoco… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?Offer=ab… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet, FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc.,U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. s&p. 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” filed Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” filed Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 17/863,337 Notice of Allowance dated Jul. 20, 2023, 9 pages. [cited by applicant]
U.S. Appl. No. 17/863,337 Final Office Action dated May 8, 2023, 11 pages. [cited by applicant]
Cited By (1)
US 12,706,766