IP Library Granted Patent US 8,370,928
Granted Patent B1
US 8,370,928 · App. 11/341,929 · Granted Feb 5, 2013

System, method and computer program product for behavioral partitioning of a network to detect undesirable nodes

Inventors: Rajiv Motwani (Bangalore, IN); Gerald S. Painkras (Bangalore, IN)
Assignee: McAfee, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,370,928
App. No.
11/341,929
Granted
Feb 5, 2013
Kind
B1
Abstract

A system, method and computer program product are provided. In use, votes from a plurality of nodes for node categorization are monitored. Further, a pattern associated with the votes is identified. Thus, malicious nodes may be identified based on the pattern.

Claims (31)

1. A method, comprising:

monitoring votes from a plurality of nodes for node categorization;

identifying a pattern associated with the votes;

identifying undesirable nodes based on the pattern associated with the votes, wherein the node categorization includes identifying at least some of the undesirable nodes as malicious nodes being associated with propagation of malware, and wherein the malicious nodes are provided on a black list; and

implementing a policy at a firewall that precludes communication with the malicious nodes provided on the black list and that withdrawals data access rights for the malicious nodes provided on the black list, wherein a network is partitioned for the malicious nodes based on the pattern, and wherein partitions that include the malicious nodes are refined over iterations of subsequent voting sessions involving the plurality of nodes.

2. The method of claim 1 , wherein the votes categorize at least some of the plurality of nodes as white listed nodes.

3. The method of claim 1 , wherein monitoring includes monitoring the votes during multiple voting sessions.

4. The method of claim 3 , wherein each voting session involves votes submitted by a plurality of the nodes relating to a newly added node, or to interactions between existing nodes.

5. The method of claim 1 , wherein the undesirable nodes are identified by grouping at least some of the plurality of nodes into groups based on the pattern associated with the votes.

6. The method of claim 5 , wherein at least some of the plurality of nodes with similar votes are grouped together.

7. The method of claim 6 , wherein at least some of the plurality of nodes with a predetermined threshold of similar votes are grouped together.

8. The method of claim 5 , whereupon one of nodes in one of the groups being black listed, all of the nodes of the group are black listed.

9. The method of claim 5 , whereupon one of nodes in one of the groups being white listed, all of the nodes of the group are white listed.

10. The method of claim 1 , wherein at least some of the plurality of nodes includes at least one of users, accounts, and computers.

11. The method of claim 1 , wherein the votes are submitted by at least some of the plurality of nodes utilizing a network.

12. The method of claim 1 , wherein at least some of the plurality of nodes are members of a peer-to-peer network.

13. The method of claim 1 , wherein, for each possible pair of nodes in the plurality of nodes, the pattern associated with the votes is identified by comparing votes between the pair of nodes to identify the similarities amongst the votes and the differences amongst the votes.

14. The method of claim 13 , wherein the comparing includes summing the similarities amongst the votes and the differences amongst the votes to calculate a net result.

15. The method of claim 1 , wherein a pair of nodes in the plurality of nodes are grouped together where the pair of nodes both include a threshold number of differences with respect to a common node during a plurality of voting sessions, when, during the voting sessions, remaining nodes in the plurality of nodes include similarities with respect to the common node.

16. The method of claim 1 , wherein network communication is allowed to nodes categorized as white listed nodes.

17. A computer program product embodied on a non-transitory computer readable medium for performing operations, comprising:

monitoring votes from a plurality of nodes for node categorization;

identifying a pattern associated with the votes;

identifying undesirable nodes based on the pattern associated with the votes, wherein the node categorization includes identifying at least some of the undesirable nodes as malicious nodes being associated with propagation of malware, and wherein the malicious nodes are provided on a black list; and

implementing a policy at a firewall that precludes communication with the malicious nodes provided on the black list and that withdrawals data access rights for the malicious nodes provided on the black list, wherein a network is partitioned for the malicious nodes based on the pattern, and wherein partitions that include the malicious nodes are refined over iterations of subsequent voting sessions involving the plurality of nodes.

18. A system, comprising:

a processor, wherein the system is configured for:

monitoring votes from a plurality of nodes for node categorization;

identifying a pattern associated with the votes;

identifying undesirable nodes based on the pattern associated with the votes, wherein the node categorization includes identifying at least some of the undesirable nodes as malicious nodes being associated with propagation of malware, and wherein the malicious nodes are provided on a black list; and

implementing a policy at a firewall that precludes communication with the malicious nodes provided on the black list and that withdrawals data access rights for the malicious nodes provided on the black list, wherein a network is partitioned for the malicious nodes based on the pattern, and wherein partitions that include the malicious nodes are refined over iterations of subsequent voting sessions involving the plurality of nodes.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2006
From: MOTWANI, RAJIV; PAINKRAS, GERALD S.
To: MCAFEE, INC.
Reel/Frame 017521/0845 →