IP Library Granted Patent US 9,628,512
Granted Patent B2
US 9,628,512 · App. 14/644,186 · Granted Apr 18, 2017

Malicious relay detection on networks

Inventors: Ryan James Prenger (Oakland, CA); Nicolas Beauchesne (Miami Beach, FL); Karl Matthew Lynn (Winter Garden, FL)
Assignee: Vectra Networks, Inc.
H04L63/1475G06F17/30598H04L63/1408H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,628,512
App. No.
14/644,186
Granted
Apr 18, 2017
Kind
B2
Abstract

A system and method for detecting malicious relay communications is disclosed. Network communications can be received and analyzed using such network components as a network switch. The received traffic can be parsed into sessions. Relay metadata can be extracted from the sessions and further be used to categorize the sessions into one or more types of relay metadata behaviors. Once a significant amount of sessions are detected an alarm may be triggered and/or alarm data may be generated for analysis by network security administrators.

Claims (45)

1. A system for detecting malicious relay communication data flows between a plurality of computers, comprising:

a computer processor to execute a set of program code instructions;

a memory to hold the program code instructions, in which the program code instructions comprises program code to:

receive network traffic generated by a plurality of hosts and labels the network traffic into one or more session datasets;

extract relay metadata from the one or more session datasets;

use the relay metadata to both:

(a) categorize the one or more session datasets as data items in one or more relay data structures corresponding to one or more known relay communication patterns using the relay metadata and

(b) correlate the data items into the one or more known relay communication patterns by matching the data items to both a flow direction and a statistical description of known relay communication patterns, the known relay communication patterns corresponding to types of relay behavior communication patterns registered in a database as correlating to communications from a control computer to other hosts through a relay computer; and

generate reporting output data if a number of data items in the one or more relay data structures is equal to or exceeds a limit.

2. The system of claim 1 , wherein session dataset categorization is independent of a direction of the malicious relay communication data flows.

3. The system of claim 1 , wherein the program code further uses label constraints and flow direction constraints to categorize the one or more session datasets into the one or more relay data structures.

4. The system of claim 3 , wherein at least one of the one or more relay data structures corresponds to the label constraints and the flow direction constraints that describe a first session initiated by the control computer and directed to the relay computer and a second session initiated by the relay computer and directed to a destination computer.

5. The system of claim 3 , wherein at least one of the one or more relay data structures corresponds to the label constraints and the flow direction constraints that describe a first session initiated by a destination computer and directed to the relay computer and a second session initiated by the relay computer and directed to the control computer.

6. The system of claim 3 , wherein at least one of the one or more relay data structures corresponds to the label constraints and the flow direction constraints that describe a first session initiated by the control computer and directed to the relay computer and a second session initiated by a destination computer and directed to the relay computer.

7. The system of claim 3 , wherein at least one of the one or more relay data structures corresponds to the label constraints and the flow direction constraints that describe a first session initiated by the relay computer and directed to the control computer and a second session initiated by the relay computer and directed to a destination computer.

8. The system of claim 1 , wherein the relay metadata comprises at least one or more of the following: data corresponding to an amount of bytes in a session, data corresponding to arrival times of packets in a session, data corresponding to identifiers of one or more source or destination computers, data corresponding to a first segment of a flow, data corresponding to a time elapsed between two flows in a session, data corresponding to a mean size of packets in a session, or data corresponding a distribution of characteristics of packets in a session.

9. The system of claim 1 , wherein data items in the one or more relay data structures that are older than an expiration time are removed from the one or more relay data structures.

10. A computer-implemented method for detecting malicious relay communication data flows between a plurality of computers, comprising:

labeling network traffic that is generated by a plurality of hosts into one or more session datasets;

extracting relay metadata from the one or more session datasets;

categorizing the one or more session datasets as data items in one or more relay data structures corresponding to one or more known relay communication patterns using the relay metadata;

correlating the data items into the one or more known relay communication patterns by matching the data items to both a flow direction and a statistical description of known relay communication patterns, the known relay communication patterns corresponding to types of relay behavior communication patterns registered in a database as correlating to communications from a control computer to other hosts through a relay computer; and

generating reporting output data if a number of data items in the one or more relay data structures exceeds a limit.

11. The computer-implemented method of claim 10 , wherein session dataset categorization is independent of a direction of the malicious relay communication data flows.

12. The computer-implemented method of claim 10 , wherein categorizing the one or more session datasets as data items in one or more relay data structures uses label constraints and flow direction constraints.

13. The computer-implemented method of claim 12 , wherein at least one of the one or more relay data structures corresponds to the label constraints and the flow direction constraints that describe a first session initiated by the control computer and directed to the relay computer and a second session initiated by the relay computer and directed to a destination computer.

14. The computer-implemented method of claim 12 , wherein at least one of the one or more relay data structures corresponds to the label constraints and the flow direction constraints that describe a first session initiated by a destination computer and directed to the relay computer and a second session initiated by the relay computer and directed to the control computer.

15. The computer-implemented method of claim 12 , wherein at least one of the one or more relay data structures corresponds to the label constraints and the flow direction constraints that describe a first session initiated by the control computer and directed to the relay computer and a second session initiated by a destination computer and directed to the relay computer.

16. The computer-implemented method of claim 12 , wherein at least one of the one or more relay data structures corresponds to the label constraints and the flow direction constraints that describe a first session initiated by the relay computer and directed to the control computer and a second session initiated by the relay computer and directed to a destination computer.

17. The computer-implemented method of claim 12 , wherein the relay metadata comprises at least one or more of the following: data corresponding to an amount of bytes in a session, data corresponding to arrival times of packets in a session, data corresponding to identifiers of one or more source or destination computers, data corresponding to a first segment of a flow, data corresponding to a time elapsed between two flows in a session, data corresponding to a mean size of packets in a session, or data corresponding a distribution of characteristics of packets in a session.

18. The computer-implemented method of claim 12 , wherein data items in the one or more relay data structures that are older than an expiration time are removed from the one or more relay data structures.

19. A computer program product embodied on a non-transitory computer readable medium, the non-transitory computer readable medium having stored thereon a sequence of instructions which, when executed by a processor causes the processor to execute a method for detecting malicious relay communication data flows between a plurality of computers, the method comprising:

labeling network traffic that is generated by a plurality of hosts into one or more session datasets;

extracting relay metadata from the one or more session datasets;

categorizing the one or more session datasets as data items in one or more relay data structures corresponding to one or more known relay communication patterns using the relay metadata;

correlating the data items into the one or more known relay communication patterns by matching the data items to both a flow direction and a statistical description of known relay communication patterns, the known relay communication patterns corresponding to types of relay behavior communication patterns registered in a database as correlating to communications from a control computer to other hosts through a relay computer; and

generating reporting output data if a number of data items in the one or more relay data structures exceeds a limit.

20. The computer program product of claim 19 , wherein session dataset categorization is independent of a direction of the malicious relay communication data flows.

21. The computer program product of claim 19 , wherein categorizing the one or more session datasets as data items in one or more relay data structures uses label constraints and flow direction constraints.

22. The computer program product of claim 21 , wherein at least one of the one or more relay data structures corresponds to the label constraints and the flow direction constraints that describe a first session initiated by the control computer and directed to the relay computer and a second session initiated by the relay computer and directed to a destination computer.

23. The computer program product of claim 21 , wherein at least one of the one or more relay data structures corresponds to the label constraints and the flow direction constraints that describe a first session initiated by a destination computer and directed to the relay computer and a second session initiated by the relay computer and directed to the control computer.

24. The computer program product of claim 21 , wherein at least one of the one or more relay data structures corresponds to the label constraints and the flow direction constraints that describe a first session initiated by the control computer and directed to the relay computer and a second session initiated by a destination computer and directed to the relay computer.

25. The computer program product of claim 21 , wherein at least one of the one or more relay data structures corresponds to the label constraints and the flow direction constraints that describe a first session initiated by the relay computer and directed to the control computer and a second session initiated by the relay computer and directed to a destination computer.

26. The computer program product of claim 19 , wherein the relay metadata comprises one or more of the following: data corresponding to an amount of bytes in a session, data corresponding to arrival times of packets in a session, data corresponding to identifiers of one or more source or destination computers, data corresponding to a first segment of a flow, data corresponding to a time elapsed between two flows in a session, data corresponding to a mean size of packets in a session, and data corresponding a distribution of characteristics of packets in a session.

27. The computer program product of claim 19 , wherein data items in the one or more relay data structures that are older than an expiration time are removed from the one or more relay data structures.

Assignments (6)
SECURITY INTEREST Recorded Oct 29, 2024
From: VECTRA AI, INC.
To: AB PRIVATE CREDIT INVESTORS LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 069061/0588 →
CHANGE OF NAME Recorded Sep 20, 2024
From: VECTRA NETWORKS, INC.
To: VECTRA AI, INC.
Reel/Frame 069012/0717 →
RELEASE OF SECURITY INTEREST Recorded Mar 19, 2021
From: SILVER LAKE WATERMAN FUND, L.P., AS AGENT
To: VECTRA AI, INC.
Reel/Frame 055656/0351 →
CHANGE OF NAME Recorded Nov 4, 2019
From: VECTRA NETWORKS, INC.
To: VECTRA AI, INC.
Reel/Frame 050925/0991 →
SECURITY INTEREST Recorded Mar 13, 2019
From: VECTRA AI, INC.
To: SILVER LAKE WATERMAN FUND, L.P., AS AGENT
Reel/Frame 048591/0071 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2016
From: PRENGER, RYAN JAMES; BEAUCHESNE, NICOLAS; LYNN, KARL MATTHEW
To: VECTRA NETWORKS, INC.
Reel/Frame 040806/0229 →
Continuity (2)
Provisional Application 61951487 · Mar 11, 2014
Related Publication 20150264083A1 · Sep 17, 2015