IP Library Granted Patent US 11,516,181
Granted Patent B2
US 11,516,181 · App. 16/914,210 · Granted Nov 29, 2022

Device, system and method for defending a computer network

Inventor: Christopher J. Jordan (Great Falls, VA)
Assignee: McAfee, LLC
H04L63/0245H04L63/0227H04L63/1416H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,516,181
App. No.
16/914,210
Granted
Nov 29, 2022
Kind
B2
Abstract

A non-transitory, processor-readable medium includes code representing instructions to cause a processor to perform a method. The method includes receiving, from a traffic filter at a boundary of a network, a network communication and determining the network communication is a first anomalous communication associated with a service that does not exist within the network, uses a non-readable character set, or includes a malicious payload. The method further includes, at least partially based on the determining, generating a first rule, at least partially based on an analysis of a subset of partial or exact fingerprints of the first anomalous communication. The first rule is communicated to the traffic filter for the traffic filter to filter, from network communications external to the network, a second anomalous communication.

Claims (40)

1. A non-transitory, processor-readable medium comprising code representing instructions to cause a processor to perform a method comprising:

receiving, from a traffic filter at a boundary of a network, a network communication;

determining which the network communication is, from among being a first anomalous communication associated with a service that does not exist within the network, using a non-readable character set, or including a malicious payload;

defining a fingerprint, based on an order of a plurality of tokens of a network protocol included in the first anomalous communication;

at least partially based on the determining, generating a first rule, at least partially based on an analysis of the fingerprint; and

communicating, to the traffic filter, the first rule for the traffic filter for filtering, from network communications external to the network, a second anomalous communication.

2. The non-transitory, processor-readable medium of claim 1 , the method further comprising:

comparing a normal communication with the first anomalous communication to determine an impact of the first rule.

3. The non-transitory, processor-readable medium of claim 1 , wherein the determining determines that the first anomalous communication includes the malicious payload, the method further comprising generating a second rule based on an anomaly associated with the malicious payload.

4. The non-transitory, processor-readable medium of claim 1 , the method further comprising:

determining an impact of the first rule on the network; and

updating the first rule to reduce the impact.

5. The non-transitory, processor-readable medium of claim 1 , the method further comprising:

routing the first anomalous communication to a predetermined component within the network, responsive to a determination that the first anomalous communication is associated with the service that does not exist within the network.

6. The non-transitory, processor-readable medium of claim 1 , the method further comprising:

making statistical categorization of the first anomalous communication at least partially based on chunks, the chunks being patterns in exact fingerprints of a previous communication.

7. The non-transitory, processor-readable medium of claim 1 , the method further comprising:

generating at least one of the tokens, using a sliding window for a length in bits.

8. A method, comprising:

receiving, from a traffic filter at a boundary of a network, a network communication;

determining which the network communication is, from among being a first anomalous communication associated with a service that does not exist within the network, using a non-readable character set, or including a malicious payload;

defining a fingerprint, based on an order of a plurality of tokens of a network protocol included in the first anomalous communication;

at least partially based on the determining, generating a first rule, at least partially based on an analysis of the fingerprint; and

communicating, to the traffic filter, the first rule for the traffic filter for filtering, from network communications external to the network, a second anomalous communication.

9. The method of claim 8 , further comprising:

comparing a normal communication with the first anomalous communication to determine an impact of the first rule.

10. The method of claim 8 , wherein the determining determines that the first anomalous communication includes the malicious payload, the method further comprising generating a second rule based on an anomaly associated with the malicious payload.

11. The method of claim 8 , further comprising:

determining an impact of the first rule on the network; and

updating the first rule to reduce the impact.

12. The method of claim 8 , further comprising:

routing the first anomalous communication to a predetermined component within the network, responsive to a determination that the first anomalous communication is associated with the service that does not exist within the network.

13. An apparatus, comprising:

a receiver that receives, from a traffic filter at a boundary of a network, a network communication; and

a processor configured to perform a determination as to which the network communication is, from among being a first anomalous communication associated with a service that does not exist within the network, using a non-readable character set, or including a malicious payload,

the processor further configured to define a fingerprint, based on an order of a plurality of tokens of a network protocol included in the first anomalous communication, and to, at least partially based on the determination, generate a first rule, at least partially based on an analysis of the fingerprint, wherein the receiver communicates, to the traffic filter, the first rule for the traffic filter for filtering, from network communications external to the network, a second anomalous communication.

14. The apparatus of claim 13 , wherein the processor further is configured to compare a normal communication with the first anomalous communication to determine an impact of the first rule.

15. The apparatus of claim 13 , wherein the processor further is configured to determine that the first anomalous communication includes the malicious payload, and to generate a second rule based on an anomaly associated with the malicious payload.

16. The apparatus of claim 13 , wherein the processor further is configured to determine an impact of the first rule on the network and to update the first rule to reduce the impact.

17. The apparatus of claim 13 , wherein the first anomalous communication is routed to a predetermined component within the network, responsive to a determination that the first anomalous communication is associated with the service that does not exist within the network.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
Continuity (5)
Continuation 15791144 · Oct 23, 2017
Continuation 14486740 · Sep 15, 2014
Continuation 10990329 · Nov 17, 2004
Provisional Application 60520577 · Nov 17, 2003
Related Publication 20200336461A1 · Oct 22, 2020