Invention Grant
- Patent Title: Network attack detection
-
Application No.: US15339558Application Date: 2016-10-31
-
Publication No.: US10581915B2Publication Date: 2020-03-03
- Inventor: Mathias Scherman , Daniel Mark Edwards , Tomer Koren , Royi Ronen
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Enhancements to network security are provided by identifying malicious actions taken against servers in a network environment, without having to access log data from individual servers. Seed data are collected by an administrator of the network environment, from honeypots and servers whose logs are shared with the administrator, to identify patterns of malicious actions to access the network environment. These patterns of use include ratios of TCP flags in communication sessions, entropy in the use of TCP flags over the life of a communication session, and packet size metrics, which are used to develop a model of characteristic communications for an attack. These attack models are shared with servers in the network environment to detect attacks without having to examine the traffic logs of those servers.
Public/Granted literature
- US20180124073A1 NETWORK ATTACK DETECTION Public/Granted day:2018-05-03
Information query