Invention Grant
- Patent Title: Protecting against and learning attack vectors on web artifacts
-
Application No.: US16171074Application Date: 2018-10-25
-
Publication No.: US10944770B2Publication Date: 2021-03-09
- Inventor: Mainak Roy , Chitrak Gupta
- Applicant: EMC IP Holding Company LLC
- Applicant Address: US MA Hopkinton
- Assignee: EMC IP Holding Company LLC
- Current Assignee: EMC IP Holding Company LLC
- Current Assignee Address: US MA Hopkinton
- Agency: Staniford Tomita LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/55 ; G06N20/00 ; G06F16/2455

Abstract:
A server includes a service processor hosted by a baseboard management controller (BMC) and independent of a CPU of the server. The server hosts web files. The service processor performs a set of monitoring tasks including receiving packets forming access requests made to the web files. A learning block is updated with information about suspicious packets. A counter is updated indicating a number of times a packet with a signature of a suspicious packet was received. When the counter reaches a threshold, a suspicious packet is analyzed in conjunction with other previously received suspicious packets. The analysis includes rearranging an arrival order of the suspicious packets into a new arrival sequence. The new arrival sequence of suspicious packets is matched to attack patterns in an attack pattern database. When the new arrival sequence matches an attack pattern, source IP addresses associated with the suspicious packets are added to a blacklist.
Information query