Invention Grant
- Patent Title: Distributed detection of malicious cloud actors
-
Application No.: US15500033Application Date: 2014-08-28
-
Publication No.: US10951637B2Publication Date: 2021-03-16
- Inventor: Robert Graham Clark
- Applicant: Suse LLC
- Applicant Address: US DE Wilmington
- Assignee: Suse LLC
- Current Assignee: Suse LLC
- Current Assignee Address: US DE Wilmington
- Agency: Schwegman Lundberg & Woessner. P.A.
- International Application: PCT/US2014/053199 WO 20140828
- International Announcement: WO2016/032491 WO 20160303
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/08 ; H04L12/24 ; H04L12/26

Abstract:
Examples relate to distributed detection of malicious cloud actors. In some examples, outgoing cloud packets from the cloud server are intercepted and processed to determine if a preliminary threshold is exceeded, where the outgoing cloud packets are used to identify a customer. At this stage, a potential outgoing intrusion event of a number of potential outgoing intrusion events is generated when the preliminary threshold is exceeded. The potential outgoing intrusions events are used to update an aggregate log, where the aggregate log tracks a customer subset of the cloud servers that is associated with the customer. In response to analyzing the aggregate log to determine that cloud traffic by the customer to the destination address exceeds an intrusion threshold, a notification of malicious activity by the customer is provided, wherein the intrusion threshold is satisfied at a higher cloud activity level than the preliminary threshold.
Public/Granted literature
- US20170244738A1 DISTRIBUTED DETECTION OF MALICIOUS CLOUD ACTORS Public/Granted day:2017-08-24
Information query