Invention Grant
- Patent Title: Scanner probe detection
-
Application No.: US16261655Application Date: 2019-01-30
-
Publication No.: US11184378B2Publication Date: 2021-11-23
- Inventor: Yinnon Meshi , Idan Amit , Jonathan Allon , Aviad Meyer
- Applicant: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
- Applicant Address: IL Tel Aviv
- Assignee: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
- Current Assignee: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
- Current Assignee Address: IL Tel Aviv
- Agency: Kligler & Associates Patent Attorneys Ltd
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A method, including identifying, in network data traffic, multiple scans, each of the scans including an access, in the traffic, of multiple ports on a given destination node by a given source node during a time period. A group of high-traffic ports are identified in the traffic that include one or more ports that receive respective volumes of the traffic that exceed a threshold, and respective signatures are generated for the identified port scans that indicate the ports other than the high-traffic ports that were accessed in each of the port scans. A respective frequency of occurrence of each of the signatures over the set of the port scans is computed, and a whitelist of the signatures for which the respective frequency of occurrence is greater than a threshold is assembled. Upon detecting a port scan for which the respective signature is not whitelisted, a preventive action is initiated.
Public/Granted literature
- US20200244685A1 Scanner probe detection Public/Granted day:2020-07-30
Information query