Invention Grant
- Patent Title: Detecting computer security threats using communication characteristics of communication protocols
-
Application No.: US16086142Application Date: 2017-03-03
-
Publication No.: US11194901B2Publication Date: 2021-12-07
- Inventor: Fadi El-Moussa , Ian Herwono
- Applicant: British Telecommunications Public Limited Company
- Applicant Address: GB London
- Assignee: British Telecommunications Public Limited Company
- Current Assignee: British Telecommunications Public Limited Company
- Current Assignee Address: GB London
- Agency: Patterson, Thuente Pedersen, P.A.
- Priority: EP16162937 20160330
- International Application: PCT/EP2017/055081 WO 20170303
- International Announcement: WO2017/167544 WO 20171005
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06F21/56 ; H04L12/24 ; H04L29/06

Abstract:
Systems and methods for identifying a computer security threat based on communication via a computer network. A method includes receiving a definition of acceptable network communication characteristics for communication protocols; receiving a set of security events for the communication, each security event including network communication characteristics for the communication; for each security event: a) identifying a communication protocol associated with the event; b) detecting deviations of network communication characteristics of the event from the acceptable network communication characteristics for the identified communication protocol; and c) generating a record of each deviation identifying a communication characteristic for which the deviation is detected, so as to generate a set of one or more records of deviation for the set of security events; and storing the set of records of deviation as a security threat identifier for identifying subsequent security threats by comparing with the set of records.
Public/Granted literature
- US20200302052A1 DETECTING COMPUTER SECURITY THREATS Public/Granted day:2020-09-24
Information query