Invention Grant
- Patent Title: Network security system that detects a common attacker who attacks from different source addresses
-
Application No.: US17336482Application Date: 2021-06-02
-
Publication No.: US11770394B2Publication Date: 2023-09-26
- Inventor: Harshvardhan Parmar , Vinod Vasudevan , Rajat Mohanty
- Applicant: Atos IT Solutions and Services, Inc
- Applicant Address: US DE New Castle
- Assignee: BULL SAS
- Current Assignee: BULL SAS
- Current Assignee Address: FR Les Clayes Sous Bois
- Agency: ARC IP LAW, PC
- Agent Joseph J. Mayo
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/40

Abstract:
A network security system that analyzes data from network attacks to determine which attacks came from the same attacker, even if the attacker tries to disguise its identity by spreading attacks out over time and attacking from multiple IP addresses. Intrusion detection systems or firewalls may log data for each attack, such as the time of the attack, the type of attack, and the source and target addresses. Embodiments may augment this data with derived attributes that may profile the attacker's behavior. For example, some attackers may spread out attacks over time, but always attack on the same day of the week; some attackers may spread out attacks over different IP addresses, but these addresses may all be in the same country. The original and augmented data may be clustered using an algorithm such as DBSCAN, and each attacker may be identified with one of the resulting clusters.
Public/Granted literature
- US20220394048A1 NETWORK SECURITY SYSTEM THAT DETECTS A COMMON ATTACKER WHO ATTACKS FROM DIFFERENT SOURCE ADDRESSES Public/Granted day:2022-12-08
Information query