Invention Grant
- Patent Title: Malicious port scan detection using source profiles
-
Application No.: US17464716Application Date: 2021-09-02
-
Publication No.: US11770397B2Publication Date: 2023-09-26
- Inventor: Yinnon Meshi , Idan Amit , Jonathan Allon , Aviad Meyer
- Applicant: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
- Applicant Address: IL Tel Aviv
- Assignee: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
- Current Assignee: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
- Current Assignee Address: IL Tel Aviv
- Agency: KLIGLER & ASSOCIATES PATENT ATTORNEYS LTD
- Main IPC: H04L9/40
- IPC: H04L9/40

Abstract:
A method, including identifying, in network traffic during multiple periods, scans, each scan including an access of multiple ports on a given destination node by a given source node, and computing, for each given source in the scans, an average of destinations whose ports were accessed by the given source during any scan by the given source, and a fraction of periods when the given source accessed at least one of the destinations in at least one scan performed by the given source node. A whitelist is assembled sources for which one or more of the following conditions applies: the average of destinations accessed in the scans was greater than a first threshold, and the fraction of periods during which at least one destination was accessed in at least one scan was greater than a second threshold. Upon detecting a scan by any non-whitelisted node, a preventive action is initiated.
Public/Granted literature
- US20210400073A1 Malicious port scan detection using source profiles Public/Granted day:2021-12-23
Information query