Invention Publication
- Patent Title: SECURITY ENGINE AUDIT RULES TO PREVENT INCORRECT NETWORK ADDRESS BLOCKING
-
Application No.: US17553615Application Date: 2021-12-16
-
Publication No.: US20230199022A1Publication Date: 2023-06-22
- Inventor: George Chen Kaidi
- Applicant: PAYPAL, INC.
- Applicant Address: US CA San Jose
- Assignee: PAYPAL, INC.
- Current Assignee: PAYPAL, INC.
- Current Assignee Address: US CA San Jose
- Main IPC: H04L9/40
- IPC: H04L9/40

Abstract:
Systems and methods for security engine audit rules to prevent incorrect network address blocking are disclosed. An entity such as a service provider may determine network traffic logs caused or generated by malicious web traffic and network communications, such as during a computing attack by a bad actor. The service provider may implement automated blocking controllers, which use detection rules to detect the malicious network traffic, and thereafter generate a network address blocklist that is distributed to devices, components, and servers of the service provider for network address blocking. To ensure the integrity of the detection rules, audit rules and a dynamic exclusion macro may be executed to detect when a detection rule is behaving abnormally and/or leading to anomalous results. If a detection rule is not properly blocking network addresses, the rule may be removed from execution until recovery.
Public/Granted literature
- US12177247B2 Security engine audit rules to prevent incorrect network address blocking Public/Granted day:2024-12-24
Information query