Log in
Enquire now
‌

US Patent 11770397 Malicious port scan detection using source profiles

OverviewStructured DataIssuesContributors

Contents

Is a
Patent
Patent

Patent attributes

Patent Jurisdiction
United States Patent and Trademark Office
United States Patent and Trademark Office
Patent Number
11770397
Patent Inventor Names
Yinnon Meshi
Aviad Meyer
Idan Amit
Jonathan Allon
Date of Patent
September 26, 2023
Patent Application Number
17464716
Date Filed
September 2, 2021
Patent Citations
‌
US Patent 7908655 Connectionless port scan detection on a network
‌
US Patent 8245298 Port scanning method and device, port scanning detection method and device, port scanning system, computer program and computer program product
‌
US Patent 8397284 Detection of distributed denial of service attacks in autonomous system domains
‌
US Patent 8516573 Method and apparatus for port scan detection in a network
‌
US Patent 8578345 Malware detection efficacy by identifying installation and uninstallation scenarios
‌
US Patent 9118582 Network traffic management using port number redirection
‌
US Patent 9319421 Real-time detection and classification of anomalous events in streaming data
‌
US Patent 9531736 Detecting malicious HTTP redirections using user browsing activity trees
...
Patent Primary Examiner
‌
Badri Narayanan Champakesan
CPC Code
‌
H04L 63/1475
‌
H04L 63/1416
‌
H04L 63/1425
Patent abstract

A method, including identifying, in network traffic during multiple periods, scans, each scan including an access of multiple ports on a given destination node by a given source node, and computing, for each given source in the scans, an average of destinations whose ports were accessed by the given source during any scan by the given source, and a fraction of periods when the given source accessed at least one of the destinations in at least one scan performed by the given source node. A whitelist is assembled sources for which one or more of the following conditions applies: the average of destinations accessed in the scans was greater than a first threshold, and the fraction of periods during which at least one destination was accessed in at least one scan was greater than a second threshold. Upon detecting a scan by any non-whitelisted node, a preventive action is initiated.

Timeline

No Timeline data yet.

Further Resources

Title
Author
Link
Type
Date
No Further Resources data yet.

References

Find more entities like US Patent 11770397 Malicious port scan detection using source profiles

Use the Golden Query Tool to find similar entities by any field in the Knowledge Graph, including industry, location, and more.
Open Query Tool
Access by API
Golden Query Tool
Golden logo

Company

  • Home
  • Press & Media
  • Blog
  • Careers
  • WE'RE HIRING

Products

  • Knowledge Graph
  • Query Tool
  • Data Requests
  • Knowledge Storage
  • API
  • Pricing
  • Enterprise
  • ChatGPT Plugin

Legal

  • Terms of Service
  • Enterprise Terms of Service
  • Privacy Policy

Help

  • Help center
  • API Documentation
  • Contact Us
By using this site, you agree to our Terms of Service.