Invention Grant
- Patent Title: Bind shell attack detection
-
Application No.: US15950234Application Date: 2018-04-11
-
Publication No.: US10999304B2Publication Date: 2021-05-04
- Inventor: Yinnon Meshi , Idan Amit , Eyal Firstenberg , Jonathan Allon , Yaron Neuman
- Applicant: Palo Alto Networks (Israel Analytics) Ltd.
- Applicant Address: IL Tel Aviv
- Assignee: Palo Alto Networks (Israel Analytics) Ltd.
- Current Assignee: Palo Alto Networks (Israel Analytics) Ltd.
- Current Assignee Address: IL Tel Aviv
- Agency: Kligler & Associates Patent Attorneys Ltd
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Methods, apparatus and computer program products implement embodiments of the present invention that include collecting data packets transmitted between multiple entities over a network, and grouping the packets at least according to their source and destination entities and their times, into connections to which the packets belong. Pairs of the connections are identified having identical source and destination entities and times that are together within a specified time window, and sets of features are generated for the identified pairs of the connections. The features in the pairs are evaluated in order to detect a given pair of connections indicating malicious activity, and an alert is generated for the malicious activity.
Public/Granted literature
- US20190319981A1 Bind Shell Attack Detection Public/Granted day:2019-10-17
Information query