The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Feb. 25, 2020

Filed:

Sep. 04, 2017
Applicant:

Palo Alto Networks (Israel Analytics) Ltd, Tel Aviv, IL;

Inventors:

Yinnon Meshi, Kibbutz Revivim, IL;

Jonathan Allon, Haifa, IL;

Eyal Firstenberg, Ramat HaSharon, IL;

Yaron Neuman, Zoran, IL;

Dekel Paz, Ramat Gan, IL;

Idan Amit, Ramat Gan, IL;

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06N 20/00 (2019.01); H04L 29/06 (2006.01); G06F 21/55 (2013.01); G06N 7/00 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06N 20/00 (2019.01); G06F 21/552 (2013.01); G06N 7/005 (2013.01); H04L 63/14 (2013.01); H04L 63/145 (2013.01); H04L 63/1441 (2013.01);
Abstract

A method, including collecting information on data transmitted at respective times between multiple endpoints and multiple Internet sites having respective domains, and acquiring, from one or more external or internal sources, maliciousness information for the domains. An access time profile is generated based on the times of the transmissions to the domains, and a popularity profile is generated based on the transmissions to the domains. A malicious domain profile is generated based on the acquired maliciousness information, and the collected information is modeled using the access time profile, the popularity profile and the malicious domain profile. Based on their respective modeled collected information, one or more of the domains is predicted to be suspicious, and an alert is generated for the one or more identified domains.


Find Patent Forward Citations

Loading…