The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 04, 2022

Filed:

May. 27, 2021
Applicant:

Micro Focus Llc, Santa Clara, CA (US);

Inventors:

Martin Arlitt, Calgary, CA;

Mijung Kim, Santa Clara, CA (US);

Manish Marwah, Santa Clara, CA (US);

Assignee:

MICRO FOCUS LLC, Santa Clara, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 15/173 (2006.01); H04L 43/028 (2022.01); H04L 43/0817 (2022.01); H04L 43/067 (2022.01); H04L 43/106 (2022.01);
U.S. Cl.
CPC ...
H04L 43/028 (2013.01); H04L 43/067 (2013.01); H04L 43/0817 (2013.01); H04L 43/106 (2013.01);
Abstract

Network communication events are filtered to remove the network communication events having a predicted unrelatedness to beaconing. Each network communication event has a timestamp, a source entity, and a destination entity. The filtered network communication events are aggregated by unique source entity-destination entity pairs. For each unique source entity-destination entity pair, the network communication events are timestamp-sorted, time differentials between the timestamps of adjacent network communication events are calculated, and a beacon likelihood metric is calculated from the calculated time differentials. Which of the unique source entity-destination entity pairs are indicative of beaconing are identified based on the beacon likelihood metric calculated for each unique source entity-destination entity pair.


Find Patent Forward Citations

Loading…