Patent · US Active

Detecting outlier pairs of scanned ports

US11070569B2 · kind B2 · utility

0Cited by
37References
13Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJan 30, 2019
Grant dateJul 20, 2021
Priority date
Expiry dateDec 27, 2039

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/0254
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A method, including identifying, in network data traffic, multiple scans, each of the scans including an access, in the traffic, of a plurality of ports on a given destination node by a given source node during a predefined period. Respective first probabilities of being accessed during any given scan computed for the communication ports that were accessed in the identified scans, and a respective second probability that both of the ports in the pair were accessed during any given scan are computed for each pair of the ports in the identified scans. Upon detecting a scan by one of the nodes including accesses of first and second ports on a given destination node for which the respective second probability for the pair of the first and second ports is lower than a threshold dependent upon the respective first probabilities of the first and second ports, a preventive action is initiated.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.