System and method for conditional analysis of network traffic
38 claims: 8 independent, 30 dependent
- 1CLAIMS 1. A method, comprising:receiving a plurality of packets of network traffic that carries content items directed to a plurality of different end users, for processing by an analytics system;extracting a content item from the plurality of packets of the network traffic;deriving a content identifier for the content item extracted from the plurality of packets;finding whether the content identifier appears in a cache memory of previous content that was already processed by the analytics system;when the content identifier is found in the cache memory, retrieving and outputting a cached analytics outcome of the content item;and when the content identifier is not found in the cache memory, causing the analytics system to analyze the content item to produce an analytics outcome for the content item, and caching the analytics outcome.
- 10The method according to any one of claims 1-9, wherein the content identifier comprises a first signature and a second signature, which is stronger than the first signature, and wherein finding whether the content identifier appears in the cache memory comprises checking the second signature only if checking the first signature is not sufficient for deciding that the content identifier does appear in the cache memory. 229,154/2
- 11The method according to any one of claims 1-10, and comprising, for a given content item, counting a number of matching occurrences of the given content item, and caching the number of matching occurrences in the cache memory in association with the content identifier of the given content item, for use by the analytics system.
- 20An apparatus, comprising:an input circuit, which is configured to receive network traffic that carries content items directed to a plurality of different end users, for processing by an analytics system;and at least one processor, which is configured to extract a content item from a plurality of packets of the network traffic, to derive a content identifier for the content item extracted from the plurality of packets, to find whether the content identifier appears in a cache memory of previous content that was already processed by the analytics system, to retrieve and output a cached analytics outcome of the content item when the content identifier is found in the cache memory, and, when the content item is not found in the cache memory, to cause the analytics system to produce an analytics outcome for the content item and to cache the analytics outcome.
- 29The apparatus according to any one of claims 20-28, wherein the content identifier comprises a first signature and a second signature, which is stronger than the first signature, and wherein the processor is configured to validate that the content identifier does not match any identifier in the cache memory by checking the second signature only if the first signature is not sufficient for deciding that the content identifier does appear in the cache memory.
Independent claims8
218 paragraphs in 11 sections, as filed
SYSTEM AND METHOD FOR CONDITIONAL ANALYSIS OF NETWORK TRAFFIC
FIELD OF THE DISCLOSURE
The present disclosure relates generally to network traffic processing, and particularly to methods and systems for conditional analysis of network traffic.
BACKGROUND systems that monitor and process network traffic, analytics systems, are required to cope with larqe of traffic. Often, increased traffic volumes are which is carried over the network consumed by end users traffic volumes result in hardware and computational
Some such as analytics systems, amounts of traffic. Often created by popular content, each time the content is delivered or of the increased network . demands
The increased on the systems patent a system, application method, and of a copy of application publication 2013/0247131 computer proqram product for a message . publication server . publication for machine resources .
U.S.
describes preventinq scanninq patent a threat detectinq proxy patent application a method and apparatus communications network.
publication 2012/02 device resource sharin'
U.S.
describes
U.S.
describes network security monitorinq in a application cachinq for
U.S. patent describes a social manaqement.
U.S.
describes patent a applications .
U.S. patent describes a mobile system and method optimization system.
U.S. patent 8,079,084 instructions and methods for application content associative application
2013/0127618 to machine publication 20 cachinq method publication network reporting aggregated using a describes using such.
2013/0159395 and usage analytics distributed traffic virus co-processor
THE DISCLOSURE described network
SUMMARY OF that is receivinq processinq by an extracted from the herein provides a traffic that carries analytics system. A network traffic. The
An method, content content content previous content that was system and cached. When duplicate the previous content, the content item is item is found not analytics system is for the content item, embodiment includinq items for item is item is examined to find whether it is a duplicate of already processed by the analytics the content item is found to a cached analytics outcome of retrieved and output. When the content to duplicate any previous content, the caused to produce the analytics outcome and the analytics outcome is cached.
In some embodiments, deriving a respective unique identifier tor the e unique identifier does not match any identifier in cache memory that identifiers of previous content processed by the analytic
<td> ::s system.</td><td> In</td><td> other</td><td> e mb o d i me n t s</td>
<td> response</td><td> to</td><td> findim</td><td> j that the</td>
<td> duplicate,</td><td> ca</td><td> ching</td><td> the unique</td>
<td> item, and</td><td> the</td><td> analyt</td><td> ics outcome</td>
<td> item by the</td><td> an</td><td> a 1 y 11 c s</td><td> system, in</td>
with the unique association the cache memory m identifier.
In yet other e mb o d i me n ts, part of a Uniform Resource Locator (URL) in which the con embodiment part of the UR is another embodiment, extracting extracting a traffic transaction created are infected by malware vi ng the traffic transaction. In yet another embodiment, unique digital over at least pa of the content item.
s o me e mb o d i me n t s the ng predefined portion of the content embodiments, the predefined portion is chosen to exclude item that varies among duplicates of the content item, in yet other embodiments the unique identifier includes a first signature and a
1095S4 second signature, which is stronger than the first signature, and validating that the unique identifier does not match any identifier in the cache memory includes checking the second signature only if checking the first signature is not sufficient for deciding- that the identifier does not match.
In an embodiment, the method further includes, for a given content item, counting a number of matching occurrences of the given content item, and caching the association with th the given n anothe embodiment, caching the number of matching includes deleting from the cache memory the given content identifier if the number of matching occurrences during a predefined duration is lower than a predefined threshold.
In yet another embodiment, the number of matching occurrences is multiplied by a weight factor that is based on a processing time of the content item.
In some embodiments, extracting the content item includes recognizing HTTP transactions in the network traffic and extracting the content item from the HTTP
<img file="IL229154A_D0001.tif" />
ions
In other embodiments, the content item includes a multimedia content.
In an embodiment, the analytics system produces analytics outcomes based on an analytics rule, and upon changing the analytics rule, updating cached analytics
<td> outcomes for</td><td colspan="2"> the content items</td><td> for which the</td><td colspan="2"> analytics</td>
<td> rule was app</td><td> lied. In</td><td> another «</td><td> embodiment, cha</td><td> nging</td><td> the</td>
<td> analytics rul</td><td> e includes</td><td> removing</td><td> the analytics</td><td> r u r e,</td><td> and</td>
<td> updating the</td><td> analytics</td><td> outcome;</td><td> s includes del</td><td> e t i ng</td><td> the</td>
<td> cached confer</td><td> it items f</td><td> or which</td><td> the analytics</td><td> rule</td><td> W 8. S</td>
1095S4 applied. In yet another embodiment, changing the analytics rule includes changing the analytics rule with respect to a given content type, and updating the analytics outcomes includes removing the cached content items of the given content type.
Tn some embodiments, changing the analytics rule
<td> includes</td><td> replacing the</td><td> analytics</td><td> rule</td><td> with a</td><td> new</td>
<td> analytics</td><td> rule, which is</td><td> different</td><td> from</td><td> the analyt</td><td> . i c s</td>
<td> rule, and</td><td> updating the</td><td> analytics</td><td colspan="2"> o u t c o me s i n c 1 u</td><td> . oe s</td>
<td> producing</td><td> new analytics</td><td> outcomes by</td><td> app</td><td> lyincf the</td><td> new</td>
<td> analytics</td><td> rule to the co</td><td> ntent items</td><td> and</td><td> replacing</td><td> the</td>
cached analytics outcomes with the new analytics outcomes .
There is also provided, in accordance with an embodiment that is described herein, an apparatus including an input circuit and a processor. The input circuit is configured to receive network traffic that carries content items for processing by an analytics system. The processor is configured to extract a content item from the network traffic, to find whether the content item is a duplicate of a previous content that was already processed by the analytics system and cached, to retrieve and output a cached analytics outcome of the content item when the content item is found to duplicate the previous content, and, when the content item is found not to duplicate any previous content, to cause the analytics system to produce the analytics outcome for the content item and to cache the analytics outcome.
The present disclosure will be more fully understood from the following detailed description of the embodiments thereof, taken together with the drawings in which:
1095S4
BRIEF DESCRIPTION OF THE DRAWINGS
Fig. 1 is a block diagram that schematically illustrates an analytics system, in accordance with an embodiment that is described herein; and
Fig. 2 is a flow chart that schematically illustrates a method for conditional analysis of network traffic, in accordance with an embodiment that is described herein .
DETAILED DESCRIPTION OF EMBODIMENTS
<img file="IL229154A_D0002.tif" />
Network nodes and users communicate, for example, by sending, consuming, and/or sharing various types of content. Examples of content types include web pages, electronic mails (e-mails), documents, and multimedia. In addition, some of he communication traffic may viruses. Analytics systems often receive large
To handle received traff orage many delivered network more traf f multiple times
For access content other example, an organization may deliver
a. message or a document, via e-mail, to a oarge group o recipients. The duplicate occurrences of content in the system.
In some cases, multiple copies of a given content item are stored in different physical or logical
1095S4
ΤΊ the same content (i.e., copies thereof) using different
For example, popular content may jj cont multiple servers, and delivered to are provide improved traffic embodiment perform only nevi, first occurrences of received content, while typical embodiment, the analytics resul s regarding th reported and cached in the content, th are retrieved from
T h e s e e mb o d i me n t s bus significantly reduce the and storage resources, or increase the
C12.
instances
O 1' content received emb o d i me n t. s de s c r i b e d c o mmun i c a t i ο n in items transactions) embodiments, he system (e.g., and assigns respective out unique content
1095S4 identifiers to the content items. In an embodiment, different content items are mapped to different identifiers, whereas the duplicates of each content item are mapped to identical identifiers. A unique identifier may comprise, for example, the content itself (or part thereof). As another example, the identifier may comprise a compact representation of the content such as a digital signature calculated over the content item (or part thereof). A digital signature may comprise, for example, checksum, Cyclic Redundancy Check (CRC), or a hash message-digest such as, for example, MD5.
In some embodiments, the calculation of content identifiers excludes a predefined part of the content item, e.g., time stamps or other variable information that may be embedded within the content. In some embodiments, the content identifiers of duplicate copies of given content may differ up to some limited extent so that the given content item is still distinguishable from, all other content items. For example, when generating identifiers for web pages, parts of vary from one occurrence to (e.g., t i me s amps) are marked
When a
svstern.
<td> f o r</td><td> the first time,</td><td> the respective</td><td> COI'it</td>
<td> tier</td><td> is stored in a cache</td><td> memory. The size</td><td> 0 f</td>
<td> tier</td><td> may affect the perf</td><td> Ormance accuracy</td><td> -f'_/ -L.</td>
<td> In</td><td> some e mb o d i me n t s,</td><td> to achieve the</td><td> high</td>
the the +ent serves as an identifier and is cached.
analytics system.
re subsequent given content in the input con match the identifier that cache. Typically, however, only
ΟίΟ any the the s ame content ρ r e v i o u s 1 y c a c h e d i d e n t i f i e r s are assumed to be received to time and are sufiect to
Since performing content item is much more complex than sear chi.
ng matching bi handle conte n some embodiments, the analytics system employs multi-step search methods that enable fast termination of the search procedure by recognizing nonmatching items in early steps of the search, thus reducing the search computational cost considerably. On the other hand, as earlier steps indicate possible matching, stronger and more accurate search method, with higher computational requirements, are applied.
The disclosed techniques are applicable to a variety of network analytics applications. In some embodiments, the analytics system is configured to detect in the input data occurrences of predefined search items and take suitable measures upon detection. In the context of the present patent application, the term search items may also refer to searching or analytics rules. Examples of search items include keywords and string patterns, multimedia items such as image, video, or audio, and
Q
1095S4
URLs. In such embodiments, the predefined search items are typically stored in a dedicated storage. In an embodiment, when a content item is received for the first time and sent for analytics processing as described above, an analytic operation is applied to the content or to packets in the input data that are related to that content to find an occurrence of one or more search items. The results of analytics processing are reported, and are also cached in association with the identifier of the content item. The cached results are reported again for each duplicate occurrence of the content item, so that reporting cached instead of re-processed results is transparent to the system operator.
In some embodiments, a software virus or some other malware creates certain traffic patterns such as patterns of HTTP transactions in the network traffic. For example, malware-infected servers in the network may generate large amounts of spam traffic over short time periods. When a suspicious traffic pattern (e.g., related to spam traffic) is identified for the first time, the suspicious
<td> traffic pattern</td><td> is stored</td><td> in a cache</td><td> memory and</td><td> .1. s</td>
<td colspan="3"> subject to further analytics processing to</td><td> detect whet</td><td> her</td>
<td> the pattern was</td><td> created by</td><td> malware. The</td><td> results of</td><td> the</td>
<td> analytics proces</td><td colspan="2"> sing is cached in associ</td><td> ation with</td><td> the</td>
<td> traffic pattern.</td><td> Duplicate</td><td> o c c u r r e n c e s o f</td><td> the suspici</td><td> ous</td>
<td> pattern are mate</td><td> hed to the</td><td> previously sto:</td><td> red pattern</td><td> and</td>
<td> their analytics</td><td> processing</td><td> outcomes are</td><td> retrieved f</td><td> rom</td>
<td> t n e c a c h e w i t η o</td><td colspan="2"> ut analytics processing.</td><td> The disclo</td><td> sed</td>
<td> techniques thus</td><td> free up</td><td> computational</td><td> resources</td><td> for</td>
malware processing and detection.
The disclosed techniques enable to filter out content that was previously received and processed by the
1095S4 analytics system. By processing each content item only once, reporting respective cached analytics results, and refraining from superfluous processing of duplicate content, computational and hardware resources are reduced without sacrificing the analytics performance of the system.
SYSTEM DESCRIPTION
Fig. 1 is a block diagram that schematically illustrates an analytics system 20, in accordance with an embodiment that is described herein. System 20 receives communication traffic from a communication network 24, and attempts to detect in the traffic predefined data elements such as textual phrases or multimedia contents. In the context of the present patent application, the predefined data elements to be searched are also referred to as keywords or search items. When one or more search items are detected, the system reports the detection to a user 28 using an operator terminal 32.
System 2 0 can be used, for example, in an intrusion detection system (IDS) application.
the system searches for occurrences patterns. The patterns may include, in IDS applications, of certain signature for example, Regular
<img file="IL229154A_D0003.tif" />
® (Regex) rules as used, for example, in Snort , which is an open source network intrusion prevention and detection svstern.
<td> Alt</td><td> ernatively, system</td><td> 2 0</td><td> can be used</td><td> in any o</td><td> ther</td>
<td> suitable</td><td> application in whj</td><td> i.ch</td><td> input data is</td><td> searched</td><td> for</td>
<td> occurren</td><td> c e s o f k e y w o r d s</td><td> (e</td><td> .g., textual</td><td> keywords</td><td> or</td>
certain character strings), detection of spam e.g., in electronic mail (e-mail) systems, or detection of inappropriate content using a dictionary of inappropriate
1095S4 words or phrases. Additionally or alternatively, system may be used for detecting occurrences of predefined multimedia content in the input data.
System 2 0 can also be used in data. leakage prevention (DLP) applications, which detect data leakage from a communication network. In applications of this sort, the presence of one or more search items in a data item indicates that this data item should not be allowed to exit the network. Further additionally or alternatively, system 20 can be used for detectincf communication sessions (e.g., spam) created by viruses or other malware .
Although the embodiments described herein refer mainly to processing of communication traffic, the other domains
For example, system interes on devices, as ι n comprise mate comprise any suitable public private, wireless or wire-line communication network,
e.g., a Wide-Area network (WAN) such as the Internet, a
Local-Area Network (LAN), a Metropolitan-Area Network (MAN), or a combination of network types. The communication traffic, to be used as input data by system 20, may be provided to the system, using- any suitable means. For example, the traffic may be forwarded to the system from a network element (e.g., router) in network 24, such as by port tapping or port, mirroring. In alternative embodiments, system 20 may be placed in-line in the traffic path. These embodiments are suitable, for example, for applications such as intrusion detection and prevention, data leakage prevention, antivirus or spam detection, or monitoring of inappropriate content.
Typically, although not necessarily, network 24 comprises an Internet Protocol (IP) network, and the communication traffic comprises IP packets. The description that follows focuses on web traffic, which is communicated using the Hyper Text Transfer Protocol (HTTP). In addition, in the description below, we also assume that network transmission is carried out using the Transmission Control Protocol Internet Protocol (TCP/IP) and TCP packets. Alternatively, however, the methods and systems described herein can be used with any other suitable networks and protocols, packet types, and content types. For example, other packet types may include User Datagram Protocol (UDP) packets. As another example, various data types may include Flash or video streams, images, audio, e-mail, and the like. Regardless of protocol, the packets (or possibly a higher level of abstraction of the data traffic via a suitable protocol) searched by system 20 are referred to herein generally as input data or network traffic.
In the example of Fig. 1, system 20 comprises a
<td> Network</td><td> Interface Card</td><td> (NIC)</td><td> fa f</td><td> which receives</td><td> TCP</td>
<td> packets</td><td> from networK 24.</td><td> NIC 3 6</td><td> thus</td><td> ; serves as an</td><td> input</td>
<td> circuit</td><td> that receives the</td><td> input</td><td> G ci 13</td><td> t o b e sea r c he d</td><td> . NIC</td>
stores the incoming TCP packets in a memory 40, typically comprising a Random Access Memory (RAM). A front end processor 44 extracts from the stored TCP packets (typically from the packets payload) certain content items and produces a respective content
1095S4 identifier per each content item. Examples of various content identifiers are described further below.
In some embodiments, the extracted content items may comprise structured data such as HTML web pages, URLs, multimedia items such as Flash streams, images, video clips, or audio, or some digital representation thereof. In alternative embodiments, a content item comprises the payload of one or more TCP packets.
In the description that follows the term firstoccurring content refers to the first occurrence of a given content item, and duplicate content items refer to one or more subsequent duplicate occurrences of the given content item in the input data (assuming the given item is already cached) . Note that the term first-occurring refers to any non-cached content, such as, for example, content that was deleted from the cache while eliminating old content, or because of cache size limitations. Front end processor 44 selectively stores content identifiers of the extracted content items in a cache memory 46 and uses the cached identifiers to filter out duplicate content items as described below. In some embodiments, front end processor 44 indicates to an analytics processor 50 only of first-occurring content items detected in the input data.
As described above, when a. certain content item is
<td> firstly received by</td><td> system 20, analytics</td><td> processor</td><td> 5 0</td>
<td> accepts from front</td><td> end processor 44</td><td> a respect</td><td> ive</td>
<td> indication. Analytics</td><td> processor 50 then</td><td> searches</td><td> the</td>
<td> input data stored in</td><td> memo r y 4 0 (e.g., T CI</td><td> ’ packets f</td><td> rom</td>
<td> which the content it<</td><td> sm was extracted) an</td><td> d attempts</td><td> t o</td>
<td> i de n t i f y o c c u r r e n c e s</td><td> of predefined search</td><td> items in</td><td> the</td>
<td> input data. As descri</td><td> .bed above, front eno</td><td> ί processor</td><td> 44</td>
1095S4 s t r i n g p a 1.1 e r n s) at or communicatio
TCP , HTML pages, orstreams .
(e.g., κθ v w o .ii ds
The device items, se
<td> :arch</td><td> items may</td><td> be</td>
<td> In</td><td> some embod</td><td> ime</td>
<td> ma y</td><td> be stored</td><td> in</td>
s, all or part ot the searc of speed keywords.
When rn example, processor, m some which searches orage 52 may comprise stinct dictionaries.
(or multiple he detection to user an
Fo may is sue an alert to the user session) embodiments, analytics processor kinds of actions in response to a search item.
For example, in a data leakage or intrusion prevention application, analytics processor 50 may generate an indication to block some or all of the traffic upon detecting a search item. User 28 may interact with system using an input device of terminal 32, e.g., a keyboard Ci u »
The system configuration shown in Fig. 1 is an example configuration, which is chosen purely for the sake of conceptual clarity. Alternatively, any other suitable system configuration can be used
For example
1095S4 in some embodiments system 20 comprises a single processor, which handles all the tasks that are typically carried out separately by front end processo
4 /and processor as described above. Generally, the different elements .i m p 1 e me n t e d u s i n g or hardware and state memory or magnetic storage devices
In some embodiments, analytic end processor 44, or both comprise general-purpose processors, which are programmed in software to carry out the functions described herein. The software may be downloaded to the processors in optical or electronic form, over a network, for example, or it may, additionally or alternatively, be provided and/or stored on non-transitory tangible media, such as magnetic, optical, or electronic memory.
CONTENT IDENTIFIERS
System
0 may various types
Cl types or nici y όθ s o me e mb o d i me n t s,
Resource locators
For example the content items comprise Uniform (URLs). A URL typically comprises a character string that identifies a certain resource or content in the network. In principle, the URL string itself can serve as the content identifier of the URL. In such embodiments, system 20 would process only the first content received from a given URL, and report (without re-processing) the same analytics results as reported and
1095S4 cached on the first occurrence, for subsequent content from the same URL.
In some cases, however, different instances of a URL of a given resource may comprise different character strings. For example, parts of the URL may comprise a time stamp or some other variable information. In some embodiments, processor 44 may calculate a unique identifier by excluding from the URL string any varying information. Similarly, front. end processor 44 can automatically detect and ignore variable data in web pages, such as time and date elements.
As another example, copies of a certain content item may be stored in multiple network locations accessed using different URLs. Front end processor 44 may use suitable means, such as mappincg functions or tables, to associate the different URLs (of copies of the same content) with a unique identifier.
In some embodiments, for example, when high accuracy is required, finding a matching URL in the cache is not sufficient for duplicate detection. In such embodiments, following URL matching, front end processor 44, further searches for duplicate content, in the network location to which the URL directs.
In other cases, the input data comprises multimedia content items. A multimedia content item may comprise, for example, an image, video, Flash stream, or audio. Multimedia content typically comprises data that is formatted and structured according^ to some respective standard or specification. In some embodiments, front end processor 44 extracts the multimedia content from the payload of one or more packets in memory 40. The front end processor then produces a respective content
1095S4 t identifie
Cl avrng a he result of the analytics with the respective consent
Thus, anary tit (i.e., without actually con from processing duplicate content even
Fron calculating (and comparing) digita signatures. In some embodiments search, non-matching signatures can cos of the search,
For example, the identifier may comprise gnatures of different strength search ng multiple c o mp u t a t i ο n a 1 complexity.
search when a low complexity signature rs deciding on and more nvoives tradeoff. On one hand, c o mp u t a. t i ο n a 1 e f f o r t produce and compare signatures should be small so that filtering out duplicate content would be efficient. On the such as MD5.
wrongly identified and m some embodiments, instead or ntire of the content, such as over a selected at some agnostic to s ame
For
Moreover, in some exampie, copi id of the same video clip or web page ime stamps. By omitting these the signature calculation, system 20
As the content items comprise web should search for predefined to however, often well a may comprise, for example, frequently updated string links to other web pages or content. To produce a unique identifier of a web page, front end processor 44 calculates a digital signature of the web page excluding any information that may change in subsequent accesses. For example, when a web page comprises a link to an advertisement item, front end processor 44 can ignore the link in the page and cache the advertisement item itself.
In some embodiments, system 20 is configured to recognize and alert upon detecting communication sessions that may be created by servers infected by some malware
1095S4 (e.g., uch communication sessions are often characterized by the malware software transactions. Front end processor s u s p i c .1 o u s t r a f handling content items, the suspicious pattern is cached only once. Subsequent occurrences of the same traffic pattern are recognized by front, end processor 44 matching the pattern to the already cached traffic pattern. To increase the search efficiency, processor 44 can cache and detect strings comprising multiple traffic patterns.
In some embodiments, instead of using the traffic pattern itself as identifier, front end processor 44 calculates an identifier for the traffic pattern by calculating a suitable digital signature over the pattern.
CONDITIONAL ANALYSIS BY CACHING CONTENT IDENTIFIERS
<td> Front end</td><td> processor 44 dist</td><td> inguisnes between conte</td><td> nt</td>
<td> i t e m s b a s e d ο n</td><td> similarity among</td><td> their respective conte</td><td> nt</td>
<td> identifiers. Ii</td><td> i some embodiments</td><td> front, end processor</td><td> 4 4</td>
<td> maps all the</td><td> duplicates of a</td><td> given content item to</td><td> a</td>
single unique content identifier. For example, a digital signature such as checksum, which is calculated over identical content items (or identical parts thereof), can serve as a unique identifier for duplicate content items.
<td> identical</td><td> identifiers</td><td> for</td><td> duplicati</td>
<td> calculating</td><td> signatures</td><td> over-</td><td> the cont</td>
<td> information</td><td> that may</td><td> vary</td><td> among</td>
embodiments ent items, e content items by content items may differ up to some limited extent, so
1095S4 that front end processor 44 can still distinguish (e.g., using a suitable similarity measure) between duplicate and other (i.e., non-duplicate) content items. Content identifiers that uniquely correspond to a certain content item and to all its duplicates are referred to herein as matched content identifiers.
Following the calculation of a content identifier, front end processor 44 searches in cache 46 for a respective matched content identifier. If front end processor 44 fails to find a matched content identifier, the given content is assumed to be received for the first time (i.e., first-occurring content) and the front end processor stores the respective content identifier in cache 46 and informs analytics processor 50 of detecting the first-occurring content item. When high accuracy is required, the identifier may comprise the entire content item. Analytics processor 50 then analyses the content and stores the results in cache 4 6 in association with the respective content identifier.
hand, if finds in cache 46 a identifier, the given confer i tern i s a. s s ume d to be a duplicate of a content item whose content, identifier and respective analysis results were previously stored in cache 46. Front end 44 typically reports for the duplicate detected content, the same respective analytics result that was previously cached, without informing of the detection to analytics processor 50. As a result, a given content item is cached in memory cache 4 6 and processed by analytics processor 50 only once.
When analytics processor 50 receives an indication of receiving first-occurring content, the analytics processor performs a respective analytics operation on which the content cs can he processor 50 perform any suspicious traffic pattern, transactions spam), analytics pattern was extracted to identify the specific involved.
In some embodiments, front end processor 44 counts the number of duplicates of each content item that arrive in the network during a given time duration. In these embodiments, processor 44 typically caches this number in cache 46 in association with the respective content identifier. This feature enables analytics processor 50 to recognize cyber-attacks over the network. The feature additionally enables to delete from the cache content identifiers that are not in use (i.e., did not match any a long time, thus improving the utilization of the some embodiments, processor number of by cl
Uli ime (by bi that are dent ύ byn some embodiments processor ed ist of more) matched image is of inappropriate con it caches a image .
As another example, page is found as innocent (i.e., the page does not match
1095S4 any rule) processor 44 caches a suitable indication in association with the content identifier of this page, in order not to check it again.
In some embodiments, the search items (or searching rules) stored in storage 52 may occasionally change. As a result, some of the already cached identifiers may become irrelevant. Thus, upon changing at least some of the searching rules, front end processor 44 can delete all the cached identifiers. This, however, may result in temporal computational peak, since all the traffic received following the cache clearance is first-occurring content that should be analyzed. Thus, in an embodiment, when a given rule is removed, instead of clearing the entire cache, front end processor 44 scans the cache and removes only analytics results that were produced by that rule. In alternative embodiments, if the rules change (e.g., new rules are added or existing stored rules are replaced with other rules) relates to searching rules that are defined for only a specific content or media type, front end processor 44 can delete from the cache only content identifiers of the respective content or media type, and retain identifiers of other content types. In yet other embodiments, upon storing a new
<td> searching</td><td> rule</td><td> ί n s</td><td> orage 52,</td><td> analytics processor</td><td> - J V</td>
<td> scans all</td><td> (or</td><td> part</td><td> of) the</td><td> c a. c h e d i d e n t i f i e r s,</td><td> and</td>
<td> updates th</td><td colspan="2"> e resoective</td><td> cached an.</td><td> alytics results.</td><td></td>
In some embodiments, upon rules change, instead of deleting all the respective content identifiers from the cache in a single batch, front end processor 44 can be configured to flatten the processing peak by sequentially deleting only part of the identifiers at a time, e.g., periodically.
1095S4 is a flow chart that schematically
Fig.
<img file="IL229154A_D0004.tif" />
in traffic, accordance with an analysis of network embodiment that described herein. The method is carried out jointly by front end processor 44 and analytics processor 50 (and possibly by other elements of system 20 such as NIC 36) . The method begins with System 20 receiving packets (referred to as input data) from network 24 via NIC 36, and storing the packets in RAM 40, at an input step 100.
one or more content from the an produces, :or each content identifier, at an identifier generation step 108.
types are described above.
At a cache searching step 112, front end processor 44 checks whether an identifier, which is identical to the content identifier, is already stored in cache 46. Finding an identical identifier (at step 112) means that the content item at hand is a duplicate of a content item that was previously received and analyzed by system 20, and therefore the method does not send the content item for analysis, but rather reports, at a reporting step 114, cached analysis results, which were previously associated in the cache with the content identifier, and loops back to step 100 to receive subsequent input data. If at step 112, front, end processor 44 fails to find an identical content identifier in cache 46, the content item at hand is assumed to be received by system 2 0 for the first time. Front end processor 44 then stores the content identifier calculated at. step 108 in cache 4 6 at a cachincf step 116, so that future duplicates of that
1095S4 subsequent input
Upon
16, front processor 50 he indication of rom front. end ,
respective analytics operation at an operat
Performing he analyti cs operation υγ nvorves
52. Additionally or alternatively, analytics for occurrences of the search items (in memory 40) that are related to the content item.
performing the analytics step
120, via any search items found, at eportrng step at. step
4
Z., .1 f anaiytit operation n the cache memory in association with the loops receive subsequent, input data.
f icmration configuration, whic pu r e 1 y for the exampl s
sake of concept.ua
<td> any other suita.</td><td colspan="2"> b 1 e c ο n t i gu r a t</td><td> :ion can also be</td><td> used.</td><td> For</td>
<td> example, in the</td><td colspan="2"> description o.1</td><td> : Figs. 1 and 2 a'</td><td> bove,</td><td> upon</td>
<td> detecting a dup</td><td> licate</td><td> content</td><td> item, front end</td><td colspan="2"> processor</td>
<td> 4 4 reports the</td><td> cached</td><td> analyt:</td><td> ics results relat</td><td> ed to</td><td> the</td>
In alternative embodiments, one.
1095S4 events can be analyzed by analytics processor identify patterns of possible cyber- attacks. For example, when analytics processor 50 detects that a certain URL occurs in the traffic at a rate that is 5 significantly higher than the average expected rate, the analytics processor generates a suitable alert to user 2 8 .
It will be appreciated that the embodiments described above are cited by way of example, and that the 0 present disclosure is not limited to what has been particularly shown and described hereinabove. Rather, the scope of the present disclosure includes both combinations and sub-combinations of the various features described hereinabove, as well and modifications thereof which would occur to persons skilled in the art upon reading the foregoing description and which are not disclosed in the prior art. Documents incorporated by reference in the present patent application are to be considered an integral part of the application except that to the extent any terms are defined in these incorporated documents in a manner that conflicts the in bl sp ation should
5 c ο n s i de r e d.
229,154/2
Contents11
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 22915413 | Israel | A | |
| IL20130229154 | – | – | – |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Patent renewedKB | KB | |
| Patent grantedGrantedFF | FF |
Numbers
- Publication
- 229154
- Publication, DOCDB
- 229154
- Publication, EPODOC
- IL229154
- Application
- 229154
- Application, DOCDB
- 22915413
- Application, EPODOC
- IL20130229154
Titles2
- English
- System and method for conditional analysis of network traffic
- Hebrew
- ????? ????? ?????? ????? ?? ?????? ???
Classification
- CPC, 10
- H04L67/2842
- G06F12/0813
- G06F2212/154
- G06F2212/60
- G06F2212/62
- H04L43/062
- H04L63/1408
- H04L63/1416
- H04L67/02
- H04L67/22
- IPC, 1
- H04L12 00
