Cyber-security system and methods thereof for detecting and mitigating advanced persistent threats
Claim Score by NHIP
Abstract
A method and system for adaptively securing a protected entity against a potential advanced persistent threat (APT) are provided. The method includes probing a plurality of resources in a network prone to be exploited by an APT attacker; operating at least one security service configured to output signals indicative of APT related activity of each of the plurality of probed resources; generating at least one security event respective of the output signals; determining if the at least one security event satisfies at least one workflow rule; and upon determining that the at least one security event satisfies the at least one workflow rule, generating at least one action with respect to the potential APT attack.

Term
9.8 yearsto projected expiry
Projected expiry 9 July 2036, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
31 claims: 2 independent, 29 dependent
- 1Broadest claimClaim Score 59, broad(NHIP)A method for adaptively securing a protected entity against a potential advanced persistent threat (APT), comprising:probing a plurality of resources in a network prone to be exploited by an APT attacker;operating at least one security service configured to output signals indicative of APT related activity of each of the plurality of probed resources;generating at least one security event respective of the output signals;determining if the at least one security event satisfies at least one workflow rule;and upon determining that the at least one security event satisfies the at least one workflow rule, generating at least one action with respect to the potential APT attack.
- 17A system for adaptively securing a protected entity against a potential advanced persistent threat (APT), comprising:a processor;and a memory, the memory containing instructions that, when executed by the processor, configure the system to: probe a plurality of resources in a network prone to be exploited by an APT attacker;operate at least one security service configured to output signals indicative of APT related activity of each of the plurality of probed resources;generate at least one security event respective of the output signals;determine if the at least one security event satisfies at least one workflow rule;and generate at least one action with respect to the potential APT attack, upon determining that the at least one security event satisfies the at least one workflow rule.
Independent claims2
122 paragraphs in 6 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATIONS
0001This application claims the benefit of U.S. Provisional Application No. 62/026,393 filed on Jul. 18, 2014 and U.S. Provisional Application No. 62/085,844 filed on Dec. 1, 2014, the contents of which are hereby incorporated by reference.
TECHNICAL FIELD
0002The present disclosure generally relates to cyber security systems, and more particularly to detecting and mitigating advanced persistent threats.
BACKGROUND
0003The Internet provides access to various pieces of information, applications, services, and vehicles for publishing information. Today, the Internet has significantly changed the way we access and use information. The Internet allows users to access services such as banking, e-commerce, e-trading, and other services people access in their daily lives.
0004In order to access such services, a user often shares his personal information, such as name, contact details, highly confidential information such as usernames, passwords, bank account number, credit card details, and the like, with service providers. Similarly, confidential information of companies such as trade secrets, financial details, employee details, company strategies, and the like are also stored on servers that are connected to the Internet. There is a threat that such confidential data may be accessed by malware, viruses, spyware, key loggers, and various other methods of unauthorized access to such information. Such unauthorized access poses great danger to unwary computer users.
0005Recently, the frequency and complexity level of attacks has increased on all organizations including, but not limited to, cloud providers, enterprise organizations, and network carriers. Some complex attacks, known as multi-vector attack campaigns, utilize different types of attack techniques and target network and application resources in order to identify at least one weakness that can be exploited to achieve the attack's goals, thereby compromising the entire security framework of the network.
0006Another type of complex attack is an advanced persistent threat (APT). An APT is an attack in which an unauthorized hacker gains access to a network and remains undetected for a long period of time. The intention of an APT attack is to steal data rather than to cause direct damage to the network or organization. APT attacks target organizations in sectors with high-value information, such as the national defense, manufacturing, retail, and financial industries.
0007These attacks are frequently successful because modern security solutions are not sufficiently agile and adaptive with respect to detection and mitigation of resources needed to meet such evolving threats. In addition, current security solutions cannot easily and promptly adapt to meet new technologies and topologies implemented by the entities to be protected.
0008For example, in modern computing platforms, such virtualization and software-defined networks (SDN) face real challenges to security systems. Such platforms host an enormous number of tenants with virtually distributed and dynamic resources. Each tenant can be transformed into a malicious resource, thereby attacking its own “neighbors,” or other networks.
0009Current solutions for detecting APT attacks are based on sandbox and other emulation technologies in order to detect a “zero-day” malware activity. Another type of solution for detecting APT threats is based on reputation sources and attack signature matching (IPS/Ant-virus style). In typical implementation, sandbox and reputation are based on a cloud model, i.e., content objects are copied sent to a cloud platform for execution by sandbox devices and reputation information is being updated in the cloud platform and being “injected” to the APT devices in the network.
0010Due to privacy and security reasons, transporting content to a cloud platform out of the organization network may not be feasible to privacy reasons. Therefore most APT solutions include a private cloud sandbox deployment model. Such a model requires complex implementation. Furthermore, reputation and signature based detection mechanisms are considered non zero-day attack technologies. That is, rules are not updated based on previous detected incidents.
0011Attackers have been developed techniques to bypass sandbox technologies. For example, malware can be injected to a protect environment through an external device, e.g., a USB device or an unsecured network connection (e.g., a public Wi-Fi network). Further, attackers can design malwares that cannot be executed over virtualized or in simulated environments.
0012In addition, currently available solutions for handling APT attacks suffer from drawbacks including, for example, programmability capabilities, automatic mitigation, and collaboration. For example, a security defense system that is not programmable to allow changes or adaptations to the way the nature in which the protection means operate, becomes ineffective in a matter of a few days or even few hours because such security systems fail to resist or adapt to any new evasion attempts or new attacks behaviors.
0013Security solutions, and in particular solutions for handling APT attacks, do not provide a reliable automatic mitigation capabilities. Typically, APT security solutions are not designed for both detection and automatic mitigation. As a result, system administrators do not trust currently available APT security solutions to conduct automatic attack mitigation actions due to the high level of false positive alerts generated by such systems. As a result of such false positive alerts, system administrators must often manually analyze the system's logs, decide about the best mitigation action (e.g., most accurate action that mitigate the risk), and only then to provision network control actions that will mitigate the attack.
0014On top of the above, when a security manager/administrator needs to design and implement a security solution the administrator must be specialized in the devices he has, learning its available security device and in particular understand the configuration language of each such device. Currently, there is no unified standard for configuration of such devices and/or defining the requirements for protecting the security solutions. Therefore, the cycles for creating or changing the security policies in large organizations that deploy many and different security devices are typically prolonged.
0015It would therefore be advantageous to provide a solution that would overcome the deficiencies of the prior art solutions for detecting and mitigating APT attacks.
SUMMARY
0016A summary of several example embodiments of the disclosure follows. This summary is provided for the convenience of the reader to provide a basic understanding of such embodiments and does not wholly define the breadth of the disclosure. This summary is not an extensive overview of all contemplated embodiments, and is intended to neither identify key or critical elements of all embodiments nor delineate the scope of any or all embodiments. Its sole purpose is to present some concepts of one or more embodiments in a simplified form as a prelude to the more detailed description that is presented later. For convenience, the term some embodiments may be used herein to refer to a single embodiment or multiple embodiments of the disclosure.
0017Some embodiments of the disclosure relate to a method for adaptively securing a protected entity against a potential advanced persistent threat (APT). The method comprises probing a plurality of resources in a network prone to be exploited by an APT attacker; operating at least one security service configured to output signals indicative of APT related activity of each of the plurality of probed resources; generating at least one security event respective of the output signals; determining if the at least one security event satisfies at least one workflow rule; and upon determining that the at least one security event satisfies the at least one workflow rule, generating at least one action with respect to the potential APT attack.
0018Some embodiments of the disclosure relate to a system for adaptively securing a protected entity against a potential advanced persistent threat (APT). The system comprises a processor; and a memory, the memory containing instructions that, when executed by the processor, configure the system to: probe a plurality of resources in a network prone to be exploited by an APT attacker; operate at least one security service configured to output signals indicative of APT related activity of each of the plurality of probed resources; generate at least one security event respective of the output signals; determine if the at least one security event satisfies at least one workflow rule; and generate at least one action with respect to the potential APT attack, upon determining that the at least one security event satisfies the at least one workflow rule.
BRIEF DESCRIPTION OF THE DRAWINGS
0019The subject matter disclosed herein is particularly pointed out and distinctly claimed in the claims at the conclusion of the specification. The foregoing and other objects, features, and advantages of the disclosed embodiments will be apparent from the following detailed description taken in conjunction with the accompanying drawings.
0020<figref idref="DRAWINGS">FIG. 1</figref> is a diagram of a cyber-security system implemented according to one embodiment.
0021<figref idref="DRAWINGS">FIG. 2</figref> is a block diagram of a security stack module implemented according to one embodiment.
0022<figref idref="DRAWINGS">FIG. 3</figref> illustrates security services utilized by the APT security application according to an embodiment.
0023<figref idref="DRAWINGS">FIG. 4</figref> is a block diagram of the user network and application behavior anomaly security service according to one embodiment.
0024<figref idref="DRAWINGS">FIG. 5</figref> illustrates the processing of security signals and security events by a security stack module according to one embodiment.
0025<figref idref="DRAWINGS">FIG. 6</figref> is an example for a security event derived from a SoA signal.
0026<figref idref="DRAWINGS">FIGS. 7-13</figref> illustrate the operation of the cyber security system to detect a potential APT breach occurring in a retail chain.
DETAILED DESCRIPTION
0027It is important to note that the embodiments disclosed herein are only examples of the many advantageous uses of the innovative teachings herein. In general, statements made in the specification of the present application do not necessarily limit any of the various claimed embodiments. Moreover, some statements may apply to some inventive features but not to others. In general, unless otherwise indicated, singular elements may be in plural and vice versa with no loss of generality. In the drawings, like numerals refer to like parts through several views.
0028The various disclosed embodiments include cyber security systems and methods thereof. The disclosed embodiments are designed to protect entities. A protected entity may include, for example, a layer-2 (L2) or layer-3 (L3) network element, a server application (e.g., Web, Mail, FTP, Voice and Video conferencing, database, ERP, and so on), “middle boxes” devices (e.g., firewalls, load balancers, NAT, proxies devices etc.), SDN controllers (e.g., Open Flow controllers and virtual overlay network controllers) and personal computing devices (e.g., PCs, laptops, tablet computers, smartphones, wearable computing devices, etc.). The protected entity may be deployed or otherwise accessed through various computing platforms. The computing platforms may include, but are not limited to, virtualized networks and software defined networks and software defined datacenters (SDNs and SDDCs).
0029In some embodiments, the disclosed cyber security system is configured to detect and mitigate multi-vector attack campaigns that carry APT attack campaigns. The APT attack campaigns include, but are not limited to, intelligence gathering stage, network pre-attack probes, malware propagation, information leak, and so on. The disclosed cyber security system achieves comprehensive protection by overcoming the drawbacks of prior art solutions, such of which have been discussed above.
0030The cyber-security system is arranged as a layered architecture allowing the system to adapt to changes in the protected entity and to ongoing attack campaigns. In one embodiment, the cyber security system provides the ability to create, define, or program new security applications, to modify the functionality of existing applications, and to easily correlate and create workflows between multiple security applications.
0031A security application is programmed to detect and mitigate a threat to the protected entity, determine which specific resources should be utilized for the protection, determine where the protection should take place, and so on. In an embodiment, a security application can be programmed using a set of security services discussed in more detail below.
0032<figref idref="DRAWINGS">FIG. 1</figref> is an exemplary and non-limiting diagram of the cyber security system <b>100</b> utilized to describe the various disclosed embodiments. The cyber security system <b>100</b> is configured to protect an entity (hereinafter a “protected entity”) <b>130</b> communicatively connected in a network <b>110</b>. The cyber security system <b>100</b> is also connected to the network <b>110</b>. The network <b>110</b> may be, but is not limited to, a virtualized network, a software defined network (SDN), a hybrid network, cloud services networks, or any combination thereof. The protected entity <b>130</b> may include a client network <b>130</b>-<b>2</b> or a designated resource <b>130</b>-<b>1</b>, such as a server, a point of sale host, a web service, a mail service, a database service, and so on. The client network <b>130</b>-<b>2</b> may be, for example, a local area network (LAN), etc.
0033An SDN can be implemented in wide area networks (WANs), local area networks (LANs), the Internet, metropolitan area networks (MANs), ISP backbones, datacenters, and the like. Each network element in the SDN may be a router, a switch, a bridge, a load balancer, a DPI device, and so on, as well as any virtual instantiations thereof. Typically, elements of the SDN include a central SDN controller <b>140</b> and a plurality of network elements <b>150</b>. In certain implementations, the central SDN controller <b>140</b> communicates with the network elements <b>150</b> using an OpenFlow protocol which provides a network abstraction layer for such communication, Net-conf protocol which provides mechanisms to install, manipulate, and delete the configuration of network devices, and so on.
0034In an embodiment, the network <b>110</b> may be a hybrid network in which a SDN is a sub-network of a conventional network in which its elements <b>150</b> cannot be programmed by a central SDN controller <b>140</b>. The cyber security system <b>100</b> interfaces with the network <b>110</b> through the central SDN controller <b>140</b>. In another embodiment, the entire functionality or portion of the functionality of the security system <b>100</b> can be integrated in the central SDN controller <b>140</b>. Alternatively, the functionality of the cyber security system <b>100</b> operates directly with the network elements <b>150</b> in the data-plane (or it can be a combination of the above). This allows implementing security functions in various locations in the network <b>110</b> (SDN, Legacy (non-SDN) networks, or hybrid networks) to protect the protected entity <b>130</b>.
0035The security functions are programmed by the cyber security system <b>100</b> to perform any one of, or a combination of, detection, investigation, and mitigation functions (labeled as f<b>1</b>, f<b>2</b>, and f<b>3</b> in <figref idref="DRAWINGS">FIG. 1</figref>). Such functions are executed during different phases of the operation of the cyber security system <b>100</b>, i.e., detection, investigation, and mitigation phases and independently programmed by the cyber security system <b>100</b>. It should be noted that same or all the functions (f<b>1</b>, f<b>2</b>, and f<b>3</b>) can be implemented, or otherwise performed, in the network <b>110</b>. It should be noted that the security functions can be reused throughout the different phases of the system operation for different purposes.
0036In an exemplary implementation, the cyber security system <b>100</b> includes a security stack module <b>111</b> and a network services module <b>113</b>. The security stack module <b>111</b> is configured to control and execute the various phases to secure the protected entity <b>130</b>. Specifically, the security stack module <b>111</b> is configured to create, control, program, and execute the security functions (f<b>1</b>, f<b>2</b> and f<b>3</b>) through a plurality of security applications or “apps.” The operation of the security stack module <b>111</b> is discussed in greater detail herein below with respect to <figref idref="DRAWINGS">FIG. 2</figref>.
0037The network interface module <b>113</b> provides an interface layer of the cyber security system <b>100</b> with the central SDN controller <b>140</b> to allow commutation with SDN-based network elements <b>150</b>. In another embodiment, the network interface module <b>113</b> also communicates with “legacy” network elements <b>170</b> in the network <b>110</b>. Non-limiting examples for communication drivers that allow the network interface module <b>113</b> to configure, control, and monitor legacy network elements (and technologies) <b>170</b> include, but are not limited to, BGP, BGP flow spec, NetConf, CLIs, NetFlow, Middle-boxes devices drivers (e.g., layer 4 to 7 devices such as DPI devices, firewall devices, ADC (application delivery controllers) devices etc.), end point device drivers (mobile, host based security applications), server applications such as DNS applications, Web applications, and so on.
0038<figref idref="DRAWINGS">FIG. 2</figref> shows an exemplary and non-limiting block diagram of the security stack module <b>111</b>. In an exemplary implementation, the security stack module <b>111</b> includes the following units: a security application unit <b>210</b>, a security services unit <b>220</b>, a data-plane unit <b>230</b>, and northbound network interface (NBI) <b>240</b>. The security stack module <b>111</b> is configured with a security services unit <b>220</b> and various services provided by the data-plane unit <b>230</b> that can be utilized for the execution of different security applications. Thus, security applications (each one for different purpose) can consume the same security services for their own needs. In addition, various data-plane services can be utilized by services residing in the security services unit <b>220</b>.
0039Specifically, the security application unit <b>210</b> includes at least one security application (app) <b>211</b> for APT detection and mitigation inside an organization network. Other security applications designed to provide a different type of security protection or function including, for example, low and slow DoS attacks protection, reputation security intelligence, web page scraping detection and mitigation, volumetric DoS detection and mitigation, can reside in the security application unit <b>210</b> as well.
0040According to one embodiment, different APT security applications can be executed in the security stack module <b>111</b> for different protected tenants. In such an embodiment, a protected tenant is an entity in the organization or an organization. As an example for the former, one APT security application can be programmed to protect HR department resources while another application can programmed to protect resources of the finance department. The HR department and finance departments are different protected tenants. The different resources may be part of a client network (e.g., the client network <b>132</b> shown in <figref idref="DRAWINGS">FIG. 1</figref>).
0041According to an embodiment, the cyber security system <b>100</b> is designed to allow correlation between security applications in the security applications unit <b>210</b> and security services in the security services unit <b>220</b> in order to define, create, or otherwise program a robust solution for detecting and mitigating attacks against the protected entity <b>130</b>-<b>1</b> or <b>130</b>-<b>2</b>.
0042The NBI <b>240</b> and the security services unit <b>220</b> provide the required services for the security applications <b>211</b>. The APT security application <b>211</b> is configured to implement pre-defined APIs in order to efficiently communicate with the security services <b>221</b>.
0043In one embodiment, the security services <b>221</b> are designed, in part, to allow identifying behavior of hosts and entities in the organization and detect abnormal network behavior results due to infected users and entities. Each security service <b>221</b> is designed to host multiple programmable security decision engines (SDEs, not shown in <figref idref="DRAWINGS">FIG. 2</figref>). The creation and modification of such SDEs can be performed through a SDE programming language. The SDEs, and thereby the security services <b>221</b>, can allow the cyber security system <b>100</b> to adapt to new attack behavior, unknown behaviors, or attacks that utilize new evasion techniques. The security services <b>221</b> are also designed to provide an efficient control over security functions (f<b>1</b>, f<b>2</b>, and f<b>2</b>) in the network data-plane. The security services <b>221</b> utilized by the APT security application <b>211</b> are discussed in more details below with respect to <figref idref="DRAWINGS">FIG. 3</figref>.
0044The data-plane unit <b>230</b> provides central management and control of the data-plane resources, such as routers, switches, middle-box devices, and so on. In an embodiment, the data-plane unit <b>230</b> allows the security services <b>221</b> to retrieve and store the required network and application information from the data plane resources as well as to enforce security related network control actions. Various functions provided by the data-plane unit <b>230</b> includes a topology discovery, data collection, traffic redirection, traffic distribution (L2, L3 load balancing for scaling out resources), traffic copy, and so on.
0045Topology discovery involves interacting with the data-plane network elements, SDN controllers, and orchestration systems in order to retrieve network topology information. This function is important for the topology awareness that is needed by other data-planes' functions as well as security services <b>221</b> and security applications <b>211</b>.
0046The traffic copy and redirection functions are designed to manage all network traffic redirection functions which include, but are not limited to, traffic redirection, smart traffic copying, traffic distribution, and so on.
0047The data-plane unit <b>230</b> is further configured to provide the following functions: management of quality of service (QoS) actions in the network elements, and a set of mitigation functions. The mitigation functions include basic ACLs services which are layer-2 to layer-4 access control list services that manage the distributed rules throughout the network elements. Software defined networks as well as legacy network elements <b>170</b> and hybrid networks may be supported by this service.
0048Advanced ACL functions are similar in characteristics to the basic ACL functions but can define more granular access rules including application parameters (L7). Specifically, this function can be activated according to the generated risk-chain pattern from the risk-chain pattern generation service (discussed below) as a blocking rule. The function typically operates with DPI network elements, such as, but not limited to, next generation firewalls, security web gateways for enforcing the application level ACL rules. Service rate-limits manage the QoS rules in the data plane device. Black-hole route function provides an extension of the redirection data-plane services that manage redirection of users into a black-hole. Typically, black holes are network locations where incoming or outgoing traffic is silently discarded (or “dropped”), without informing the source that the data did not reach its intended recipient. In general, the data-plane unit <b>230</b> provides all information that is required by the security services <b>221</b>, and controls the network <b>110</b> via decisions made by the security services <b>221</b> and security applications <b>211</b>.
0049In some exemplary implementations, certain functions provided by the data-plane <b>230</b> can be implemented in the central SDN controller <b>140</b>. Examples for such functions may include, but are not limited to, traffic redirection, topology discovery, and data collection.
0050The NBI <b>240</b> interfaces between the security stack module <b>111</b> and one or more external systems (not shown). The external systems may include, for example, third party security analytics systems, security intelligence feeds (e.g., reputation sources), security portals, datacenter orchestration control systems, identity management systems (such as domain controllers), DNS and DHCP services, or any other system that can provide information to the security stack module <b>111</b>. The interfaces may be, but are not limited to, CLI, REST APIs, Web UI, as well as drivers for control and/or configuration, of external systems and so on. The NBI <b>240</b> also interfaces with network services module <b>113</b>.
0051In certain implementations, each unit <b>210</b>, <b>220</b>, <b>230</b>, and <b>240</b>, as well as the security stack module <b>111</b>, are communicatively connected through a predefined set of interfaces and/or APIs. As a result, the disclosed cyber security system <b>100</b> is fully programmable and configurable. The interfaces and/or APIs may be designed to be unidirectional, bidirectional, or one-to-many bi-directional flows of information between the various modules and units.
0052It should be noted that modules in the cyber security system <b>100</b> and units <b>210</b>, <b>220</b>, and <b>230</b> in the security stack module <b>111</b> are independent. Thus, any changes in one unit or module do not necessarily result in any changes to the other modules.
0053As noted above, one or more security applications <b>211</b> can be correlated with one or more security services <b>221</b> in order to define, create, or otherwise program a robust solution for detecting and mitigating APTs. A security application <b>211</b> typically correlates security signals generated by multiple security services <b>221</b>. This allows a single security application <b>211</b> to make decisions based on multiple services in order to increase the overall decision accuracy. The correlation among security applications <b>211</b> is also performed by correlating security events (feeds) generated by other security applications <b>211</b>, thereby allowing the entire security decision-making process to be more holistic and context-based.
0054According to one embodiment, the correlation of security events is performed by a set of the workflow rules which are processed and applied by the APT security application <b>211</b>. In an embodiment, the set of workflow rules are defined by the user. In another embodiment, a learning mechanism is implemented to modify or select a set of correlation and workflow rules to execute. The correlation process is discussed in greater detail below with respect to <figref idref="DRAWINGS">FIG. 5</figref>.
0055Each, some, or all of the modules of the cyber security system <b>100</b> and the various units of the security stack module <b>111</b> may be realized by a processing system. The processing system may comprise or be a component of a larger processing system implemented with one or more processors. The one or more processors may be implemented with any combination of general-purpose microprocessors, microcontrollers, digital signal processors (DSPs), field programmable gate array (FPGAs), programmable logic devices (PLDs), controllers, state machines, gated logic, discrete hardware components, dedicated hardware finite state machines, or any other suitable entities that can perform calculations or other manipulations of information.
0056The processing system may also include machine-readable media for storing software. Software shall be construed broadly to mean any type of instructions, whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise. Instructions may include code (e.g., in source code format, binary code format, executable code format, or any other suitable format of code). The instructions, when executed by the one or more processors, cause the processing system to perform the various functions described herein.
0057<figref idref="DRAWINGS">FIG. 3</figref> shows an exemplary and non-limiting diagram of the security services <b>221</b> and data-plane services <b>230</b> utilized by the APT security application <b>211</b>. It should be noted that the security services <b>221</b> (and/or their associated SDEs) can be dynamically added, removed, or modified to provide an accurate and timely detection of APT threats.
0058According to an exemplary and non-limiting implementations, the following security services <b>221</b> may be utilized by the APT security application <b>211</b>: a user network and application behavior anomaly (UNABA) security service <b>221</b>-<b>1</b>, a sandbox security service <b>221</b>-<b>2</b>, a reputation security service <b>221</b>-<b>3</b>, a user identity security service <b>221</b>-<b>4</b>, an attack signatures security service <b>221</b>-<b>5</b>, a user challenge-response security service <b>221</b>-<b>6</b>, a real-time risk-chain pattern generation security service <b>221</b>-<b>7</b>, an anti-virus (AV) security service <b>221</b>-<b>8</b>, a Web application (WAF) security service <b>221</b>-<b>9</b>.
0059The UNABA security service <b>221</b>-<b>1</b> is a service that analyzes host-based traffic behavior. The UNABA security service <b>221</b>-<b>1</b> includes a host profile data structure and a set of SDEs programmed to continuously generate host-based scores of anomaly (SoA). A host can be any machine or resource connected to a network. For example, a host may include a client device, a server, a database, an end-point terminal (e.g., PoS), and the like. The activity of users utilizing client devices can be derived from the profile learnt for such device.
0060In an embodiment, a SoA is a security signal that can be correlated by a security application <b>211</b>. A high SoA reflects a host traffic anomaly that characterizes different types of network based attacks, such as network pre-attack probes scanning activities (intelligence gathering), malware propagation activities, abnormal remote desktop communication channels, abnormal processes installation channels, brute-force attack activities (user/pass cracking), unexpected traffic flows that represent in general a compromised host, abnormal protocol usage that represent “fake” applications, drop-zone (or drop point) traffic behavior which represents data leak from specific hosts, and so on.
0061The UNABA security service <b>221</b>-<b>1</b> is programmed to continuously learn the network and application connections activities of a host (or a group of hosts). The UNABA security service <b>221</b>-<b>1</b> implements a long-term (e.g., at least 12 weeks) of adaptive baselines per each traffic parameter. The host profile data structure of this service aggregates L2-L7 (layer 2 through layer 7 of the OSI model) parameters as well as application metadata and continuously generates base lines for each parameter (or for multiple parameter functions, such as traffic ratio), including 24 by 7 (24×7) differentiated baselines, i.e., storing base line per time and day in the week.
0062The UNABA security service <b>221</b>-<b>1</b> includes a set of SDEs programmed by a set of engine rules. A user can modify and program new SDEs by defining a new set of engine rules. Each SDE is programmed to continuously generate SoA per each host or hosts group. As noted above, high SoA reflects unusual user/service application activity as mentioned above. A detailed block diagram of the UNABA security service <b>221</b>-<b>1</b> is provided in <figref idref="DRAWINGS">FIG. 4</figref>.
0063In an embodiment, the UNABA security service <b>221</b>-<b>1</b> can be programmed to generate SoA that correlates signals from other security services <b>221</b>. Such correlation is performed by a set of engine rules discussed in greater detail below.
0064The sandbox security service <b>221</b>-<b>2</b> is programmed to selectively select the required sandbox function that is required to analyze content, such as web objects, mails attachments, executable files, and so on. The sandbox security service <b>221</b>-<b>2</b> is configured to control and manage the sandbox functions resources as well as analyze their outputs according to the correlation and workflow rules.
0065The sandbox security service <b>221</b>-<b>2</b> is configured to activate the most relevant sandbox function according to the ongoing threat. For example, if a threat was detected and the host(s) associated with it are all based on MS operating system, then the sandbox security service <b>221</b>-<b>2</b> is instructed to select (instructed by the security application) a sandbox function that is best in analyzing MS based object files and to manage the sand box function to direct its resources on these high risk detected hosts first. The security application is configured (through the security application's workflow and correlation rules) to correlate the sandbox outputs with other security services outputs, such as with the user network and application anomaly security service.
0066The attack signatures security service <b>221</b>-<b>5</b> is configured to allow management of multiple types of intrusion detection and prevention functions in the network. The service allows the security application to define and activate the relevant attack signature policies according to the ongoing detected threat, and monitor the results in a way that can be managed by the security app <b>211</b> or by other security services <b>221</b>. For example, when the UNABA security service <b>221</b>-<b>1</b> detects suspicious user brute-force attack activities, then the security application <b>211</b> will instruct the attack signature service <b>221</b>-<b>5</b> to activate a brute-force attack signature policy only on the suspicious host to allow accurate and efficient detection of the attack.
0067The reputation security service <b>221</b>-<b>3</b> is configured to allow managing and analyzing of multiple reputation sources (e.g., third party intelligence security sources). The reputation security service <b>221</b>-<b>3</b> is further configured to allow the security application <b>211</b> to inquiry the most relevant reputation source according to the ongoing detected threat. For example, if the UNABA service <b>221</b>-<b>1</b> identifies suspicious drop zone activity, then the APT security application can instruct the reputation security service <b>221</b>-<b>3</b> to select the most relevant reputation source and to monitor all traffic between the drop zone host(s) and external sites. In this case the reputation security service <b>221</b>-<b>3</b> automatically selects reputation source(s) with a database that has the information about external drop point sites and/or command-and-control (C&C) external servers that are known to be associated with controlling internal drop points servers. In general, for APT threats detection, the analysis and management of reputation information is focused on phishing sites, bad reputation malware sites, malware C&C sites and drop zones sites.
0068In an embodiment, a user identity security service <b>221</b>-<b>4</b> is configured to allow mapping a source IP address to a network host and user identity. To this end, the user identity security service <b>221</b>-<b>4</b> is configured to query an identity management system such as DNS and DHCP and Domain controllers (e.g., ActiveDirectory).
0069Other types of a security service <b>221</b> that can be used to detect APT threats include, but are not limited to, a user challenge-response security service <b>221</b>-<b>6</b> that is configured to allow the programming of advanced challenge-response actions that validate the legitimacy of users' applications. As in the case of the other security services, the user challenge-response security service <b>221</b>-<b>6</b> is configured to allow the security application <b>211</b> to instruct validation of a specific hosts' application through the most appropriate challenge response actions, and according to the on-going detected threat. According to some exemplary embodiments, the user challenge-response security service <b>221</b>-<b>5</b> is configured to activate different types of challenge-response mechanisms according the protocol and application that is to be validated (e.g., HTTP challenge for HTTP protocol related applications communication, DNS challenge for DNS traffic etc.).
0070Another type of security service <b>221</b> that can be utilized for detection of APT threats is a real-time risk chain pattern generation security service <b>221</b>-<b>7</b>, which is configured to analyze a detected anomaly parameter (e.g., anomaly that was detected by the user network & application anomaly service) and create a pattern that characterizes the anomaly. Such pattern is used for real-time investigation actions and mitigation actions of threats, as well as for forensics analysis.
0071In an embodiment, the real-time risk chain pattern generation security service <b>221</b>-<b>7</b> is configured to provide the security application <b>211</b> the risk chain development pattern, and in return the security application <b>211</b> decides which security services <b>221</b> need to be activated. The decision is based on a set of correlation and workflow rules (that are either set manually or automatically by the system).
0072It should be noted that the security services <b>221</b> listed above are merely examples and other services can be utilized in the cyber security system <b>100</b> according to the embodiments disclosed herein. In various non-limiting embodiments, a programming language is provided in order to allow users to create and modify security applications <b>211</b> and to create and modify the SDEs contained in each security service <b>221</b>, as per business needs.
0073<figref idref="DRAWINGS">FIG. 4</figref> shows an exemplary block diagram of the UNABA security service <b>221</b>-<b>1</b> according to one embodiment. The UNABA security service <b>221</b>-<b>1</b> is a cornerstone in detecting APT attacks as typically hackers gain access to a network <b>110</b> and remain undetected for a long period of time by exploiting legitimate users' and servers' hosts in the network <b>110</b> and pretending normal behavior of such users and servers activities.
0074The UNABA security service <b>221</b>-<b>1</b> includes a host profile module <b>410</b>, a plurality of user anomaly behavioral SDEs <b>420</b>, and a set of normalization functions <b>440</b>. The host profile module <b>410</b> is configured to store and compute baseline parameters for the host activity over a period of predefined time (e.g., 12 weeks). The host profile module <b>410</b> typically stores baselines of each host traffic parameter as well as baselines of multiple parameters function (e.g., ratios of inbound vs. outbound traffic parameters, relative portions of application traffic parameter, relative frequency, and so on). Each, some, or all of the modules and/or engines of UNABA security service <b>221</b>-<b>1</b> may be realized by a processing system. Examples for such a processing system are provided above.
0075In an embodiment, each profile stored in the host profile module <b>410</b> is structured with two sections: classification and characteristics. The classification includes host traffic classification parameters in a hierarchy structure. Each hierarchy level is defined as a “flow-path.” The characteristics section includes dynamic characteristics of traffic parameters per each classification flow-path. The characteristics of a traffic parameter include real-time and baselines of rate and rate-invariant parameters.
0076The user anomaly behavioral SDEs <b>420</b> are configured to generate based on engine rules and the respective profile and flow-path a SoA per host. In order to compute a SoA for a host, real-time as well as adaptive baselines of a host are retrieved from the host profile module <b>410</b> and each parameter therein is normalized by normalization functions <b>440</b>. As noted above, each parameter or a set of parameters has its own normalization function <b>440</b>. The adaptive normalization functions are tuned by the adapted base lines in a predetermined time interval. In an embodiment, the time interval is one hour. Each normalization function <b>440</b> generates a parameter deviation weight (a behavior anomaly level) in a format that can be processed by the user anomaly behavioral SDEs <b>420</b>. Normalization functions <b>440</b> are also responsible for normalizing signals from other security services <b>221</b> as shown in <figref idref="DRAWINGS">FIG. 4</figref>.
0077The computed SoAs are provided to the APT security application <b>211</b>, which decides an action to be executed. Such an action may include, for example, activate more SDEs in the detection phase, initiate an investigation phase and activate investigation services, initiate mitigation phase and activate mitigation services, and so on. It should be noted that the security application workflow decisions are based on the real-time risk-chain pattern generation service results (i.e., the risk chain pattern and its progress in time).
0078As shown in <figref idref="DRAWINGS">FIG. 4</figref>, the UNABA security service <b>221</b>-<b>1</b> can also correlate outputs (signals) of other security services <b>221</b>. A typical correlation may be with outputs from, reputation <b>221</b>-<b>3</b>, attack signatures <b>221</b>-<b>5</b>, and sandbox <b>221</b>-<b>2</b> security services (discussed in detail above). The outputs of the security services <b>221</b> (which are inputs to the UNABA security service <b>221</b>-<b>1</b>) may be integer values, Boolean values, and other values. Such values are normalized by the normalization functions <b>440</b> into a format that can be processed by the SDEs of the UNABA security service <b>221</b>-<b>1</b>.
0079In order to detect APT attacks, the UNABA security service <b>221</b>-<b>1</b> is configured with a set of SDEs <b>420</b>. Each such SDE <b>420</b> is programmed to evaluate or detect host's user or server behavioral anomalies caused due to APTs' activities. These anomalies that each SDE <b>420</b> is responsible to evaluate abnormal usage of include, but not limited to, pre-attack research and intelligence gathering activities (manually or automatically generated) such as network probes, application probes, brute-force activities to reveal user/pass, propagation activities, data leak activities, and so on.
0080The propagation activities (manually and automatically generated) include, for example, abnormal remote desktop traffic. Such abnormal traffic may be, but is not limited to, abnormal files copied to or from remote hosts, abnormal processes execution on remote hosts, abnormal service(s) activations/terminations (e.g., FTP or Mail service enablement on some server etc.). Other propagation activities that the SDEs <b>420</b> are responsible to detect include, for example, malware spreading/propagation activities, malware automatic brute-force activities, and so on.
0081In an embodiment, data leak activities (manual or automatic), such as abnormal communication of a “crowd” of hosts that are infected with some malware and which upload data to specific host(s) in the organization (defined as internal drop zone or point), abnormal upload of data from hosts that are known to include confidential information to other sites outside of the organization, and so on.
0082In an embodiment, SDEs <b>420</b> analyzing unexpected traffic flows are also utilized by of the APT security application <b>211</b>. These SDEs <b>420</b> are part of the UNABA security service <b>221</b>-<b>1</b> and analyze the “maturity” of each host in the network <b>110</b> according to time and traffic parameters. A “mature” host or user that starts to communicate with other network hosts and utilize protocol(s) and/or application(s) not previously used, is flagged as suspicious. Flagged hosts and users are typically involved in one of the attack stages mentioned above (e.g., pre-attack intelligence gathering, propagation or data leak).
0083Other malicious activities that can indicate a potential APT attack include unusual geographic communication (e.g., users communicate with new geographical locations); unusual user's application behavior; unusual content type consumed by a specific application (e.g., binary content to Facebook® or Twitter® accounts); hosts connections with unusual traffic symmetry (e.g., unusual upload or download activities, clients that act like servers, etc.); unusual time-based activity (24×7 activity) of hosts based on parameters, such as L4 connection, bandwidth, destinations, application type, abnormal periodic behavior, and so on.
0084The user anomaly behavioral SDEs <b>420</b> can be also configured to detect or evaluate anomalies related to applications executed on a host device. Such anomalies include, for example, unusual DNS traffic (e.g., too many DNS query from the same client, same size of DNS requests from the same client, fast flux behavior (e.g., same domain that is represented by multiple dynamically changed IP addresses); unusual browser types usage, and the like. In an embodiment, each user anomaly behavioral SDE <b>420</b> generates a SoA that quantifies the deviation of the host's, or hosts group's behavioral parameters from the norm as determined by a respective of profile maintained in the host profile module <b>410</b>. The SoA may be in a form of an integer value, a Boolean value, or a certain level (e.g., high, low, medium), or any other form that measures level of activity. The SoA is continuously generated, and thereby can be changed over time and can be used to measure trends of anomaly scores.
0085As noted above, the SoA is generated by a set of decision engine rules that can be processed by each engine in a security service <b>221</b>. The engine rules typically include one or more of: a set of Boolean operators (e.g., AND, OR, NOT); a set of weights level (Low, Mid, High); and so on. The generated SoA (signals) are fed to the security application <b>211</b>. The security application <b>211</b> can translate the signals into a security event fed to the application's correlation and workflow rule (<b>544</b>). For example, a high SoA value may be translated into a security event, while a low SoA value may not create an event.
0086<figref idref="DRAWINGS">FIG. 5</figref> shows the processing of security signals according to an exemplary and non-limiting embodiment. In this example, each of the security services <b>510</b>, <b>520</b>, and <b>530</b> generates security signals by means of their respective SDEs. The SDE <b>510</b>, <b>520</b>, and <b>530</b> may be any of the security services noted above. The security signals are fed to an APT security application <b>540</b> that checks if one and/or any combination of the received signals satisfy at least one event rule <b>542</b>. The security signals may be generated in response to detection of malware activity such as pre-attack intelligence gathering, malware propagation activities, drop zone behavior, and so on.
0087The event rules <b>542</b> can be applied on the signal value, duration, and so on. In a non-limiting embodiment, a syntax of the event rule may be defined as follows:
0000<tables id="TABLE-US-00001" num="00001"><table frame="none" colsep="0" rowsep="0"><tgroup align="left" colsep="0" rowsep="0" cols="1"><colspec colname="1" colwidth="217pt" align="left" /><thead><row><entry namest="1" nameend="1" align="center" rowsep="1" /></row></thead><tbody valign="top"><row><entry> IF <level><signal type><signal attribute(s)><condition type><operator</entry></row><row><entry>condition><units><2<sup>nd </sup>condition type><units> THEN event <”event</entry></row><row><entry>name”></entry></row><row><entry namest="1" nameend="1" align="center" rowsep="1" /></row></tbody></tgroup></table></tables><br /> The various parameters of the event rule are defined in the exemplary Table 1.
0000<tables id="TABLE-US-00002" num="00002"><table frame="none" colsep="0" rowsep="0" pgwide="1"><tgroup align="left" colsep="0" rowsep="0" cols="3"><colspec colname="1" colwidth="77pt" align="left" /><colspec colname="2" colwidth="77pt" align="left" /><colspec colname="3" colwidth="105pt" align="left" /><thead><row><entry namest="1" nameend="3" rowsep="1">TABLE 1</entry></row><row><entry namest="1" nameend="3" align="center" rowsep="1" /></row><row><entry>Operator/Parameter</entry><entry>Description</entry><entry>Values/Options</entry></row><row><entry namest="1" nameend="3" align="center" rowsep="1" /></row></thead><tbody valign="top"><row><entry><level></entry><entry>The anomaly level of</entry><entry>H—High</entry></row><row><entry /><entry>signal</entry><entry>M—Med</entry></row><row><entry /><entry /><entry>L—Low</entry></row><row><entry><signal type></entry><entry>A type of the generated</entry><entry>SoA—Score of Anomaly</entry></row><row><entry /><entry>signals</entry><entry>Rep.—Reputation score</entry></row><row><entry /><entry /><entry>AV Alert—AV attack</entry></row><row><entry /><entry /><entry>IPS Alert—Intrusion attack</entry></row><row><entry /><entry /><entry>Sandbox Alert—Sandbox attack</entry></row><row><entry><Signal attribute></entry><entry>A structure of optional</entry><entry>Src ID—Host name, Hosts group,</entry></row><row><entry /><entry>meta data attributes</entry><entry>IP address User name</entry></row><row><entry /><entry>associated with the</entry><entry>Src risk—High, Med, Low that</entry></row><row><entry /><entry>signal that can be set.</entry><entry>represents a level of risk</entry></row><row><entry /><entry /><entry>associated with the source ID.</entry></row><row><entry /><entry /><entry>Dst ID—Same as Src</entry></row><row><entry /><entry /><entry>Dst risk,—Same as Src risk</entry></row><row><entry /><entry /><entry>Prot—L4 protocol</entry></row><row><entry /><entry /><entry>L7 prot—L7 protocol name</entry></row><row><entry /><entry /><entry>Dport—L4 port number</entry></row><row><entry /><entry /><entry>Application—Application name</entry></row><row><entry><Condition type></entry><entry>Types of conditions that</entry><entry>Period</entry></row><row><entry /><entry>can be selected in the</entry><entry>Occurrences</entry></row><row><entry /><entry>rule</entry></row><row><entry><operator condition></entry><entry>Logical conditions</entry><entry>>, =>, =, <=</entry></row><row><entry><units></entry><entry>The threshold that the</entry><entry>Time units</entry></row><row><entry /><entry>user sets according to</entry><entry>Occurrences units</entry></row><row><entry /><entry>the condition type that</entry></row><row><entry /><entry>was selected</entry></row><row><entry><2<sup>nd </sup>condition type></entry><entry>2<sup>nd </sup>condition type that</entry><entry>In-period</entry></row><row><entry /><entry>can be selected in the in</entry><entry>Unlimited</entry></row><row><entry /><entry>the rule</entry></row><row><entry><“event name”></entry><entry>The name of the event</entry><entry>User defined text</entry></row><row><entry /><entry>that will be triggered.</entry></row><row><entry /><entry>The system generates a</entry></row><row><entry /><entry>unique event ID as well.</entry></row><row><entry namest="1" nameend="3" align="center" rowsep="1" /></row></tbody></tgroup></table></tables>
0088For example, <figref idref="DRAWINGS">FIG. 6</figref> shows a security signal derived from a SoA value. The security signal is in a form of a pulse. In this example, the event rules <b>542</b> define that if the pulse is high (high SoA) for a duration of more than the 25 seconds, then a security event is triggered. An example for an event rule for detecting network scan is: <ul id="ul0001" list-style="none"><li id="ul0001-0001" num="0000"><ul id="ul0002" list-style="none"><li id="ul0002-0001" num="0089">If <H>SoA=>1 m, then event <auto probe></li></ul></li></ul>
0090The rule identifies that if the value of the SoA is high for a duration of at least 1 minute, then an event is triggered. For example in this case the event represents a scan activity, which is part of a pre-attack probe activities.
0091Referring back to <figref idref="DRAWINGS">FIG. 5</figref>, security events generated from signals received only from services <b>510</b> and <b>520</b> are shown. That is, signals from service <b>530</b> did not match any event rule <b>542</b>. The security events are correlated by the application <b>540</b> using the correlation rules <b>544</b>. As noted above, events that satisfy at least one correlation rule <b>544</b> will trigger an action, such as, but not limited to, a mitigation action, an investigation action, and so on.
0092As an example, a correlation rule <b>544</b> can correlate between a reputation event and a host anomaly event. In an embodiment, correlation rules <b>544</b> can be defined for the different phases of the operation of the system security application <b>211</b>, i.e., detection phase, investigation phase, and a mitigation phase.
0093The operation of the security services discussed above can be utilized during the detection phase, investigation phase and mitigation phase of the APT security application. The detection phase can be concluded upon a determination that a potential attack is taken place. Such detection in achieved once a detection correlation rule <b>544</b> is satisfied.
0094The investigation phase may be activated in order to validate (or de-validate) and better define the attack behavior. This phase is typically a more advanced detection phase that narrows down the scope of suspicious hosts and identifies more specific traffic flows associated with the anomaly from and to these hosts. Thus, the investigation phase can be utilized to reduce the false positive event rate into a level that allows accurate mitigation of the threat, filter out unnecessary logs, and to evaluate the potential impact of the security incident. Further, the investigation phase allows for making an educated decision about the level of mitigation operations.
0095The operation of investigation phase may be performed by the various security services described above. Specifically, the following security services can be utilized during the investigation phase. The attack signature security service <b>221</b>-<b>5</b>, the reputation security service <b>221</b>-<b>3</b>, the sandbox security service <b>221</b>-<b>2</b>, the Anti-Virus (AV) service <b>221</b>-<b>8</b>, and the user challenge/response security service <b>221</b>-<b>6</b> which can be also used in the mitigation phase.
0096The following describes the operation of the cyber security system <b>100</b> to detect an APT campaign that was result with a breach occurred in a retail chain. In this case, during the APT attack confidential information of customers is targeted (e.g., credit cards, passwords, identities, and social security numbers). The following is a discussion of the APT attack lifecycle and implementations of the disclosed APT security applications and engines to prevent such an attack.
0097In <figref idref="DRAWINGS">FIG. 7</figref> the first stage of the attack is illustrated. In this stage, an intrusion is performed into a retail store's network <b>710</b>. The retail store's network <b>170</b> is the first point from which the entire attack campaign is conducted.
0098The attack begins with an intrusion into one of the retail store's external contractors <b>720</b>. The attacker uses the Citadel malware through the use of a phishing email campaign. This malware is designed to steal personal information and credentials through man in the browser (MitB) techniques. In this example, the malware is used in order to steal web application credentials within an infected machine browser of the external (HVAC) contractor <b>720</b> of the retail store.
0099<figref idref="DRAWINGS">FIG. 8</figref> refers to the intrusion second stage of the attack during which a retail store web services intrusion has occurred. The attacker uses the contractor's stolen credentials to gain access into the retail store's web hosted web services <b>730</b>. These web services <b>730</b> are dedicated to the retail store's partners. In this case, the contractor <b>720</b> is a partner having access to some electronic billing, contracting submission, and project management services.
0100The attacker uses the stolen credentials in order to gain access from the Internet into the web services <b>730</b> and then exploit web service vulnerabilities. Such vulnerabilities allow the attacker to execute code (scripts) on the retail store's web applications. This operation allows the attacker to executable OS commands of the web service host.
0101This can be summarized as the intrusion stage, in which the attacker gains credentials and access to certain levels of the retail store's hosts. It should be noted that until this step, the only unusual activity (from the retail store network perspective) is an upload of an executable file into the retail store's web services <b>730</b>. These web services <b>730</b> are typically supposed to receive only forms, at least from certain partners.
0102The intrusion stage can be detected by the UNABA security service <b>221</b>-<b>1</b> and WAF security service <b>221</b>-<b>9</b>. The UNABA security service <b>221</b>-<b>1</b> would detect unusual upload behavior to web services and the security application <b>211</b> would correlate that with WAF logs provided by the WAF security service <b>221</b>-<b>9</b> that indicate possible “injection”/“web intrusion” activity. The UNABA security service <b>221</b>-<b>1</b> would include a profile of each partner (e.g., contractor) with access to the retail store's network <b>710</b>. Abnormal upload activity would be detected based on data symmetry parameters, the source geographical location, and activity time (as an example, others parameters may use). The UNABA security service <b>221</b>-<b>1</b> would operate on data collected, for example, by DPIs connected at edge routers of the retail store's network <b>710</b>. The security application <b>211</b> can include a correlation rule that correlates between triggered events, such as abnormal user activity of certain type (e.g., the abnormal upload activity) and a WAF log of certain type that represent a code injection.
0103<figref idref="DRAWINGS">FIG. 9</figref> refers to intelligence gathering and the identification of targets by the APT attacker. Once the attacker can run operating system commands on a host of the web services, the attacker can start generating intelligence gathering operations (also known as “pre-attack probes”). These operations, which can be done manually or automatically through attack tools, allow the attacker to gather information about the retail store's network <b>710</b>, and thus find the relevant targets for the next steps in the attack life cycle.
0104Targets in the retail store are services that maintain credit cards and/or social security numbers information. Such services can include databases <b>770</b> and point of sales machines <b>760</b>. Once the attacker identifies the services' names that may maintain credit cards information, and the likes, the attacker queries the DNS <b>750</b> to retrieve the IP addresses of such servers (again, this can be done automatically or manually).
0105The UNABA security service <b>221</b>-<b>1</b> can detect the gathering of information by identifying unexpected hosts' traffic activities and anomaly protocol usage (e.g., abnormal LDAP query rates per host, abnormal DNS resolve rates per host, abnormal amount and rate of protocol error response per host and server, new and unexpected application flows that are generated by the host), Such anomalies can be detected by the security decision engines executed by the UNABA security service <b>221</b>-<b>1</b>. The SDEs can be dynamically programmed by a set of engine rules.
0106<figref idref="DRAWINGS">FIG. 10</figref> describes the stage of installing processes. After finding the PoS service names <b>760</b> and DB service names <b>770</b>, the attacker needs to propagate processes into the network elements that can access these services and then take control and install other processes that can steal and send out the credit cards information. In order to propagate and install processes in the retail store's network <b>710</b>, the attacker operates to get hold of the domain administrative privileges (e.g., within a Microsoft® network) using “pass-the-hash” attack techniques. The pass-the-hash attack allows the attacker to steal a token that resides inside the hosts' memory (that an administrator has used), which represents the password of the administrator (called NT hash). Using the stolen NT hash, the attacker creates an active directory (AD) <b>740</b> new user accounts with administrator privileges.
0107Now, the attacker has privileges to access and install processes on different network elements. At this stage, in order to find the target IPs in the network <b>710</b> and identify security defenses such as firewalls, intrusion prevention system, and so on that are protecting them, the attacker uses network scanners such as “Angry IP Scanner”, NMAP, and the likes. A scanner is used in order to find which computers are accessible from the current web servers.
0108In order to bypass detected firewalls rules that block access to some network element or server, the attacker utilizes tools that can tunnel through the firewalls (e.g., port forwarding IT tools that utilize traffic encapsulation techniques, etc.) and then executes new processes on the target hosts, or on hosts that can access these targets.
0109To detect such network scanning activity, the UNABA security service <b>221</b>-<b>1</b> would detect abnormal wide connection distribution with abnormal portion of connection that are non-complete (in this attack case, all are originated by the compromised web services hosts. In addition, an anti-virus security service <b>221</b>-<b>8</b> can be activated (by the security application) to scan the web services hosts and look for evidence of installed scanning tools. According to the disclosed embodiments, the security application <b>211</b> correlates events that are triggered due to network scanning activities from 221-1 and events from the anti-virus detection services.
0110<figref idref="DRAWINGS">FIG. 11</figref> describes the penetration and control stage. At this stage the attacker installs new processes on the target servers hosts or hosts that have access to these targets. With this aim, the attacker can use different types of remote desktop, processes execution tools, and the administrator credentials, remote desktop tools (e.g., a RDP and a PsExec). Using these remote tools and administrator credentials, the attacker is able to run scripts on the DB services <b>770</b> and install malware on the PoS servers <b>760</b>.
0111For collecting the credit cards and personal information (such as social security numbers) from the target services, the attacker uses MS SQL query tools. In order to search and steal information from the PoS machines <b>760</b> directly, the attacker uses the ‘kaptoxa’ malware on all PoS machines <b>760</b>. The attacker installs the malware using the tools mentioned herein above. The malware scans (scrapes) the memory of the PoS <b>760</b> and when the malware identifies a credit card pattern it opens a communication socket and sends the credit card pattern to an internal drop zone. It should be noted that in the case of the PoS machine <b>760</b>, the malware must quickly send the credit card information before such information is removed from the RAM of the PoS. As long as the information resides in the RAM it is usually in its un-encrypted form, therefore sending it directly from the RAM insures easy visibility into the card numbers.
0112To detect such malicious activity, the UNABA security service <b>221</b>-<b>1</b> is configured to identify unusual usage of remote-desktop and remote process execution tools, such as Telnet, RDP, VNC, PuTTY, in the network <b>110</b>. SDEs in the UNABA security service <b>221</b>-<b>1</b> identify activities, such as hosts that are generating traffic associated with such tools to destination hosts. In a normal network behavior, such hosts typically do not communicate with remote desktop applications. The SDEs can also identify, for example, if the usage pattern of these remote-desktop or application deviates from the usual pattern.
0113In addition, based on the signals received from the UNABA security service <b>221</b>-<b>1</b>, the security application <b>211</b> can instruct the anti-virus security service <b>221</b>-<b>8</b> to scan the target hosts of which the detected remote-desktop and remote processes tools are communicating with (e.g., PoS and DB services hosts) and to search for malware related evidences (e.g., PoS related malware such as the Kaptoxa malware). The security application <b>211</b> correlates (according to the correlation and workflow rules) the security events from received from the security services <b>221</b>-<b>1</b> and <b>221</b>-<b>9</b> in order to decide about the next actions.
0114<figref idref="DRAWINGS">FIG. 12</figref> refers to the collecting stolen information stage. At this stage the attacker creates a file share service <b>780</b> on a remote server inside the target network (this is typically done also by a remote desktop application that the attacker will use with its credential to enable services). The malware, on PoS <b>760</b>, scrapes the RAM memory of the host, identifies credit-cards' number patterns and send these numbers to file share server using the SMB protocols (this last activity is defined as an internal drop zone activity).
0115To detect such malicious activity, the UNABA security service <b>221</b>-<b>1</b> would identify the abnormal remote desktop that enables the file share service, as well as the internal drop zone activity.
0116In addition, the UNABA security service <b>221</b>-<b>1</b> identifies the internal drop zone activity by a SDE that analyzes the connection distribution, the L7 protocol distribution, as well as the traffic symmetry. In the case of drop zone, an abnormal narrow connection distribution (multiple hosts that communicate with a single host), with an abnormal narrow L7 protocol distribution (abnormal common protocol), as well as abnormal upload traffic symmetry would result with high SoA generated by this SDE.
0117<figref idref="DRAWINGS">FIG. 13</figref> refers to the stage of sending out stolen credit cards' information. Once such information arrives to the file share server, which is also an FTP enabled machine <b>780</b>, a script on the machine sends the file to the attacker's controlled FTP account (an external host), using an internal FTP client.
0118To detect such malicious activity, the UNABA and reputation security services <b>221</b>-<b>1</b> and <b>221</b>-<b>3</b> are utilized. The UNABA security service <b>221</b>-<b>1</b> would identify the unusual source and destination with an upload behavior activity, periodic upload behavior during unusual hours of operation, and a source with a new protocol usage (not limited by these parameters). Then the security application <b>211</b> will instruct the reputation security service <b>221</b>-<b>3</b> to provide intelligence information about the external destination IP address. The security application <b>211</b> correlates the signals from the security services <b>221</b>-<b>1</b> and <b>221</b>-<b>3</b> generate an action according to the correlation and workflow rules (e.g., in case the external IP has high bad reputation score, which is associated with known public drop points then the action will be to block this traffic through the mitigation phase services).
0119The various embodiments disclosed herein can be implemented as hardware, firmware, software, or any combination thereof. Moreover, the software is preferably implemented as an application program tangibly embodied on a program storage unit or non-transitory computer readable medium consisting of parts, or of certain devices and/or a combination of devices. The application program may be uploaded to, and executed by, a machine comprising any suitable architecture. Preferably, the machine is implemented on a computer platform having hardware such as one or more central processing units (“CPUs”), a memory, and input/output interfaces. The computer platform may also include an operating system and microinstruction code. The various processes and functions described herein may be either part of the microinstruction code or part of the application program, or any combination thereof, which may be executed by a CPU, whether or not such a computer or processor is explicitly shown. In addition, various other peripheral units may be connected to the computer platform such as an additional data storage unit and a printing unit. Furthermore, a non-transitory computer readable medium is any computer readable medium except for a transitory propagating signal.
0120It should be understood that any reference to an element herein using a designation such as “first,” “second,” and so forth does not generally limit the quantity or order of those elements. Rather, these designations are generally used herein as a convenient method of distinguishing between two or more elements or instances of an element. Thus, a reference to first and second elements does not mean that only two elements may be employed there or that the first element must precede the second element in some manner. Also, unless stated otherwise a set of elements comprises one or more elements. In addition, terminology of the form “at least one of A, B, or C” or “one or more of A, B, or C” or “at least one of the group consisting of A, B, and C” or “at least one of A, B, and C” used in the description or the claims means “A or B or C or any combination of these elements.” For example, this terminology may include A, or B, or C, or A and B, or A and C, or A and B and C, or <b>2</b>A, or <b>2</b>B, or <b>2</b>C, and so on.
0121All examples and conditional language recited herein are intended for pedagogical purposes to aid the reader in understanding the principles of the disclosed embodiments and the concepts contributed by the inventor to furthering the art, and are to be construed as being without limitation to such specifically recited examples and conditions. Moreover, all statements herein reciting principles, aspects, and embodiments of the disclosure, as well as specific examples thereof, are intended to encompass both structural and functional equivalents thereof. Additionally, it is intended that such equivalents include both currently known equivalents as well as equivalents developed in the future, i.e., any elements developed that perform the same function, regardless of structure.
Contents6
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US12238125B2 | Cited by | United States of America | Search report |
| US10608990B2 | Cited by | United States of America | Search report |
| US10530794B2 | Cited by | United States of America | Applicant |
| US11799784B2 | Cited by | United States of America | Applicant |
| US11539633B2 | Cited by | United States of America | Search report |
| US11483375B2 | Cited by | United States of America | Search report |
| US11574071B2 | Cited by | United States of America | Applicant |
| US11748331B2 | Cited by | United States of America | Applicant |
| US12093375B2 | Cited by | United States of America | Applicant |
| US11558409B2 | Cited by | United States of America | Applicant |
| US10534907B2 | Cited by | United States of America | Applicant |
| US10574672B2 | Cited by | United States of America | Search report |
| US12316666B2 | Cited by | United States of America | Applicant |
| US11556637B2 | Cited by | United States of America | Applicant |
| US10938851B2 | Cited by | United States of America | Search report |
| US11599395B2 | Cited by | United States of America | Applicant |
| US11483246B2 | Cited by | United States of America | Applicant |
| US11032304B2 | Cited by | United States of America | Applicant |
| US10536476B2 | Cited by | United States of America | Search report |
| US2023171292A1 | Cited by | United States of America | Search report |
| US10482241B2 | Cited by | United States of America | Applicant |
| US10623425B2 | Cited by | United States of America | Search report |
| US10601853B2 | Cited by | United States of America | Applicant |
| US10523715B1 | Cited by | United States of America | Search report |
| US11283832B2 | Cited by | United States of America | Applicant |
| US11438360B2 | Cited by | United States of America | Applicant |
| US2025112923A1 | Cited by | United States of America | Search report |
| US12547737B1 | Cited by | United States of America | Search report |
| US12348519B1 | Cited by | United States of America | Applicant |
| US10530792B2 | Cited by | United States of America | Applicant |
| CN112242991A | Cited by | China | Search report |
| US10552605B2 | Cited by | United States of America | Applicant |
| US11431676B2 | Cited by | United States of America | Search report |
| US2019306188A1 | Cited by | United States of America | Search report |
| US10534908B2 | Cited by | United States of America | Applicant |
| US10986111B2 | Cited by | United States of America | Applicant |
| US12095668B2 | Cited by | United States of America | Applicant |
| WO2021217239A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US2022070102A1 | Cited by | United States of America | Search report |
| US12192109B2 | Cited by | United States of America | Applicant |
| US12603921B1 | Cited by | United States of America | Applicant |
| US2019121886A1 | Cited by | United States of America | Search report |
| US9912692B1 | Cited by | United States of America | Search report |
| CN111083114A | Cited by | China | Search report |
| US10631168B2 | Cited by | United States of America | Search report |
| US12212595B2 | Cited by | United States of America | Applicant |
| US2018007068A1 | Cited by | United States of America | Search report |
| US12235830B2 | Cited by | United States of America | Applicant |
| US12120032B2 | Cited by | United States of America | Applicant |
| US11461458B2 | Cited by | United States of America | Applicant |
| US12041117B2 | Cited by | United States of America | Search report |
| US11184382B2 | Cited by | United States of America | Search report |
| US11012465B2 | Cited by | United States of America | Applicant |
| US2018176238A1 | Cited by | United States of America | Applicant |
| US11470094B2 | Cited by | United States of America | Applicant |
| US10542016B2 | Cited by | United States of America | Applicant |
| US10193919B2 | Cited by | United States of America | Search report |
| US10783138B2 | Cited by | United States of America | Search report |
| US10673879B2 | Cited by | United States of America | Applicant |
| US10771495B2 | Cited by | United States of America | Applicant |
| US12670246B2 | Cited by | United States of America | Applicant |
| US12355770B2 | Cited by | United States of America | Search report |
| US10630705B2 | Cited by | United States of America | Applicant |
| US10681064B2 | Cited by | United States of America | Applicant |
| US11093608B2 | Cited by | United States of America | Applicant |
| US2015249676A1 | Cited by | United States of America | Pre-grant |
| US11128651B2 | Cited by | United States of America | Applicant |
| US12596793B2 | Cited by | United States of America | Applicant |
| US12423418B1 | Cited by | United States of America | Applicant |
| US10162970B2 | Cited by | United States of America | Search report |
| US9516050B2 | Cited by | United States of America | Search report |
| US11399021B2 | Cited by | United States of America | Applicant |
| US12432242B1 | Cited by | United States of America | Applicant |
| US12328337B2 | Cited by | United States of America | Search report |
| US10764306B2 | Cited by | United States of America | Applicant |
| US12634345B2 | Cited by | United States of America | Search report |
| US2015128274A1 | Cites | United States of America | Pre-grant |
| US9628507B2 | Cites | United States of America | Pre-grant |
15 members in 4 offices
Members15
| Document | Office | Kind | |
|---|---|---|---|
| US2016021056A1 | United States of America | A1 | |
| US2016021135A1 | United States of America | A1 | |
| WO2016010806A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2016057166A1 | United States of America | A1 | |
| US2016078236A1 | United States of America | A1 | |
| WO2016089567A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US9565204B2 | United States of America | B2 | |
| CN106537406A | China | A | |
| US2017111396A1 | United States of America | A1 | |
| EP3170121A1 | European Patent Office (EPO) | A1 | |
| EP3170121A4 | European Patent Office (EPO) | A4 | |
| US9892270B2 | United States of America | B2 | |
| US9967279B2 | United States of America | B2 | |
| US9979753B2 | United States of America | B2 | |
| US11115437B2 | United States of America | B2 |
132 transactions on the USPTO file
Allowed after 2 non-final rejections, 2 final rejections, 1 RCE and 1 appeal.
- Non-final rejections
- 2
- Final rejections
- 2
- RCEs
- 1
- Appeals
- 1
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Entity Status Set To Undiscounted (Initial Default Setting or Status Change)BIG. | BIG. | |
| Payment of Maintenance Fee, 4th Yr, Small EntityM2551 | M2551 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Email NotificationEML_NTR | EML_NTR | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Email NotificationEML_NTR | EML_NTR | |
| Email NotificationEML_NTR | EML_NTR | |
| Filing Receipt - CorrectedFLRCPT.C | FLRCPT.C | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Correspondence Address ChangeC.AD | C.AD | |
| Miscellaneous Incoming LetterLET. | LET. | |
| Printer Rush- No mailingTCPB | TCPB | |
| Printer Rush- No mailingTCPB | TCPB | |
| Printer Rush- No mailingTCPB | TCPB | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Reasons for AllowanceEX.R | EX.R | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Amendment/Argument after PTAB DecisionBD.A | BD.A | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail PTAB Decision on Appeal - Affirmed in PartMAPDP | MAPDP | |
| PTAB Decision - Examiner Affirmed in PartAPDP | APDP | |
| Email NotificationEML_NTR | EML_NTR | |
| Docketing Notice Mailed to AppellantAP_DK_M | AP_DK_M | |
| Assignment of Appeal NumberAPAS | APAS | |
| Appeal Awaiting PTAB DocketingAPWD | APWD | |
| Appeal ready for PAC reviewARBP | ARBP | |
| Reply Brief FiledAPRB | APRB | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Examiner's AnswerMAPEA | MAPEA | |
| Exam. Ans. Review CompletePACC | PACC | |
| Examiner's Answer to Appeal BriefAPEA | APEA | |
| Appeal Brief Review CompleteAPBR | APBR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| track 1 OFFT1OFF | T1OFF | |
| Appeal Brief FiledAP.B | AP.B | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Notice of Appeal FiledN/AP | N/AP | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Response after Non-Final ActionA... | A... | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Email NotificationEML_NTF | EML_NTF | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF |
21 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| AssignmentAS | AS | |
| Fee payment procedureENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: BIG.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| Information on status: patent application and granting procedure in generalPUBLICATIONS -- ISSUE FEE PAYMENT VERIFIEDSTPP | STPP | |
| AssignmentAS | AS | |
| Information on status: patent application and granting procedure in generalNOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONSSTPP | STPP | |
| Information on status: patent application and granting procedure in generalAWAITING TC RESP., ISSUE FEE NOT PAIDSTPP | STPP | |
| Information on status: patent application and granting procedure in generalNOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONSSTPP | STPP | |
| Information on status: patent application and granting procedure in generalAMENDMENT / ARGUMENT AFTER BOARD OF APPEALS DECISIONSTPP | STPP | |
| Information on status: appeal procedureAppealBOARD OF APPEALS DECISION RENDEREDSTCV | STCV | |
| Information on status: appeal procedureAppealON APPEAL -- AWAITING DECISION BY THE BOARD OF APPEALSSTCV | STCV | |
| Information on status: appeal procedureAppealEXAMINER'S ANSWER TO APPEAL BRIEF MAILEDSTCV | STCV | |
| AssignmentAS | AS |
Numbers
- Publication
- 20160057166
- Application
- 14799954
Titles
- English
- CYBER-SECURITY SYSTEM AND METHODS THEREOF FOR DETECTING AND MITIGATING ADVANCED PERSISTENT THREATS
Patent term adjustment
- A delay
- +8 daysthe office missed an examination deadline
- C delay
- +625 daysinterference, secrecy order or appeal
- Applicant delay
- −273 days
- Net adjustment
- 360 days
Classification
- CPC, 9
- H04L63/1441
- H04L63/145
- H04L63/20
- H04L63/14
- G06F21/552
- G06F21/56
- H04L63/1483
- H04L63/02
- H04L63/1416
- IPC, 1
- H04L29 06
- USPC, 2
- 726023000
- 726022000