Invention Grant
- Patent Title: Port scan detection using destination profiles
-
Application No.: US17464709Application Date: 2021-09-02
-
Publication No.: US11770396B2Publication Date: 2023-09-26
- Inventor: Yinnon Meshi , Idan Amit , Jonathan Allon , Aviad Meyer
- Applicant: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
- Applicant Address: IL Tel Aviv
- Assignee: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
- Current Assignee: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
- Current Assignee Address: IL Tel Aviv
- Agency: KLIGLER & ASSOCIATES PATENT ATTORNEYS LTD
- Main IPC: H04L9/40
- IPC: H04L9/40

Abstract:
A method, including identifying, in network data traffic, a set of pairs of source and destination nodes, each pair having a given source node, a given destination node, and one or more ports accessed in the traffic between the nodes in each pair, and computing, for each pair, a respective baseline that indicates a first number of the ports that source nodes other than the given source node in the pair accessed on the given destination node during a first period. For each pair, a respective test score is computed that indicates a difference between a second number of the ports that the given source node in the pair accessed on the given destination node during a second period and the baseline, and a preventive action is initiated with respect to the given source node in any of the pairs for which the test score is greater than a threshold.
Public/Granted literature
- US20210400072A1 Port scan detection using destination profiles Public/Granted day:2021-12-23
Information query