×

Apparatus method and medium for tracing the origin of network transmissions using N-gram distribution of data

  • US 9,003,528 B2
  • Filed: 07/17/2012
  • Issued: 04/07/2015
  • Est. Priority Date: 11/12/2003
  • Status: Active Grant
First Claim
Patent Images

1. A method of tracing the location of an origin computer system that initially transmits a suspect data payload across a computer network to an end target computer system, the method comprising:

  • creating, using a hardware processor, a connection record for a transmission to a first computer system through the computer network of a plurality of computer systems;

    generating, using the hardware processor, a byte value statistical distribution of data contained in a data payload corresponding to the connection record;

    calculating, using the hardware processor, a distance between the byte value statistical distribution of data contained in the data payload and a model distribution representative of normal payloads transmitted through the computer network;

    identifying, using the hardware processor, the data payload as a suspect data payload based on the calculated distance;

    setting, using the hardware processor, the first computer system as a suspect computer system;

    upon determining at least one byte value statistical distribution that is similar to the byte value statistical distribution of the data contained in the suspect data payload, determining, using the hardware processor, address information associated with the at least one byte value statistical distribution; and

    setting, using the hardware processor, a second computer system associated with the address information as the suspect computer system.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×