Communicating network flow data using a network protocol
By defining new Ethernet types in network communication and embedding PIDs, the problem of insufficient correlation capabilities of event logs and network traffic data in the prior art is solved, process-level correlation capabilities are realized, and the efficiency of security monitoring and event management is improved.
Patent Information
- Application Number
- JP2023534683
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-12-16
- Filing Date
- 2021-11-16
- Publication Date
- 2025-06-18
- Estimated Expiration
- 2041-11-16
AI Technical Summary
The prior art is difficult to effectively associate process identifiers (PIDs) and network traffic data in event logs in network communications, resulting in a lack of process-level correlation capabilities in security monitoring and event management.
By defining a new Ethernet type and embedding process identifiers (PIDs) during communication, network communication is carried out at a specific level of abstraction, thereby carrying PIDs in the network package header, realizing the association between PIDs and network traffic data.
It realizes the direct correlation between PID and network traffic data in event logs in network communication, improves the process-level correlation capabilities of security monitoring and event management, and reduces the performance losses caused by high-traffic data processing in the prior art.
Smart Images

Figure 0007695026000001 
Figure 0007695026000002 
Figure 0007695026000003
Abstract
Description
Technical Field
[0001] The present invention generally relates to the field of computer networks, and more particularly to networking data sources.
Background Art
[0002] The Wikipedia article "Abstraction layer" (as of November 16, 2020) states the following: "In computing, an abstraction layer or level of abstraction is a way of hiding the working details of a subsystem and enabling a separation of concerns to promote interoperability and platform independence. Examples of software models that use an abstraction layer include the OSI model for network protocols, OpenGL, and other graphics libraries. In computer science, an abstraction layer is a generalization of a conceptual model or algorithm away from a particular possible implementation. These generalizations arise from broad similarities that are best encapsulated by models that represent the similarities present in various specific implementations. The simplification provided by a good abstraction layer enables useful concepts or design patterns to be easily reused by extraction, and thus the situations in which it can be accurately applied can be quickly recognized. If one layer depends on another layer, that layer is considered to be above the other layer. All layers can exist without a layer above them and require a layer below them to function. Often, abstraction layers can be structured into a hierarchy of levels of abstraction. The OSI model has seven abstraction layers. Each layer of the model encapsulates and addresses different parts of the needs of digital communication, thereby reducing the complexity of the associated engineering solutions."
[0003] The "Open Systems Interconnection Protocol" on Wikipedia (as of November 16, 2020) states the following: "The Open Systems Interconnection Protocol is a family of information exchange standards jointly developed by ISO and ITU-T.... The OSI protocol stack consists of seven conceptual layers. These layers form a hierarchy of functions starting from physical hardware components and reaching up to the user interface at the software application level. Each layer receives information from the layer above, processes it, and then passes it to the next layer. Each layer adds encapsulated information (headers) to the incoming information before passing it to the lower layer. Headers generally include source and destination addresses, error control information, protocol identification, and protocol parameters, such as flow control options and sequence numbers. Layer 1: Physical Layer This layer deals only with physical plugs and sockets and the electrical specifications of signals. This is the medium through which digital signals are transmitted. It can be used with twisted pair, coaxial cable, fiber optic, wireless, or other transmission media. Layer 2: Data Link Layer The data link layer packages the raw bits from the physical layer into frames (logical, structured packets of data).... This layer serves to transfer frames from one host to another. It can perform error checking.... Layer 3: Network Layer... This level is responsible for transferring data between systems within a network using the network layer address of the machine to track the destination and the source. This layer uses routers and switches to manage its traffic (control of control flow, error checking, routing, etc.). Thus, all routing decisions are made here to handle end-to-end data transmission. Layer 4: Transport Layer The transport layer transmits data between the source process and the destination process. Generally, two connection modes, namely, connection-oriented or connectionless, are recognized.... Layer 5: Session Layer... The session layer controls the dialogue (connection) between computers.It establishes, manages, and terminates connections between local and remote applications. It provides full-duplex, and half-duplex or simplex operation, and establishes checkpointing, deferral, termination, and resume procedures.... Layer 6: Presentation Layer This layer defines the data types of the application layer and encrypts / decrypts them. Protocols, such as MIDI, MPEG, and GIF, are presentation layer formats shared by various applications. Layer 7: Application Layer... This enables tracking of how each application communicates with another application. The destination address and the source address are linked to a specific application.
[0004] The "EtherType" (sometimes denoted as "ethertype") on Wikipedia (as of November 16, 2020) states the following: "The EtherType is a 2-octet field in an Ethernet frame. It is used to indicate which protocol is encapsulated in the payload of the frame and, at the receiving side, to determine how the payload is to be processed by the data link layer. The same field is also used to indicate the size of some Ethernet frames. The EtherType is also used as the basis for 802.1Q VLAN tagging, encapsulating packets from a VLAN for transmission multiplexed with other VLAN traffic on an Ethernet trunk.... The Ethernet frame contains an EtherType field. Each lower-order slot specifies 1 octet. The EtherType is 2 octets long. In the most recent implementations of Ethernet, the field within the Ethernet frame used to describe the EtherType can also be used to represent the size of the payload of the Ethernet frame.... With the emergence of the IEEE 802 standards, for IEEE 802 networks other than Ethernet, as well as non-IEEE networks that use an IEEE 802.2 LLC header, such as FDDI, a Subnetwork Access Protocol (SNAP) header combined with the IEEE 802.2 LLC header is used to convey the EtherType of the payload. However, in the case of Ethernet, Ethernet II framing is still used...." (Footnotes are omitted).
[0005] Wikipedia's "protocol stack" (as of November 16, 2020) states the following: "A protocol stack or network stack is an implementation of a computer networking protocol suite or protocol family. Although some of these terms are used interchangeably, strictly speaking, the suite is the definition of communication protocols, and the stack is their software implementation.... Individual protocols within a suite are often designed with a single purpose in mind. This modularity simplifies design and evaluation. Each protocol module typically communicates with two other protocols and is thus commonly envisioned as a layer in a protocol stack. The lowest protocol always deals with the low-level interaction with the communication hardware. Each higher layer adds an accumulative function. User applications typically deal with only the topmost layer.... In actual implementations, the protocol stack is often divided into the following three main sections: media, transport, and application. A particular operating system or platform often has two clearly defined software interfaces: one between the media layer and the transport layer, and another between the transport layer and the application. The interface between the media and the transport defines how the transport protocol software utilizes a particular media and hardware type and is associated with the device driver.... Exemplary protocol stack and corresponding layers[:] Protocol layer HTTP application TCP transport IP internet or network Ethernet link or data link IEEE 802.3ab physical" (footnotes omitted). SUMMARY OF THE INVENTION MEANS FOR SOLVING THE PROBLEM
[0006] According to one aspect of the present invention, there is provided a method, computer program product, system, or combination thereof for performing the following operations (not necessarily in the following order): (i) defining a new Ethernet type to be used when communicating a PID (Process Identification Code), where the new Ethernet type is assigned a new Ethernet type code; (ii) determining a selected abstraction layer from a plurality of abstraction layers to be used when communicating the PID; and (iii) performing a plurality of network communications between two or more computers of a networked computer system using each communication, where performing each given communication includes (a) inserting the new Ethernet type code and the PID of the process that causes the given communication into a data structure, and (b) communicating the data structure between a plurality of computers of the networked computer system in the selected abstraction layer.
Brief Description of the Drawings
[0007]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Mode for Carrying Out the Invention
[0008] The detailed description of the present invention is divided into the following four subsections: I. Hardware and software environment, II. Exemplary embodiments, III. Further comments or embodiments or combinations thereof, and IV. Definitions.
[0009] I. Hardware and software environment
[0010] The present invention can be a system, method, computer program product, or a combination thereof. The computer program product can include one or more computer-readable storage media having thereon computer-readable program instructions for causing a processor to execute aspects of the present invention.
[0011] The computer-readable storage media can be a tangible device that can hold and store instructions for use by an instruction execution device. The computer-readable storage media can be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer-readable storage media includes: portable computer diskette (登録商標), a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disc read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, punch card, or a mechanically encoded device such as a raised structure in a groove having instructions recorded thereon, and any suitable combination thereof. As used herein, a computer-readable storage medium should not be construed to be a transient signal per se, such as, for example, a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through an optical fiber cable), or an electrical signal transmitted through a wire.
[0012] As used herein, a "storage device" is defined as something made or adapted to store computer code in a manner that the computer code can be accessed by a computer processor. A storage device typically includes a storage medium that is the material in which or on which data of the computer code is stored. The term "storage medium" should be construed to cover situations in which a plurality of different types of storage media are used.
[0013] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to respective computing devices / processing devices, or to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network can be composed of copper wire transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. A network adapter card or network interface in each computing device / processing device receives the computer-readable program instructions from the network and transmits the computer-readable program instructions for storage in a computer-readable storage medium within the individual computing devices / processing devices.
[0014] The computer-readable program instructions for carrying out the operation of the present invention can be any combination of assembly instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or source code or object code written in any combination of one or more programming languages, such as object-oriented programming languages, such as Smalltalk, C++, etc., conventional procedural programming languages (e.g., the "C" programming language or similar programming languages). The computer-readable program instructions can be executed entirely on the user's computer, partially on the user's computer, partially as a stand-alone software package on the user's computer, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer via any type of network, such as a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, an electronic circuit, such as a programmable logic circuit, a field-programmable gate array (FPGA) or a programmable logic array (PLA), can execute the computer-readable program instructions by utilizing the state information of the computer-readable program instructions, by personalizing the electronic circuit.
[0015] Aspects of the invention are described herein with reference to methods, apparatus (systems), and computer program products or flowcharts or block diagrams or combinations thereof according to embodiments of the invention. It will be understood that each block of the flowchart or block diagram or combinations thereof, and combinations of multiple blocks in the flowchart or block diagram or combinations thereof, can be implemented by computer-readable program instructions.
[0016] These computer-readable program instructions are provided to a computer processor or other programmable data processing apparatus to create means for implementing the functions / operations specified in one or more blocks of the flowchart or block diagram or combinations thereof, such that instructions executed via the processor of the computer or other programmable data processing apparatus implement the functions / operations specified in one or more blocks of the flowchart or block diagram or combinations thereof, creating a machine. These computer-readable program instructions may also be stored in a computer-readable storage medium that includes instructions for implementing the functions / operations specified in one or more blocks of the flowchart or block diagram or combinations thereof, such that a manufactured article including the computer-readable storage medium storing the instructions implements the functions / operations specified in one or more blocks of the flowchart or block diagram or combinations thereof.
[0017] These computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device such that instructions executed on the computer, other programmable data processing apparatus, or other device implement the functions / operations specified in one or more blocks of the flowchart or block diagram or combinations thereof, causing a series of operational steps to be executed on the computer, other programmable apparatus, or other device to generate a process implemented on the computer.
[0018] The flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of a system, method, and computer program product or possible implementation of a computer program, according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions, which includes one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions shown in the block may occur in a different order than shown in the drawings. For example, two consecutive blocks shown may actually be achieved as one step executed simultaneously, substantially simultaneously, partially, or wholly in a temporally overlapping manner, depending on the functions involved, or the blocks may be executed in reverse order. It should be noted that each block of the block diagram or flowchart or combination thereof, and combinations of multiple blocks of the block diagram or flowchart or combination thereof, can be implemented by a special purpose hardware-based system that performs a specified function or operation, or can execute a combination of special purpose hardware and computer instructions.
[0019] As shown in FIG. 1, the networked computer system 100 is one embodiment of a hardware and software environment for use with various embodiments of the present invention. The networked computer system 100 includes a packet syntax designer subsystem 102 (which may also be referred to more simply as subsystem 102 herein); client subsystems 104, 106, 108, 110, and 112; and a communication network 114. Subsystem 102 includes a packet syntax designer computer 200, a communication unit 202, a processor set 204, an input / output (I / O) interface set 206, a memory 208, a persistent storage 210, a display 212, one or more external devices 214, a random access memory (RAM) 230, a cache 232, and a program 300.
[0020] Subsystem 102 can be a laptop computer, a tablet computer, a netbook computer, a personal computer (PC), a desktop computer, a personal digital assistant (PDA), a smartphone, or any other type of computer (see the definition of "computer" in the Definitions section below). Program 300 is a set of machine-readable instructions or data or a combination thereof used to create, manage, and control certain software functions that will be described in detail below in the Exemplary Embodiments subsection of the Detailed Description of the Invention section.
[0021] Subsystem 102 is capable of communicating with other computer subsystems via communication network 114. Network 114 can be, for example, a local area network (LAN), a wide area network (WAN), such as the Internet, or a combination thereof, and can comprise a wired connection, a wireless connection, or an optical fiber connection. Generally, network 114 can be any combination of connections and protocols that support communication between a server and a client subsystem.
[0022] Subsystem 102 is shown as a block diagram having a number of double arrows. These double arrows (without separate reference numerals) represent a communication fabric that provides communication between various components of subsystem 102. This communication fabric can be implemented in any architecture designed to pass data or control information or a combination thereof between processors (e.g., microprocessors, communication and network processors, etc.), system memory, peripheral devices, and any other hardware components within a computer system. For example, the communication fabric can be implemented, at least in part, using one or more buses.
[0023] Memory 208 and persistent storage 210 are computer-readable storage media. Generally, memory 208 can comprise any suitable volatile or non-volatile computer-readable storage media. It should be further noted that in the present or near future or both, (i) one or more external devices 214 may be able to supply some or all of the memory for subsystem 102, or (ii) devices external to subsystem 102 may be able to supply memory for subsystem 102, or may be able to be supplied in a combination of (i) and (ii) above. Both memory 208 and persistent storage 210 store data in a manner that is less transient than a signal in transit and store data on a tangible medium (e.g., a magnetic domain or an optical domain). In this embodiment, memory 208 is volatile storage while persistent storage 210 provides non-volatile storage. The medium used by persistent storage 210 may also be removable. For example, a removable hard disk may be used for persistent storage 210. Other examples include optical disks and magnetic disks, thumb drives, and smart cards that are inserted into a drive for transfer onto another computer-readable storage medium that is also part of persistent storage 210.
[0024] Communication unit 202 provides communication with other data processing systems or devices external to subsystem 102. In these examples, communication unit 202 comprises one or more network interface cards. Communication unit 202 can provide communication through the use of either or both physical and wireless communication links. Any software module discussed herein can be downloaded through a communication unit (e.g., communication unit 202) to a persistent storage device (e.g., persistent storage 210).
[0025] The I / O interface set 206 enables the input and output of data with other devices that can be locally connected in data communication with the packet syntax designer computer 200. For example, the I / O interface set 206 provides connections to a set of external devices 214. The set of external devices 214 will typically include devices such as a keyboard, keypad, touch screen, or some other suitable input device, or combinations thereof. The set of external devices 214 can also include a portable computer-readable storage medium, such as a thumb drive, portable optical or magnetic disk, and memory card. Software and data used to practice embodiments of the present invention, such as program 300, can be stored on such a portable computer-readable storage medium. The I / O interface set 206 is also connected in data communication with a display 212. The display 212 is a display device that provides a mechanism for displaying data to a user and can be, for example, a computer monitor or a display screen of a smartphone.
[0026] In this embodiment, program 300 is stored in persistent storage 210, typically via one or more memories of memory 208, for access or execution by, or for access and execution by, one or more computer processors of processor set 204. Those skilled in the art will understand that program 300 may be stored in a more highly distributed manner during its execution time, when not executed, or both. Program 300 may comprise both machine-readable and executable instructions or physical data, or a combination thereof (i.e., the types of data stored in a database). In this particular embodiment, persistent storage 210 includes a magnetic hard disk drive. By way of some possible variations, persistent storage 210 may include a solid state hard drive, a semiconductor storage device, a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, or any other computer-readable storage medium capable of storing program instructions or digital information.
[0027] The programs described in the specification are identified based on the uses in which the programs are implemented in particular embodiments of the invention. However, it should be understood that any particular program names herein are used for convenience only, and thus the invention should not be limited to being identified or implied by such names or to being used only in any particular uses so identified and implied.
[0028] The descriptions of the various embodiments of the invention are presented for purposes of illustration and are not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments. The terms used herein are selected to best explain the principles of the embodiments, the practical application, or a technical improvement found in the marketplace, or to enable those skilled in the art to understand the embodiments disclosed herein.
[0029] II. Exemplary Embodiments
[0030] As shown in FIG. 1, the networked computer system 100 is an environment in which an exemplary method according to the present invention can be executed. As shown in FIG. 2, the flowchart 250 shows an exemplary method according to the present invention. As shown in FIG. 3, the program 300 executes or controls the performance of at least some of the method operations of the flowchart 250. This method and the associated software will now be discussed over the following paragraphs with extensive reference to the blocks of FIGS. 1, 2, and 3.
[0031] The process begins at operation S255, where the Ethernet type module ("mod") 302 defines a new Ethernet type (see definition in the Background section above) for communicating process id values (PIDs) associated with a given packet in the header of the packet itself. As can be seen from the syntax definition 308 diagram shown in FIG. 4, for the packets generated by this embodiment, the Ethernet type id of this new Ethernet type is 3 bytes long. Alternatively, the new Ethernet type id can be 2 bytes long.
[0032] The process proceeds to operation S260, where the protocol stack layer module 304 determines one or more layers of the protocol suite over which PIDs would be communicated if the network were implemented using a protocol stack that conforms to the protocol suite. In embodiments that use the OSI protocol suite, the protocol layers that may be selected are as follows: (i) the transport layer protocol, (ii) the network layer protocol, (iii) the data link layer protocol, or (iv) the physical layer protocol, or combinations thereof. In this example, the PID would be communicated only within the packet header of a packet that is made according to the packet syntax definition for packets made according to the transport layer protocol in the transport layer of the abstraction (i.e., the transmission control protocol (TCP)). (See the definition of the "abstraction layer" in the Background section above.) Alternatively and / or additionally, other layers from among the above four layers may insert PIDs within the definition of their packets, frames, or other associated data units, or combinations thereof.
[0033] The process proceeds to operation S265, where the packet syntax module 306 generates a syntax definition 308 for TCP packets that are to be communicated over the communication network 114 during normal operation. A detailed block diagram of this packet syntax is shown in FIG. 4. Other types of syntax that include the position for the communication of PID values (e.g., the order of header fields, byte assignments) may be used. For example, FIG. 5, which is described in the next subsection of the Detailed Description section of the present invention, shows different packet syntax definitions for use in one or more other embodiments of the present invention.
[0034] The process proceeds to operation S270 (which may also be referred to as "normal operation"), where network communication occurs between two or more of client subsystems 104, 106, 108, 110, and 112. When these communications occur during normal operation, the following two things happen: (i) logs are maintained at various client subsystems (as is currently conventional), and (ii) data including the communication of many TCP packets (which include the PID in the header) that are generated and encapsulated according to syntax definition 308 is communicated. More specifically, with respect to item (ii) in the list described above, each TCP packet for communicating data at the transport layer is generated according to a "process". Each process has its own PID, and the process that causes the generation of a given TCP packet will place its associated PID within the given TCP packet header according to syntax definition 308.
[0035] The process proceeds to operation S275, where communication collection module 310 collects a set of network communications for analysis (e.g., there may have been a glitch or crash during normal operation of networked computer system 100). In this example, this means collecting the TCP packets communicated during normal operation.
[0036] The process proceeds to operation S280, where collection log module 312 collects the logs generated and maintained by client subsystems 104, 106, 108, 110, and 112.
[0037] The process proceeds to operation S285, where correlation module 314 correlates the PIDs occurring in the various log data with the PIDs in the headers of the TCP packets. The purpose and advantages of this correlation operation will be described in detail in the next subsection of the detailed description of the present invention.
[0038] III. Further Comments or Embodiments or Combinations Thereof
[0039] According to some embodiments of the present invention, with respect to the current state of the art, the following facts, potential problems, or potential areas for improvement, or combinations thereof, are recognized: (i) An effective security intelligence and event management system depends on a combination of event logs and network flow data; (ii) Event logs provide visibility into processes running on specific hosts (e.g., web server logs, proxy logs, mail servers, Windows domains, VPN (virtual private network) services, intrusion detection systems (IDS), intrusion prevention systems (IPS), and other network security products); (iii) It also has the function of connecting to other sequential data sources, such as databases, and obtaining logs from them; (iv) Event logs are uniquely identified by the process ID (PID) in use over a specific time period for a given host IP (Internet Protocol) address; (v) Network flow data visualizes everything across the network and is uniquely identified by, at least, a combination of source IP, source port, destination IP, destination port, and protocol over a specific time period; (vi) The only correlation that can be performed between the two data sources is via the IP address that performs an action within a specified time window; (vii) It is desirable that these actions can be further correlated so as to determine which PID triggered a network flow, or vice versa; (viii) Existing solutions that help solve this problem include actively monitoring network connections at the endpoints so that the network connections can be associated with a given PID; (ix) These solutions are useful but have processes that generate high-traffic data, which may result in a performance degradation in the capture of real-time events; (x) Duplication of existing event data as queries can be regenerated due to performance issues;(xi) The solution does not meet the objective of correlating event data to a given PID; or (xii) There are numerous examples of log sources that can provide process level information, such as the above-mentioned process level information including osquery, SysFlow, Kubernetes, Sysdig, and Sysmon; or a combination of the above (i) - (xii).;
[0040] Some embodiments of the present invention may include one or more of the following operations, features, characteristics, or advantages, or combinations thereof, for improvement regarding the correlation that can be performed between event logs and network flow data: (i) Using existing commercially available software; (ii) Correlation can be performed between event logs of all network connections at the endpoint itself and network flow data logs; (iii) Utilizing a kernel module to capture and record logs; (iv) All network communications are established (established between endpoint information of other systems); or (v) Even if reduced to only a flow session identifier and PID, this typically requires at least 16 bits of memory, excluding additional bytes necessary to transfer this information to a SIEM (security information and event management) endpoint; or a combination of the above (i) - (v).
[0041] Some embodiments of the present invention may include one or more of the following operations, features, characteristics, or advantages, or combinations thereof: (i) Embedding a process ID (PID) in network traffic; (ii) Embedding the PID in the header of a packet in a style similar to that of the IEEE (Institute of Electrical and Electronics Engineers) for VLAN (virtual local area network) tags; (iii) Linux (登録商標)In the base system, the maximum number of PIDs is 2^22, which means it can be embedded within a 3-byte field; or, (iv) in the case of including the additional "Ethernet type" required for the underlying protocol, this results in a total of 5 bytes of memory being added to the network packet; or a combination of (i)-(iv) above.
[0042] Some embodiments of the present invention may include one or more of the following operations, features, characteristics, or advantages, or combinations thereof: (i) Often, enterprises already have administrative control over devices on the network, such as but not limited to the above-mentioned devices including laptops, servers, networking devices (such as routers and firewalls); (ii) It can be implemented as a network protocol and fully processed on the internal network, where a kernel module is added to the endpoints to inject their PIDs into the network traffic; (iii) Add other modules to the networking device before routing network traffic to a larger Ethernet (a larger segment of the enterprise network or the entire Internet itself); or (iv) Visibility can be obtained on the internal network without affecting compatibility with external communications (for example, similar management of internal and external network protocols is already being carried out in a VLAN); or a combination of (i)-(iv) above.
[0043] Some embodiments of the present invention may include one or more of the following operations, features, characteristics, or advantages, or combinations thereof: (i) There is very little additional data that needs to be transferred from the endpoint itself (only 5 bytes as described above); (ii) It can be managed on the internal network without affecting packets outside the network; or (iii) Only the kernel is changed through the module without the need to change individual processes on the endpoint; or a combination of (i)-(iii) above.
[0044] As shown in FIG. 5, the packet syntax definition 500 includes the following: a preamble portion 502 (8 bytes long), a destination media access control (MAC) address portion 504 (6 bytes long), a source MAC address portion 506 (6 bytes long), a process id (PID) portion 508 (including a PID Ethernet type / size portion 508a (2 bytes long) and a PID portion 508b (3 bytes long)), a packet-level Ethernet type / size portion 510 (2 bytes long), a payload portion 512 (a very large number of bytes long), and an error check portion 514 (4 bytes long). Note that in this embodiment, the PID Ethernet type / size portion is 2 bytes long, while the process ID is 3 bytes long.
[0045] As shown in FIG. 6, the system 600 includes the following system components: an endpoint computer 602, a TAP (network tap) block 604, a network security monitoring computer 606, a network device 608, and an external network / Internet 610. The endpoint computer 602 is used with a new kernel module for this new network protocol (i.e., the TAP block 604). A network security monitoring computer 606 (e.g., a computer equipped with a commercially available SIEM product) that reads packets and creates a two-way flow record supplies flow information to a SIEM tool for correlation. In this embodiment, the network device 608 is a router that has knowledge of the new network protocol. The external network / Internet 610 does not necessarily have knowledge of the network protocol of FIG. 5.
[0046] One embodiment of the method according to the present invention includes the following operations: (i) the endpoint process starts a network connection where the kernel module inserts the PID; (ii) the packet traverses the internal network; (iii) the packet is mirrored by a TAP device (which can also be a SPAN (switched port analyzer) port in the switch) to a network security monitoring tool, where at this point the PID is correlated with the flow session identifier (at least the source IP, source port, destination IP, destination port, and protocol), and this pre-correlated information can be directly supplied into the SIEM tool; (iv) the packet continues to traverse the internal network and reaches the edge network device; (v) the edge network device deletes the new network protocol and forwards the packet with only the original basic information; (vi) the packet continues its route to its final destination; (vii) one or more response packets return through the network route; (viii) one or more response packets are also mirrored to the network security endpoint for two-way flow correlation; (ix) the packets can be automatically correlated with the request packets characterized by the PID because their network flow tables are the same; or (x) one or more response packets are received and processed by the endpoint host; or a combination of (i) to (x) above.
[0047] Note that some conventional techniques embed a "packet tag" within the IP option header, but this tag is not the PID itself. To achieve the correlation between the process log and the network flow, some embodiments of the present invention may use the following methods: (i) extract the packet tag; (ii) correlate the packet tag with the PID; or (iii) correlate the PID with the event log; or a combination of (i) to (iii) above.
[0048] Some embodiments of the present invention may include one or more of the following operations, features, characteristics, or advantages, or combinations thereof: (i) performing correlation not only at the host level but also at the individual process level, or (ii) not having to perform a correlation operation because the PID is communicated directly as "raw network traffic"; or a combination of (i) to (ii) above.
[0049] One embodiment of the method according to the present invention is for use in a security intelligence and event management computer system (SIEMCS), for example, the above SIEMCS having a first host computer device and a network. The method includes the following operations (not necessarily in the following order): (i) generating, on the first host computer device, a first event log, for example, the above first event log including information indicating the operation of the first host computer device; (ii) assigning a first process ID (PID) code to the first event log; (iii) using the first PID code over a certain period for the Internet protocol (IP) address associated with the first host computer device; (iv) collecting a network flow data set including at least information indicating the following: the source IP of each given communication, the source port of each given communication, the destination IP of each given communication, the destination port of each given communication, and the protocol of each given communication; or (v) determining, based on the first PID code, the first event log, and the network flow data set, that the first host computer device identified by the first PID code has triggered a first network flow; or a combination of (i) to (v) above. IV. Definitions
[0050] The present invention: The subject matter described by the phrase "the present invention" should not be taken as absolutely indicating that it is included by either the claims at the time of filing or the claims that may ultimately be issued after patent examination. The phrase "the present invention" is used to help the reader obtain a general sense that the present disclosure is potentially novel, but as indicated by the use of the phrase "the present invention", this understanding is provisional and tentative and may be changed during the patent examination process as relevant information is developed and the claims are potentially amended.
[0051] Embodiment: Refer to the above definition of "the present invention". Similar cautions apply to the phrase "embodiment".
[0052] And / or: Inclusive "or". For example, A, B, "and / or" C means that at least one of A or B or C is true and applicable.
[0053] Including / include / includes: Unless otherwise expressly stated, it means "including but not necessarily limited to".
[0054] Module / sub-module: A module refers to any possible set of hardware, firmware, software, or combinations thereof that operate to perform a certain function, regardless of whether (i) it is locally proximate; (ii) it is widely distributed; (iii) it is proximate within a larger software code; (iv) it is located within a single software code; (v) it is located within a single storage device, memory, or medium; (vi) it is mechanically connected; (vii) it is electrically connected; or (viii) it is connected by data communication; or a combination of (i) to (viii) above.
[0055] Computer: Any device having important data processing or machine-readable instruction reading capabilities, such as, but not limited to, desktop computers, mainframe computers, laptop computers, FPGA-based devices, smartphones, PDAs, body-mounted or plug-in computers, embedded device style computers, application-specific integrated circuit (ASIC)-based devices.
Claims
1. A method implemented on a computer, comprising: Defining a new Ethernet type to be used when communicating a process identification code (PID), wherein the new Ethernet type is assigned a new Ethernet type code; Determining a selected abstraction layer from a plurality of abstraction layers to be used when communicating the PID; and Performing a plurality of network communications between two or more computers of a networked computer system using each communication. comprising wherein performing each given communication comprises: Inserting the new Ethernet type code and the PID of the process causing the given communication into a data structure; and Communicating the data structure between a plurality of computers of the networked computer system in the selected abstraction layer. comprising the method.
2. The method according to claim 1, wherein the data structure is any one of a packet, a frame, or raw data.
3. The method according to claim 1, wherein each of some of the plurality of abstraction layers corresponds to at least a part of seven layers of an Open Systems Interconnection (OSI) model.
4. The selected abstraction layer is an OSI transport layer; and each data structure is a packet formed according to the Transmission Control Protocol (TCP), wherein the new Ethernet type code and the PID for the packet are inserted into a packet header. The method according to claim 3.
5. The new Ethernet type code is 2 bytes long; and each PID is 3 bytes long. The method according to claim 4.
6. The method according to claim 3, wherein the selected abstraction layer is one of the following OSI layers, namely, the network layer, the data link layer protocol, or the physical layer.
7. A computer program, wherein the computer program defines a new Ethernet type to be used when communicating a process identification code (PID), wherein the new Ethernet type is assigned a new Ethernet type code; determines a selected abstraction layer from a plurality of abstraction layers to be used when communicating the PID; and performs a plurality of network communications between two or more computers of a networked computer system using each communication causes one or more processors to execute each step of the method including wherein performing each given communication includes inserting the new Ethernet type code and the PID of the process causing the given communication into a data structure, and communicating the data structure between a plurality of computers of the networked computer system in the selected abstraction layer including the computer program.
8. The computer program according to claim 7, wherein the data structure is one of the data structure types of a packet, a frame, or raw data.
9. The computer program according to claim 7, wherein each of some of the plurality of abstraction layers corresponds to at least a part of seven layers of an Open Systems Interconnection (OSI) model.
10. The selected abstraction layer is the OSI layer transport layer, and Each data structure is a packet formed in accordance with the Transmission Control Protocol (TCP), where the new Ethernet type code and the PID for the packet are inserted into the packet header, the computer program according to claim 9.
11. The new Ethernet type code is 2 bytes in length; and, Each PID is 3 bytes in length, The computer program according to claim 10.
12. The selected abstraction layer is one of the following OSI layers, namely, the network layer, the data link layer protocol, or the physical layer, the computer program according to claim 9.
13. A computer system, One or more processors; One or more storage devices; and, Computer code collectively stored in the one or more storage devices Comprising, Wherein the computer code, Defines a new Ethernet type to be used when communicating a Process Identification Code (PID), where the new Ethernet type is assigned a new Ethernet type code; Determines a selected abstraction layer from a plurality of abstraction layers to be used when communicating a PID; and, Performs a plurality of network communications between two or more computers of a networked computer system using each communication A plurality of instructions for causing one or more processors to execute operations including at least Including, Wherein performing each given communication is, Inserting the new Ethernet type code and the PID of the process causing the given communication into a data structure, and, In the selected abstraction layer, communicating a data structure among a plurality of computers of the networked computer system comprising the computer system. **Claim 14** The computer system according to claim 13, wherein the data structure is any one of a packet, a frame, or raw data. **Claim 15** The computer system according to claim 13, wherein each of some of the plurality of abstraction layers corresponds to at least a part of seven layers of an Open Systems Interconnection (OSI) model. **Claim 16** The selected abstraction layer is an OSI transport layer; and each data structure is a packet formed according to the Transmission Control Protocol (TCP), wherein the new Ethernet type code and the PID for the packet are inserted into a packet header. The computer system according to claim 15. **Claim 17** The new Ethernet type code is 2 bytes long; and each PID is 3 bytes long. The computer system according to claim 16. **Claim 18** The computer system according to claim 15, wherein the selected abstraction layer is one of the following OSI layers, namely, a network layer, a data link layer protocol, or a physical layer.
Citation Information
Patent Citations
Ethernet type packet discrimination data type
JP2018504799A
Apparatus and method for configuring channel resource in wireless communication system
US20200170043A1