IP Library Patent Application 14383024
Patent Application
App. No. 14/383,024

ANOMALY DETECTION TO IDENTIFY COORDINATED GROUP ATTACKS IN COMPUTER NETWORKS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/383,024
Abstract

Systems, apparatuses, methods, and computer programs for detecting anomalies to identify coordinated group attacks on computer networks are provided. An anomaly graph of a network including nodes, edges, and an indegree of the nodes in the anomaly graph may be determined. Nodes with an indegree of at least two may be designated as potential targets. Nodes with no incoming connections may be designated as potentially compromised nodes. The designated potentially compromised nodes may be outputted as potentially associated with a coordinated attack on the network when the potentially compromised nodes connect to one or more of the same potential target nodes.

Claims (113)

1 . A computer-implemented method, comprising:

determining, by a computing system, an anomaly graph of a network comprising nodes, edges, and an indegree of the nodes in the anomaly graph;

designating, by the computing system, nodes with an indegree of at least two as potential targets;

designating, by the computing system, nodes with no incoming connections as potentially compromised nodes; and

outputting, by the computing system, the designated potentially compromised nodes as potentially associated with a coordinated attack on the network when the potentially compromised nodes connect to at least one of the same potential target nodes.

2 . The computer-implemented method of claim 1 , wherein the steps of claim 1 are performed periodically, by the computing system, during sliding time windows.

3 . The computer-implemented method of claim 1 , further comprising:

deleting, by the computing system, incoming edges going to nodes with an indegree of one from the anomaly graph.

4 . The computer-implemented method of claim 1 , further comprising:

determining, by the computing system, each weakly connected subgraph in the anomaly graph.

5 . The computer-implemented method of claim 4 , further comprising:

calculating a summary statistic for O k for each subgraph using a number of undirected edges in the given subgraph, the summary statistic determined by:

O

k

=

i

<

j

max

{

I

(

e

ij

E

k

)

,

I

(

e

ji

E

k

)

}

where e ij and e ji represent edges in a set of edges E k for the given subgraph.

6 . The computer-implemented method of claim 1 , wherein the computing system is configured to treat all of the nodes and edges in the anomaly graph as independent entities.

7 . The computer-implemented method of claim 1 , wherein for a p-value threshold Tε(0,1), the anomaly graph S t =(V t s ,E t s ) of the network is formed from the edges that have a positive p-value below the threshold:

E t s ={( i,j )ε E t |p ij,t <T}

V t s ={iεV t |∃j≠iεV t s.t .( i,j )ε E t s or ( j,i )ε E t s }

where E t s is a set of edges in S t , V t s is the set of nodes in S t , and p ij,t is the p-value for a given edge (i,j)εE t .

8 . An apparatus, comprising:

at least one processor; and

memory storing computer program instructions, wherein the instructions, when executed by the at least one processor, are configured to cause the at least one processor to:

monitor a network over time periods to determine anomalous behavior signifying potential activity from a group of attackers during at least one time period; and

provide an indication that a potential group attack is occurring in the network when anomalous behavior is determined during at least one time period.

9 . The apparatus of claim 8 , wherein the anomalous behavior comprises overlapping or correlated behavior where a group of potentially compromised nodes attempt to connect to common nodes during at least one of the time periods.

10 . The apparatus of claim 8 , wherein the instructions are further configured to cause the at least one processor to determine a p-value for each edge in the network, where the p-value indicates how far a respective edge has deviated from its normal behavior.

11 . The apparatus of claim 10 , wherein for a p-value threshold Tε(0,1) the instructions are further configured to cause the at least one processor to form an anomaly graph S t =(V t s ,E t s ) of the network from edges that have a positive p-value below the threshold:

E t s ={( i,j )ε E t |p ij,t <T}

V t s ={iεV t |∃j≠iεV t s.t .( i,j )ε E t s or ( j,i )ε E t s }

where E t s is a set of edges in S t , V t s is the set of nodes in S t , and p ij,t is the p-value for a given edge (i,j)εE t .

12 . The apparatus of claim 11 , wherein the instructions are further configured to cause the at least one processor to:

delete incoming edges going to nodes with an indegree of one from the anomaly graph.

13 . The apparatus of claim 11 , wherein the instructions are further configured to cause the at least one processor to:

determine each weakly connected subgraph in the anomaly graph.

14 . The apparatus of claim 13 , wherein the instructions are further configured to cause the at least one processor to calculate a summary statistic for O k for each subgraph using a number of undirected edges in the given subgraph, the summary statistic determined by:

O

k

=

i

<

j

max

{

I

(

e

ij

E

k

)

,

I

(

e

ji

E

k

)

}

where e ij and e ji represent edges in a set of edges E k for the given subgraph.

15 . A system, comprising:

memory storing computer program instructions configured to detect anomalies in a network; and

a plurality of processing cores configured to execute the stored computer program instructions, wherein the plurality of processing cores is configured to:

generate an anomaly graph for a network during a time period;

determine whether multiple nodes with no indegree and common node connections exist during the time period; and

generate an indication of a potential group attack on the network when the system determines that multiple nodes with no indegree and common node connections exist in one or more subgraphs of the anomaly graph.

16 . The system of claim 15 , wherein the indication comprises potentially compromised nodes having no indegree and common node connection, and potential target nodes with an indegree of two or more to which the potentially compromised nodes are connected.

17 . The system of claim 15 , wherein the plurality of processing cores are further configured to determine a p-value for each edge in the network, where the p-value indicates how far a respective edge has deviated from its normal behavior.

18 . The system of claim 17 , wherein for a p-value threshold Tε(0,1), the processing cores are further configured to form the anomaly graph S t =(V t s ,E t s ) of the network from edges that have a positive p-value below the threshold:

E t s ={( i,j )ε E t |p ij,t <T}

V t s ={iεV t |∃j≠iεV t s.t .( i,j )ε E t s or ( j,i )ε E t s }

where E t s is a set of edges in S t , V t s is the set of nodes in S t , and p ij,t is the p-value for a given edge (i,j)εE t .

19 . The system of claim 15 , wherein the processing cores are further configured to:

delete incoming edges going to nodes with an indegree of one from the anomaly graph.

20 . The system of claim 15 , wherein the processing cores are further configured to:

determine each weakly connected subgraph in the anomaly graph.

Assignments (5)
CHANGE OF NAME Recorded Feb 18, 2021
From: IMPERIAL INNOVATIONS LIMITED
To: IP2IPO INNOVATIONS LIMITED
Reel/Frame 055314/0787 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2020
From: HEARD, NICHOLAS, DR.; TURCOTTE, MELISSA JULIA MARIE, MISS
To: IMPERIAL COLLEGE OF SCIENCE, TECHNOLOGY AND MEDICINE
Reel/Frame 052842/0914 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2020
From: IMPERIAL COLLEGE OF SCIENCE, TECHNOLOGY AND MEDICINE
To: IMPERIAL INNOVATIONS LIMITED
Reel/Frame 052843/0066 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2018
From: LOS ALAMOS NATIONAL SECURITY, LLC
To: TRIAD NATIONAL SECURITY, LLC
Reel/Frame 047396/0489 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2014
From: NEIL, JOSHUA CHARLES, MR.
To: LOS ALAMOS NATIONAL SECURITY, LLC
Reel/Frame 033671/0593 →