IP Library › Granted Patent US 10,003,985
Granted Patent B1
US 10,003,985 · App. 14/625,988 · Granted Jun 19, 2018

System and method for determining reliability of nodes in mobile wireless network

Inventors: Gavin D. Holland (Oak Park, CA); Michael D. Howard (Westlake Village, CA); Tsai-Ching Lu (Thousand Oaks, CA); Karim El Defrawy (Santa Monica, CA); Matthew S. Keegan (Boston, MA); Kang-Yu Ni (Calabasas, CA)
Assignee: HRL Laboratories, LLC
H04W24/06H04L41/147H04L43/045H04L43/12H04W24/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,003,985
App. No.
14/625,988
Filed
Feb 19, 2015
Granted
Jun 19, 2018
Kind
B1
Examiner
TRAN, DZUNG
Art Unit
2829
USPC
702/183
Abstract

Described is a system for determining reliability of nodes in a mobile wireless network. The system is operable for receiving an Exploitation Network (Xnet) database. The Xnet database has an Xnet structure formed of a physical node layer (NetTopo), a network dependent (NetDep) layer, and an application dependent (AppDep) layer. The NetTopo layer includes NetTopo graphs reflecting connectivity between the nodes. The NetDep layer includes NetDep graphs reflecting connectivity dependencies amongst the nodes, and the AppDep layer includes Appdep graphs reflecting software application dependencies amongst the nodes. An Xnet Analytics Engine is run that monitors and evaluates reliability of each node in the mobile wireless network to provide a reliability estimate of each node.

Claims (48)

1. A system for determining reliability of nodes in a mobile wireless network, the system comprising:

one or more processors and a memory, the memory being a non-transitory computer-readable medium having executable instructions encoded thereon, such that upon execution of the instructions, the one or more processors perform operations of:

receiving an Exploitation Network (Xnet) database, the Xnet database having an Xnet structure formed of a physical node layer (NetTopo), a network dependent (NetDep) layer, and an application dependent (AppDep) layer, the NetTopo layer having NetTopo graphs reflecting connectivity between the nodes, the NetDep layer having NetDep graphs reflecting connectivity dependencies amongst the nodes, and the AppDep layer having Appdep graphs reflecting software application dependencies amongst the nodes;

running an Xnet Analytics Engine that monitors and evaluates reliability of each node in the mobile wireless network to provide a reliability estimate of each node and designating suspect nodes;

actively probing suspect nodes to determine if behaviors that caused the suspect nodes to be suspected are due to consequences of normal operation or malicious operation; and

isolating nodes in the mobile wireless network that are determined to be exhibiting behaviors due to malicious operation.

2. The system as set forth in claim 1 , wherein the Xnet Analytics Engine further comprises:

an Xnet Dynamics (XD) module that is operable for detecting and predicting critical transitions in the AppDep and NetDep layers for misinformation identification;

an Xnet Controllability and Observability (XCO) module that is operable for identifying nodes in the Xnet for active probing and observation as suspect nodes;

an Xnet Evolvability (XE) module that is operable for predicting potential propagation and consequences of an attack on one or more nodes and focusing resources for monitoring and protecting the network; and

a Reliability Estimation (RE) module that is operable for receiving data from each of the XD module, XCO module, and XE module to generate a reliability estimation of each node in the mobile wireless network, the reliability estimation being a trust metric.

3. The system as set forth in claim 2 , wherein if a node's trust metric falls below a threshold, causing the XCO module to actively probe and observe the node to test the reliability estimate.

4. The system as set forth in claim 3 , wherein the XD module receives a data plane of behavior time series as extracted from the AppDep and NetDep layers to generate structure dependency changes in the AppDep and NetDep layers, the structure dependency changes being indicative of critical transitions in the AppDep and NetDep layers between misbehaving nodes for misinformation identification.

5. The system as set forth in claim 4 , wherein the XCO module receives the AppDep graphs, NetDep graphs, NetTopo graphs, and structure dependency changes as generated by the XD module to identify the nodes in the Xnet for active probing and observation as suspect nodes.

6. The system as set forth in claim 5 , wherein the XE module receives the Xnet structure, the misbehaving nodes, and suspect nodes to generate a confidence measure of how well an observed pattern of node failures matches a contagion or cascade failure, such that if the confidence measure exceeds a threshold, the XE module outputs simulation results of anticipated contagion paths with a set of anticipated critical nodes whose failures can trigger collapse of the Xnet structure.

7. A method for determining reliability of nodes in a mobile wireless network, the method comprising an act of:

causing one or more processors to execute instructions on a memory, such that upon execution of the instructions, the one or more processors perform operations of:

receiving an Exploitation Network (Xnet) database, the Xnet database having an Xnet structure formed of a physical node layer (NetTopo), a network dependent (NetDep) layer, and an application dependent (AppDep) layer, the NetTopo layer having NetTopo graphs reflecting connectivity between the nodes, the NetDep layer having NetDep graphs reflecting connectivity dependencies amongst the nodes, and the AppDep layer having Appdep graphs reflecting software application dependencies amongst the nodes; and

running an Xnet Analytics Engine that monitors and evaluates reliability of each node in the mobile wireless network to provide a reliability estimate of each node and designating suspect nodes;

actively probing suspect nodes to determine if behaviors that caused the suspect nodes to be suspected are due to consequences of normal operation or malicious operation; and

isolating nodes in the mobile wireless network that are determined to be exhibiting behaviors due to malicious operation.

8. The method as set forth in claim 7 , wherein running the Xnet Analytics Engine further comprises operations of:

detecting and predicting, with an Xnet Dynamics (XD) module, critical transitions in the AppDep and NetDep layers for misinformation identification;

identifying, with an Xnet Controllability and Observability (XCO) module, nodes in the Xnet for active probing and observation as suspect nodes;

predicting, with an Xnet Evolvability (XE) module, potential propagation and consequences of an attack on one or more nodes and focusing resources for monitoring and protecting the network; and

receiving, with a Reliability Estimation (RE) module, data from each of the XD module, XCO module, and XE module to generate a reliability estimation of each node in the mobile wireless network, the reliability estimation being a trust metric.

9. The method as set forth in claim 8 , wherein if a node's trust metric falls below a threshold, causing the XCO module to actively probe and observe the node to test the reliability estimate.

10. The method as set forth in claim 9 , wherein the XD module receives a data plane of behavior time series as extracted from the AppDep and NetDep layers to generate structure dependency changes in the AppDep and NetDep layers, the structure dependency changes being indicative of critical transitions in the AppDep and NetDep layers between misbehaving nodes for misinformation identification.

11. The method as set forth in claim 10 , wherein the XCO module receives the AppDep graphs, NetDep graphs, NetTopo graphs, and structure dependency changes as generated by the XD module to identify the nodes in the Xnet for active probing and observation as suspect nodes.

12. The method as set forth in claim 11 , wherein the XE module receives the Xnet structure, the misbehaving nodes, and suspect nodes to generate a confidence measure of how well an observed pattern of node failures matches a contagion or cascade failure, such that if the confidence measure exceeds a threshold, the XE module outputs simulation results of anticipated contagion paths with a set of anticipated critical nodes whose failures can trigger collapse of the Xnet structure.

13. A computer program product for determining reliability of nodes in a mobile wireless network, the computer program product comprising:

a non-transitory computer-readable medium having executable instructions encoded thereon, such that upon execution of the instructions by one or more processors, the one or more processors perform operations of:

receiving an Exploitation Network (Xnet) database, the Xnet database having an Xnet structure formed of a physical node layer (NetTopo), a network dependent (NetDep) layer, and an application dependent (AppDep) layer, the NetTopo layer having NetTopo graphs reflecting connectivity between the nodes, the NetDep layer having NetDep graphs reflecting connectivity dependencies amongst the nodes, and the AppDep layer having Appdep graphs reflecting software application dependencies amongst the nodes; and

running an Xnet Analytics Engine that monitors and evaluates reliability of each node in the mobile wireless network to provide a reliability estimate of each node and designating suspect nodes;

actively probing suspect nodes to determine if behaviors that caused the suspect nodes to be suspected are due to consequences of normal operation or malicious operation; and

isolating nodes in the mobile wireless network that are determined to be exhibiting behaviors due to malicious operation.

14. The computer program product as set forth in claim 13 , wherein running the Xnet Analytics Engine further comprises operations of:

detecting and predicting, with an Xnet Dynamics (XD) module, critical transitions in the AppDep and NetDep layers for misinformation identification;

identifying, with an Xnet Controllability and Observability (XCO) module, nodes in the Xnet for active probing and observation as suspect nodes;

predicting, with an Xnet Evolvability (XE) module, potential propagation and consequences of an attack on one or more nodes and focusing resources for monitoring and protecting the network; and

receiving, with a Reliability Estimation (RE) module, data from each of the XD module, XCO module, and XE module to generate a reliability estimation of each node in the mobile wireless network, the reliability estimation being a trust metric.

15. The computer program product as set forth in claim 14 , wherein if a node's trust metric falls below a threshold, causing the XCO module to actively probe and observe the node to test the reliability estimate.

16. The computer program product as set forth in claim 15 , wherein the XD module receives a data plane of behavior time series as extracted from the AppDep and NetDep layers to generate structure dependency changes in the AppDep and NetDep layers, the structure dependency changes being indicative of critical transitions in the AppDep and NetDep layers between misbehaving nodes for misinformation identification.

17. The computer program product as set forth in claim 16 , wherein the XCO module receives the AppDep graphs, NetDep graphs, NetTopo graphs, and structure dependency changes as generated by the XD module to identify the nodes in the Xnet for active probing and observation as suspect nodes.

18. The computer program product as set forth in claim 17 , wherein the XE module receives the Xnet structure, the misbehaving nodes, and suspect nodes to generate a confidence measure of how well an observed pattern of node failures matches a contagion or cascade failure, such that if the confidence measure exceeds a threshold, the XE module outputs simulation results of anticipated contagion paths with a set of anticipated critical nodes whose failures can trigger collapse of the Xnet structure.

19. The system as set forth in claim 1 , wherein actively probing suspect nodes includes forcing packets through one or more suspect nodes to detect if the one or more suspect node's forwarding service is following protocol.

20. The method as set forth in claim 7 , wherein actively probing suspect nodes includes forcing packets through one or more suspect nodes to detect if the one or more suspect node's forwarding service is following protocol.

21. The computer program product as set forth in claim 13 , wherein actively probing suspect nodes includes forcing packets through one or more suspect nodes to detect if the one or more suspect node's forwarding service is following protocol.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2015
From: HOLLAND, GAVIN D.; HOWARD, MICHAEL D.; LU, TSAI-CHING; EL DEFRAWY, KARIM; KEEGAN, MATTHEW S.; NI, KANG-YU
To: HRL LABORATORIES, LLC
Reel/Frame 036627/0377 →
CONFIRMATORY LICENSE Recorded Jul 9, 2015
From: HRL LABORATORIES, LLC
To: AFRL/RIJ
Reel/Frame 036088/0516 →
Continuity (10)
Continuation In Part 14209314 · Mar 13, 2014
Continuation In Part 13904945 · May 29, 2013
Continuation In Part 14625988
Continuation In Part 13904945 · May 29, 2013
Continuation In Part 13748223 · Jan 23, 2012
Provisional Application 61941893 · Feb 19, 2014
Provisional Application 61784167 · Mar 14, 2013
Provisional Application 61589634 · Jan 23, 2012
Provisional Application 61589646 · Jan 23, 2012
Provisional Application 61694510 · Aug 29, 2012
Cited By (2)
US 12,231,448 US 12,462,031