IP Library Granted Patent US 10,296,832
Granted Patent B1
US 10,296,832 · App. 14/960,371 · Granted May 21, 2019

System and method for detecting an undesirable event

Inventor: David Segev (Lapid, IL)
Assignee: ThetaRay Ltd.
G06N5/02G06F16/283G06F17/30592G06N5/04
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,296,832
App. No.
14/960,371
Granted
May 21, 2019
Kind
B1
Abstract

A system for detecting an unknown undesirable event comprises an input device configured to receive a dataset comprising a plurality n of multidimensional datapoints (MDDPs), a processor configured to embed the MDDPs in an lower dimension embedded space to obtain embedded MDDPs, and a detection engine configured to calculate distributions of distances D nn i , i=1, . . . , n of each embedded MDDP from a plurality of nearest-neighbors (nn) to compute a threshold D nn t and to classify a particular MDDP of the dataset or a newly arrived MDDP (NAMDDP) as an abnormal MDDP based on comparison with threshold D nn t , wherein the classification is automatic and unsupervised without relying on a signature, rules or domain expertise and wherein the particular MDDP classified as abnormal is indicative of the unknown undesirable event.

Claims (23)

1. A method for detecting an unknown undesirable event, comprising the steps of:

a) receiving a dataset I comprising a plurality n of multidimensional datapoints (MDDPs) with dimension m≥3, I being a matrix of size n×m and wherein n>>m;

normalizing the MDDPs to obtain distributions of normalized MDDPs (NMDDPs) and applying whitening principal component analysis (WPCA) to the distributions of NMDDPs to obtain a lower dimension embedded space with embedded normalized NMDDPs, wherein the applying of WPCA includes applying singular value decomposition (SVD) to a covariance matrix I T I where T is the transpose of matrix I, wherein the whitening in the WPCA renders the distributions of the NMDDPs less redundant and wherein covariance matrix I T I has a dimension m×m much smaller than n×m;

c) calculating distributions of distances D nn i , i=1, . . . , n of each embedded NMDDP from a plurality of nearest-neighbors (nn) to compute a threshold D nn t ; and

d) classifying a particular MDDP of the dataset or a newly arrived MDDP (NAMDDP) as an abnormal MDDP based on comparison with threshold D nn t , wherein the classification is automatic and unsupervised without relying on a signature, rules or domain expertise and wherein the particular MDDP classified as abnormal is indicative of the unknown undesirable event

whereby the whitening, the embedding in a lower dimension space and the application of SVD to covariance matrix I T I with a dimension much smaller than that of matrix I reduce computer memory needs and speed up computing operations.

2. The method of claim 1 , wherein the embedded space has a dimension k<m.

3. The method of claim 1 , wherein the step of calculating distributions of distances D nn i , i=1, . . . , n of each embedded NMDDP from a plurality of nearest-neighbors (nn) to compute a threshold D nn t includes applying a Gaussian mixture to each distribution to obtain Gaussian weights and using the Gaussian weights to compute threshold D nn t .

4. The method of claim 3 , wherein applying a Gaussian mixture to each distribution to obtain Gaussian weights and using the Gaussian weights to compute threshold D nn t includes computing threshold D nn t from a posterior probability for each element in D nn i .

5. The method of claim 1 , wherein the classification is performed offline.

6. The method of claim 1 , wherein the classification is performed online.

7. The method of claim 1 , wherein the unknown undesirable event is selected from the group consisting of a cyber-threat, a cyber-attack, an operational malfunction, an operational breakdown, a process malfunction, a process breakdown, a financial risk event, a financial threat event, a financial fraud event, money laundering and a financial network intrusion event.

8. The method of claim 1 , further comprising the step of scoring the particular abnormal MDDP.

9. A system for detecting an unknown undesirable event, comprising:

a) an input device configured to receive a dataset I comprising a plurality n of multidimensional datapoints (MDDPs) with dimension m≥3, I thereby being a matrix of size n×m;

b) a processor configured to normalize the MDDPs to obtain distributions of normalized MDDPs (NMDDPs) and to apply whitening principal component analysis (WPCA) to the distributions of NMDDPs to obtain a lower dimension embedded space with embedded normalized NMDDPs, wherein the applying of WPCA includes applying singular value decomposition (SVD) to a covariance matrix I T I where T is the transpose of matrix I, wherein the whitening in the WPCA renders the distributions of the NMDDPs less redundant and wherein covariance matrix I T I has a dimension m×m much smaller than n×m; and

c) a detection engine configured to calculate distributions of distances D nn i , i=1, . . . , n of each embedded NMDDP from a plurality of nearest-neighbors (nn) to compute a threshold D nn t and to classify a particular MDDP of the dataset or a newly arrived MDDP (NAMDDP) as an abnormal MDDP based on comparison with threshold D nn t , wherein the classification is automatic and unsupervised without relying on a signature, rules or domain expertise and wherein the particular MDDP classified as abnormal is indicative of the unknown undesirable event,

whereby the whitening, the embedding in a lower dimension space and the application of SVD to covariance matrix I T I with a dimension much smaller than that of matrix I reduce computer memory needs and speed up computing operations.

10. The method of claim 9 , wherein the configuration to calculate distributions of distances D nn i , i=1, . . . , n of each embedded NMDDP from a plurality of nearest-neighbors (nn) to compute a threshold D nn t includes a configuration to apply a Gaussian mixture to each distribution to obtain Gaussian weights and to use the Gaussian weights to compute threshold D nn t .

11. The method of claim 10 , wherein configuration to apply a Gaussian mixture to each distribution to obtain Gaussian weights and to use the Gaussian weights to compute threshold D nn t includes a configuration compute threshold D nn t from a posterior probability for each element in D nn i .

12. The method of claim 9 , wherein the classification is performed offline.

13. The method of claim 9 , wherein the classification is performed online.

14. The method of claim 9 , wherein the unknown undesirable event is selected from the group consisting of a cyber-threat, a cyber-attack, an operational malfunction, an operational breakdown, a process malfunction, a process breakdown, a financial risk event, a financial threat event, a financial fraud event, money laundering and a financial network intrusion event.

Assignments (4)
SECURITY INTEREST Recorded Jun 25, 2024
From: THETA RAY LTD
To: HSBC BANK PLC
Reel/Frame 067826/0839 →
SECURITY INTEREST Recorded Dec 27, 2022
From: THETA RAY LTD
To: KREOS CAPITAL VI (EXPERT FUND) L.P.
Reel/Frame 062207/0011 →
SECURITY INTEREST Recorded Jun 30, 2021
From: THETARAY LTD.
To: KREOS CAPITAL VI (EXPERT FUND) L.P.
Reel/Frame 056711/0546 →
SECURITY INTEREST Recorded Oct 10, 2019
From: THETA RAY LTD
To: SILICON VALLEY BANK
Reel/Frame 050682/0517 →
Cited By (1)
US 12,222,712