IP Library Granted Patent US 9,407,652
Granted Patent B1
US 9,407,652 · App. 14/970,317 · Granted Aug 2, 2016

Network anomaly detection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,407,652
App. No.
14/970,317
Granted
Aug 2, 2016
Kind
B1
Abstract

A security system detects anomalous activity in a network. The system logs user activity, which can include ports used, compares users to find similar users, sorts similar users into cohorts, and compares new user activity to logged behavior of the cohort. The comparison can include a divergence calculation. Origins of user activity can also be used to determine anomalous network activity. The hostname, username, IP address, and timestamp can be used to calculate aggregate scores and convoluted scores.

Claims (34)

1. An anomaly-detection computer system to identify when an user of a network is a malicious actor, the anomaly-detection computer system comprising:

one or more computer readable storage devices configured to store one or more software modules including computer executable instructions; and

one or more hardware computer processors in communication with the one or more computer readable storage devices and configured to execute the one or more software modules in order to cause the computer system to:

log, to the one or more computer readable storage devices, activity on the network by a plurality of users, the activity comprising indications of port numbers associated with the activity on the network;

calculate similarity scores by, in part, comparing port numbers associated with a first user of the plurality of users to port numbers associated with other users of the plurality of users, the similarity scores calculated based at least in part on the logged activity on the network;

sort the plurality of users into a plurality of cohorts based at least in part on which of the plurality of users have similarity scores that satisfy a similarity threshold;

store data into a memory, the data identifying which of the plurality of users were sorted into the plurality of cohorts;

detect a first port number indicated in a new network activity of the first user of the plurality of users, wherein the first user is associated with a first cohort of the plurality of cohorts; and

determine, based at least in part on a comparison performed by the one or more processors of the first port number to other port numbers associated with the first cohort, that the new network activity associated with the first user is anomalous.

2. The anomaly detection computer system of claim 1 , wherein the activity on the network comprises accessing a distributed resource through a plurality of different network IP addresses.

3. The anomaly detection computer system of claim 1 , further configured to calculate the similarity scores by determining at least one of:

a cosine similarity score; and

a Jaccard similarity score.

4. The anomaly detection computer system of claim 3 , wherein the anomaly detection system is configured to calculate the similarity scores by performing an inverse user frequency transform.

5. The anomaly detection computer system of claim 1 , wherein the anomaly detection system is configured to determine if the new network activity by the first user is anomalous by determining the first port has been used by other members of the first cohort.

6. The anomaly detection computer system of claim 1 , further configured to perform a Kullback-Leibler divergence.

7. The anomaly detection computer system of claim 1 , further configured to receive user information about the plurality of users, and wherein the anomaly detection system is further configured to sort the plurality of users into a plurality of cohorts based at least in part on the similarity scores and the user information.

8. The anomaly detection computer system of claim 1 ,

wherein the new network activity is authenticated by the credentials of the first user; and

wherein the one or more hardware computer processors are further configured to execute the one or more software modules in order to cause the computer system to restrict, based at least in part on determining that the new network activity by the first user is anomalous, an ability of the first user to access a network resource.

9. The anomaly detection computer system of claim 1 , wherein the first port is a port of a computer of the first user.

10. The anomaly detection computer system of claim 1 , wherein the first port comprises at least one of a port of a server hosting the network resource and a port of a second server hosting the network resource.

11. The anomaly detection computer system of claim 1 , wherein the network is a virtual private network.

12. A computer readable, non-transitory storage medium having a computer program stored thereon executable by one or more processors of an anomaly detection system in a network to:

log resource accesses by a plurality of users during a first time period;

calculate a plurality of similarity scores for the plurality of users, the plurality of similarity scores comprising a first similarity score between a first user of the plurality of users and a second user of the plurality of users;

assign, based at least in part on the first similarity score exceeding a similarity threshold, the first user and the second user to a first cohort;

log first data comprising port numbers used in accessing a first plurality of resource accesses by the first user during a second time period that is at least partially different from the first time period;

log second data comprising port numbers used in accessing a second plurality of resource accesses by members of the first cohort;

determine a probability score of the first plurality of resource accesses occurring based on the second data; and

generate, based at least on the probability score, an indicator of a potential anomaly.

13. The storage medium of claim 12 , wherein the probability score is a Kullback-Leibler divergence of the first plurality of resource accesses to the second plurality of resource accesses.

14. The storage medium of claim 12 , wherein the probability score is a Kullback-Leibler divergence of the second plurality of resource accesses to the first plurality of resource accesses.

15. The storage medium of claim 12 , wherein the first plurality of resources accesses contains a first distribution of access to a set of resources, and wherein the second plurality of resource accesses contains a second distribution of accesses to the set of resources.

Assignments (8)
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 22, 2016
From: KESIN, MAXIM; JONES, SAMUEL
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 038989/0637 →