IP Library › Granted Patent US 9,979,738
Granted Patent B2
US 9,979,738 · App. 15/075,052 · Granted May 22, 2018

System and method to detect attacks on mobile wireless networks based on motif analysis

Inventors: Gavin D. Holland (Newbury Park, CA); Michael D. Howard (Westlake Village, CA); Chong Ding (Riverside, CA); Tsai-Ching Lu (Thousand Oaks, CA)
Assignee: HRL Laboratories, LLC
H04L63/1416H04L63/145H04W12/10H04W84/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,979,738
App. No.
15/075,052
Granted
May 22, 2018
Kind
B2
Abstract

Described is a system for detecting attacks on networks. A hierarchical representation of activity of a communication network is used to detect and predict sources of misinformation in the communication network. The hierarchical representation includes temporal patterns of communication between at least one pair of nodes, each temporal pattern representing a motif, having a size, in the hierarchical representation. Changes in motifs provide a signal for a misinformation attack.

Claims (44)

1. A system for detecting attacks on networks, the system comprising:

one or more processors and a non-transitory memory having instructions encoded thereon such that when the instructions are executed, the one or more processors perform operations of:

detecting and predicting sources of misinformation in a communication network using a hierarchical representation of activity of the communication network;

wherein the hierarchical representation comprises a plurality of nodes and temporal patterns of communication between at least one pair of nodes, each temporal pattern representing a motif, having a size, in the hierarchical representation, and

wherein changes in motifs provide a signal for a misinformation attack.

2. The system as set forth in claim 1 , wherein the one or more processors further perform an operation of generating a visual representation on a display relating to motifs of interest to identify a misinformation attack.

3. The system as set forth in claim 2 , wherein a misinformation attack is characterized by an over-representation of motifs having a predetermined size.

4. The system as set forth in claim 3 , wherein a size threshold for detection of a misinformation attack is set by learning a maximum frequency of motifs of each size in a normal baseline operation of the communication network.

5. The system as set forth in claim 4 , wherein if a frequency of any motif size surpasses double the maximum frequency, a misinformation attack signal is detected.

6. The system as set forth in claim 5 , wherein the one more processors further perform operations of:

introducing a motif attribution measure at each node i of the communication network; and

for each node i, defining m i as a frequency of sub-graphs to which it contributes;

wherein a m i greater than double the maximum frequency indicates a likelihood that node i is an attacker.

7. The system as set forth in claim 1 , wherein the hierarchical representation comprises a plurality of data tables that describe applications and services running on the communication network and a set of inter-dependencies between the applications and services.

8. A computer-implemented method for detecting attacks on networks, comprising:

an act of causing one or more processors to execute instructions stored on a non-transitory memory such that upon execution, the one or more processors perform operations of:

detecting and predicting sources of misinformation in a communication network using a hierarchical representation of activity of the communication network;

wherein the hierarchical representation comprises a plurality of nodes and temporal patterns of communication between at least one pair of nodes, each temporal pattern representing a motif, having a size, in the hierarchical representation, and

wherein changes in motifs provide a signal for a misinformation attack.

9. The method as set forth in claim 8 , wherein the one or more processors further perform an operation of generating a visual representation on a display relating to motifs of interest to identify a misinformation attack.

10. The method as set forth in claim 9 , wherein a misinformation attack is characterized by an over-representation of motifs having a predetermined size.

11. The method as set forth in claim 10 , wherein a size threshold for detection of a misinformation attack is set by learning a maximum frequency of motifs of each size in a normal baseline operation of the communication network.

12. The method as set forth in claim 11 , wherein if a frequency of any motif size surpasses double the maximum frequency, a misinformation attack signal is detected.

13. The method as set forth in claim 12 , wherein the one or more processors further perform operations of:

introducing a motif attribution measure at each node i of the communication network; and

for each node i, defining m i as a frequency of sub-graphs to which it contributes;

wherein a m i greater than double the maximum frequency indicates a likelihood that node i is an attacker.

14. The method as set forth in claim 8 , wherein the hierarchical representation comprises a plurality of data tables that describe applications and services running on the communication network and a set of inter-dependencies between the applications and services.

15. A computer program product for detecting attacks on networks, the computer program product comprising:

computer-readable instructions stored on a non-transitory computer-readable medium that are executable by a computer having one or more processors for causing the processor to perform operations of:

detecting and predicting sources of misinformation in a communication network using a hierarchical representation of activity of the communication network;

wherein the hierarchical representation comprises a plurality of nodes and temporal patterns of communication between at least one pair of nodes, each temporal pattern representing a motif, having a size, in the hierarchical representation, and

wherein changes in motifs provide a signal for a misinformation attack.

16. The computer program product as set forth in claim 15 , further comprising instructions for causing the one or more processors to perform an operation of generating a visual representation on a display relating to motifs of interest to identify a misinformation attack.

17. The computer program product as set forth in claim 16 , wherein a misinformation attack is characterized by an over-representation of motifs having a predetermined size.

18. The computer program product as set forth in claim 17 , wherein a size threshold for detection of a misinformation attack is set by learning a maximum frequency of motifs of each size in a normal baseline operation of the communication network.

19. The computer program product as set forth in claim 18 , wherein if a frequency of any motif size surpasses double the maximum frequency, a misinformation attack signal is detected.

20. The computer program product as set forth in claim 19 , further comprising instructions for causing the one or more processors to perform operations of:

introducing a motif attribution measure at each node i of the communication network; and

for each node i, defining m i as a frequency of sub-graphs to which it contributes;

wherein a m i greater than double the maximum frequency indicates a likelihood that node i is an attacker.

21. The computer program product as set forth in claim 15 , wherein the hierarchical representation comprises a plurality of data tables that describe applications and services running on the communication network and a set of inter-dependencies between the applications and services.

22. The system as set forth in claim 1 , wherein upon detection of an attack of misinformation on the communication network, the one or more processors further perform an operation of performing a mitigation action.

23. The system as set forth in claim 22 , wherein the mitigation action comprises isolating an attacking node from the rest of the communication network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2017
From: HOLLAND, GAVIN D.; HOWARD, MICHAEL D.; DING, CHONG; LU, TSAI-CHING
To: HRL LABORATORIES, LLC
Reel/Frame 042394/0302 →
Continuity (12)
Continuation In Part 14625988 · Feb 19, 2015
Continuation In Part 14209314 · Mar 13, 2014
Continuation In Part 13904945 · May 29, 2013
Continuation In Part 13748223 · Jan 23, 2013
Provisional Application 61941893 · Feb 19, 2014
Provisional Application 61784167 · Mar 14, 2013
Provisional Application 61589634 · Jan 23, 2012
Provisional Application 61589646 · Jan 23, 2012
Provisional Application 61694510 · Aug 29, 2012
Provisional Application 62135136 · Mar 18, 2015
Provisional Application 62135142 · Mar 18, 2015
Related Publication 20170318033A1 · Nov 2, 2017