IP Library Granted Patent US 10,084,822
Granted Patent B2
US 10,084,822 · App. 15/158,605 · Granted Sep 25, 2018

Intrusion detection and prevention system and method for generating detection rules and taking countermeasures

Inventors: Dimitrios Papamartzivanos (Eppelheim, DE); Felix Gomez Marmol (Heidelberg, DE)
Assignee: NEC CORPORATION
H04L63/20G06N7/005H04L63/0263H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,084,822
App. No.
15/158,605
Granted
Sep 25, 2018
Kind
B2
Abstract

A detection rules generation engine includes an initial population creation subsystem configured to receive filtered network traffic instances from a network tap and to build an initial population of decision trees having nodes which are sorted based on an information gain of network features of the traffic instances. A parents selection subsystem is configured to select two individuals from the population based on a selection probability. A depth selection subsystem is configured to select a depth among the nodes of the decision trees. A parents crossover subsystem is configured to apply a crossover operation on the selected individuals. A parents mutation subsystem is configured to apply a mutation operation on the selected individuals. A population replacement subsystem is configured to generate a next population.

Claims (55)

1. A detection rules generation engine, comprising one or more processors and/or servers, which alone or in combination, are configured to provide for execution of the following steps:

receiving filtered network traffic instances from a network tap and building an initial population of decision trees having nodes which are sorted based on an information gain of network features of the traffic instances;

selecting two individuals from the population based on a selection probability, wherein the selection probability is given by:

F ( I i )=α f 1 ( I i )+β f 2 ( I i )+γ f 3 ( I i ),

where:

f 1 (I i ) is the class-based selection function for the i th individual,

f 2 (I i ) is the actual fitness function for the i th individual,

f 3 (I i ) is the missing classes function of the best individual, and

α, β and γ are the weights of f 1 , f 2 and f 3 , respectively (where α+β+γ=1);

selecting a depth among the nodes of the decision trees;

applying a crossover operation on the selected individuals;

applying a mutation operation on the selected individuals; and

generating a next population.

2. The detection rules generation engine according to claim 1 , wherein the one or more processors and/or servers are further configured to provide for execution of the step of selecting a best individual of the next population.

3. The detection rules generation engine according to claim 2 , wherein the one or more processors and/or servers are further configured to provide for execution of the step of adding any missing classes to the best individual.

4. The detection rules generation engine according to claim 1 , wherein the one or more processors and/or servers are configured to provide for execution of the step of performing the crossover operation by swapping randomly chosen branches between the selected individuals so as to provide a synthesis to the selected depth.

5. The detection rules generation engine according to claim 1 , wherein the one or more processors and/or servers are configured to provide for execution of the step of performing the mutation operation by splitting the nodes of the selected individuals at the selected depth and at a splitting point which provides a highest information gain.

6. The detection rules generation engine according to claim 1 , further comprising a population database configured to store the next population.

7. A method for generating detection rules, comprising:

receiving filtered network traffic instances from a network tap;

building an initial population of decision trees having nodes which are sorted based on an information gain of network features of the traffic. instances;

selecting two individuals from the population based on a selection probability, wherein the selection probability is given by:

F ( I i )=α f 1 ( I i )+β f 2 ( I i )=γ f 3 ( I i ),

where:

f 1 (I i ) is the class-based selection function for the i th individual,

f 2 (I i ) is the actual fitness function for the i th individual,

f 3 (I i ) is the missing classes function of the best individual, and

α,β and γ are the weights of f 1 , 2 and 3 , respectively (where α+β+γ=1);

selecting a depth among the nodes of the decision trees;

applying a crossover operation on the selected individuals;

applying a mutation operation on the selected individuals; and

generating a next population.

8. The method according to claim 7 , further comprising selecting a best individual of the next population.

9. The method according to claim 8 , further comprising adding any missing classes to the best individual.

10. The method according to claim 7 , further comprising:

transforming the decision tree of the best individual into decision rules;

adding the decision rules into a decision rules database;

evaluating network traffic based on the decision rules in the decision rules database;

providing an alert based on the network traffic satisfying conditions of the decision rules; and

initiating countermeasures against a potential attack.

11. The method according to claim 7 , wherein the crossover operation is performed by swapping randomly chosen branches between the selected individuals so as to provide a synthesis to the selected depth.

12. The method according to claim 7 , wherein the mutation operation is performed by splitting the nodes of the selected individuals at the selected depth and at a splitting point which provides a highest information gain.

13. A tangible, non-transitory computer readable medium having instructions thereon, which, when executed on one or more processors cause execution of a method comprising:

building an initial population of decision trees having nodes which are sorted based on an information gain of network features of filtered traffic instances;

selecting two individuals from the population based on a selection probability, wherein the selection probability is given by:

F ( I i )=α f 1 ( I i )+β f 2 ( I i )+γ f 3 ( I i ),

where:

f 1 (I i ) is the class-based selection function for the i th individual,

f 2 (I i ) is the actual fitness function for the i th individual,

f 3 (I i ) is the missing classes function of the best individual, and

α,β and γ are the weights of f 1 , f 2 and f 3 , respectively (where α+β+γ=1);

selecting a depth among the nodes of the decision trees;

applying a crossover operation on the selected individuals;

applying a mutation operation on the selected individuals; and

generating a next population.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 14, 2018
From: NEC LABORATORIES EUROPE GMBH
To: NEC CORPORATION
Reel/Frame 046781/0411 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2017
From: NEC EUROPE LTD.
To: NEC LABORATORIES EUROPE GMBH
Reel/Frame 044979/0698 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2016
From: PAPAMARTZIVANOS, DIMITRIOS; MARMOL, FELIX GOMEZ
To: NEC EUROPE LTD.
Reel/Frame 038903/0615 →
Continuity (1)
Related Publication 20170339187A1 · Nov 23, 2017
Cited By (2)
US 12,244,629 US 12,592,952