IP Library › Granted Patent US 11,082,442
Granted Patent B1
US 11,082,442 · App. 15/174,175 · Granted Aug 3, 2021

Automated setting of risk score aggregation weights for detection of access anomalies in a computer network

Inventors: Eyal Kolman (Raanana, IL); Carmit Sahar (Tel-Aviv, IL)
Assignee: EMC IP Holding Company LLC
H04L63/1433H04L63/08H04L63/102H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,082,442
App. No.
15/174,175
Filed
Jun 6, 2016
Granted
Aug 3, 2021
Kind
B1
Art Unit
2432
USPC
726/7
Abstract

A processing device in one embodiment comprises a processor coupled to a memory and is configured to generate access profiles for respective user identifiers, to obtain data characterizing a current access for a given one of the user identifiers, to extract a plurality of features from the data characterizing the current access for the given user identifier, and to generate feature risk scores based on the extracted features and the access profile for the given user identifier. The processing device is further configured to aggregate the feature risk scores into a composite risk score. The aggregation illustratively comprises weighting the feature risk scores utilizing automatically-set feature risk score weights. The composite risk score is compared to a threshold, and an alert is generated relating to the current access based on a result of comparing the composite risk score to the threshold.

Claims (283)

1. A method for automated detection of access anomalies in at least one network, the method comprising steps of:

generating access profiles for respective user identifiers;

obtaining data characterizing a current access for a given one of the user identifiers;

extracting a plurality of features from the data characterizing the current access for the given user identifier;

generating feature risk scores for the current access based on the extracted features and the access profile for the given user identifier;

determining deviations of respective probability distributions of the generated feature risk scores from one or more corresponding predetermined probability distributions;

automatically setting feature risk score weights for the respective generated feature risk scores based at least in part on the determined deviations, the size of each automatically-set feature risk score weight corresponding to a size of the deviation of the respective probability distribution of the corresponding feature risk score from the one or more corresponding predetermined probability distributions;

aggregating the feature risk scores to form a composite risk score wherein the aggregating comprises weighting the feature risk scores utilizing the automatically-set feature risk score weights and aggregating the weighted feature risk scores together to form the composite risk score;

comparing the composite risk score to a threshold;

generating an alert relating to the current access based on a result of comparing the composite risk score to the threshold; and

automatically taking one or more remedial actions relating to the current access based on the result of comparing the composite risk score to the threshold, the one or more remedial actions comprising one or more of:

requesting a submission of one or more additional authentication factors from a user device associated with the given user identifier;

terminating the current access; and

suspending the current access until the one or more additional authentication factors are obtained and verified;

wherein the alert is transmitted over said at least one network to a security agent; and

wherein the steps are performed by at least one processing device comprising a processor coupled to a memory.

2. The method of claim 1 wherein the predetermined probability distribution characterizes an ideal feature risk score that provides a significant contribution to the composite risk score in the presence of an anomaly relating to the corresponding feature but in the absence of such an anomaly provides minimal contribution to the composite risk score.

3. The method of claim 1 wherein the predetermined probability distribution is configured in accordance with the following equation:

p

⁡

(

s

)

=

1

K

⁢

exp

⁡

(

-

αs

)

,

where s denotes a feature risk score, p(s) denotes probability of the feature risk score s, α is a selectable parameter, and K is a normalizing factor.

4. The method of claim 3 wherein the normalizing factor K is configured in accordance with the following equation:

K

=

1

-

exp

⁡

(

-

10

⁢

0

⁢

α

)

α

,

where α is the selectable parameter and the feature risk scores are in the range [0, 100].

5. The method of claim 1 wherein the deviation of the probability distribution of a given one of the feature risk scores from the predetermined probability distribution is determined based at least in part on a distance computed between the probability distribution of the given feature risk score and the predetermined probability distribution.

6. The method of claim 5 wherein the distance is computed in accordance with the following equation:

D

=

∫

0

1

⁢

0

⁢

0

⁢

(

g

⁡

(

s

)

-

f

⁡

(

s

)

)

2

⁢

d

⁢

s

where D denotes the distance, s denotes a feature risk score, g(s) denotes the predetermined probability distribution, f(s) denotes the probability distribution of the given feature risk score, and the feature risk scores are in the range [0, 100].

7. The method of claim 5 wherein the distance is computed in accordance with the following equation:

D

=

∫

0

1

⁢

0

⁢

0

⁢

g

⁡

(

s

)

⁢

f

⁡

(

s

)

⁢

d

⁢

s

where D denotes the distance, s denotes a feature risk score, g(s) denotes the predetermined probability distribution, f (s) denotes the probability distribution of the given feature risk score, and the feature risk scores are in the range [0, 100].

8. The method of claim 5 wherein the distance is computed in accordance with the following equation:

D

=

-

∫

0

1

⁢

0

⁢

0

⁢

g

⁡

(

s

)

⁢

log

⁢

g

⁡

(

s

)

f

⁡

(

s

)

⁢

d

⁢

s

where D denotes the distance, s denotes a feature risk score, g(s) denotes the predetermined probability distribution, f(s) denotes the probability distribution of the given feature risk score, and the feature risk scores are in the range [0, 100].

9. The method of claim 5 wherein the distance is computed in accordance with the following equation:

D

=

max

s

0

⁢

{

∫

-

∞

s

0

⁢

g

⁡

(

s

)

-

f

⁡

(

s

)

⁢

d

⁢

s

}

where D denotes the distance, s denotes a feature risk score, s 0 denotes a running parameter, g(s) denotes the predetermined probability distribution, f(s) denotes the probability distribution of the given feature risk score, and the feature risk scores are in the range [0, 100].

10. The method of claim 5 wherein the distance is computed in accordance with the following equation:

D

=

-

log

⁡

(

∫

0

1

⁢

0

⁢

0

⁢

g

⁡

(

s

)

⁢

f

⁡

(

s

)

⁢

d

⁢

s

)

where D denotes the distance, s denotes a feature risk score, g(s) denotes the predetermined probability distribution, f (s) denotes the probability distribution of the given feature risk score, and the feature risk scores are in the range [0, 100].

11. The method of claim 1 wherein the deviation of the probability distribution of a given one of the feature risk scores from the predetermined probability distribution is determined based at least in part on an aggregation of respective samples of the given feature risk score projected over the predetermined probability distribution.

12. The method of claim 11 wherein the aggregation is computed in accordance with the following equation:

A

=

∏

i

=

1

N

⁢

g

⁡

(

s

i

)

N

where A denotes the aggregation, s i denotes a particular one of the samples in the aggregation, N denotes a total number of the samples in the aggregation, and g(s i ) denotes the projection of the sample s i over the predetermined probability distribution.

13. The method of claim 11 wherein the aggregation is computed in accordance with the following equation:

A

=

1

N

⁢

∑

i

=

1

N

⁢

g

⁡

(

s

i

)

where A denotes the aggregation, s i denotes a particular one of the samples in the aggregation, N denotes a total number of the samples in the aggregation, and g(s i ) denotes the projection of the sample s i over the predetermined probability distribution.

14. The method of claim 1 wherein one or more of the automatically-set weights each incorporate prior knowledge information relating to the corresponding feature risk score.

15. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes said at least one processing device:

to generate access profiles for respective user identifiers;

to obtain data characterizing a current access for a given one of the user identifiers;

to extract a plurality of features from the data characterizing the current access for the given user identifier;

to generate feature risk scores for the current access based on the extracted features and the access profile for the given user identifier;

to determine deviations of respective probability distributions of the generated feature risk scores from one or more predetermined probability distributions;

to automatically set feature risk score weights for the respective generated feature risk scores based at least in part on the determined deviations, the size of each automatically-set feature risk score weight corresponding to a size of the deviation of the respective probability distribution of the corresponding feature risk score from the one or more corresponding predetermined probability distributions;

to aggregate the feature risk scores to form a composite risk score wherein the aggregating comprises weighting the feature risk scores utilizing automatically-set feature risk score weights and aggregating the weighted feature risk scores together to form the composite risk score;

to compare the composite risk score to a threshold;

to generate an alert relating to the current access based on a result of comparing the composite risk score to the threshold; and

to automatically take one or more remedial actions relating to the current access based on the result of comparing the composite risk score to the threshold, the one or more remedial actions comprising one or more of:

requesting a submission of one or more additional authentication factors from a user device associated with the given user identifier;

terminating the current access; and

suspending the current access until the one or more additional authentication factors are obtained and verified;

wherein the alert is transmitted over said at least one network to a security agent.

16. The processor-readable storage medium of claim 15 wherein the program code when executed by said at least one processing device causes said at least one processing device to determine the deviation of the probability distribution of a given one of the feature risk scores from the predetermined probability distribution based at least in part on a distance computed between the probability distribution of the given feature risk score and the predetermined probability distribution.

17. The processor-readable storage medium of claim 15 wherein the program code when executed by said at least one processing device causes said at least one processing device to determine the deviation of the probability distribution of a given one of the feature risk scores from the predetermined probability distribution based at least in part on an aggregation of respective samples of the given feature risk score projected over the predetermined probability distribution.

18. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

said at least one processing device being configured:

to generate access profiles for respective user identifiers;

to obtain data characterizing a current access for a given one of the user identifiers;

to extract a plurality of features from the data characterizing the current access for the given user identifier;

to generate feature risk scores for the current access based on the extracted features and the access profile for the given user identifier;

to determine deviations of respective probability distributions of the generated feature risk scores from one or more predetermined probability distributions;

to automatically set feature risk score weights for the respective generated feature risk scores based at least in part on the determined deviations, the size of each automatically-set feature risk score weight corresponding to a size of the deviation of the respective probability distribution of the corresponding feature risk score from the one or more corresponding predetermined probability distributions;

to aggregate the feature risk scores to form a composite risk score wherein the aggregating comprises weighting the feature risk scores utilizing automatically-set feature risk score weights and aggregating the weighted feature risk scores together to form the composite risk score;

to compare the composite risk score to a threshold;

to generate an alert relating to the current access based on a result of comparing the composite risk score to the threshold; and

to automatically take one or more remedial actions relating to the current access based on the result of comparing the composite risk score to the threshold, the one or more remedial actions comprising one or more of:

requesting a submission of one or more additional authentication factors from a user device associated with the given user identifier;

terminating the current access; and

suspending the current access until the one or more additional authentication factors are obtained and verified;

wherein the alert is transmitted over said at least one network to a security agent.

19. The apparatus of claim 18 wherein the deviation of the probability distribution of a given one of the feature risk scores from the predetermined probability distribution is determined based at least in part on a distance computed between the probability distribution of the given feature risk score and the predetermined probability distribution.

20. The apparatus of claim 18 wherein the deviation of the probability distribution of a given one of the feature risk scores from the predetermined probability distribution is determined based at least in part on an aggregation of respective samples of the given feature risk score projected over the predetermined probability distribution.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2016
From: KOLMAN, EYAL; SAHAR, CARMIT
To: EMC CORPORATION
Reel/Frame 038818/0766 →
Cited By (5)
US 12,200,003 US 12,289,334 US 12,301,632 US 12,326,941 US 12,712,920