IP Library Granted Patent US 11,171,974
Granted Patent B2
US 11,171,974 · App. 15/357,399 · Granted Nov 9, 2021

Distributed agent based model for security monitoring and response

Inventors: Yael Gertner (Champaign, IL); Frederick S. M. Herz (Milton, WV); Walter Paul Labys (Fairfax, VA)
Assignee: Inventship LLC
H04L63/1425H04L63/145H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,171,974
App. No.
15/357,399
Granted
Nov 9, 2021
Kind
B2
Abstract

An architecture is provided for a widely distributed security system (SDI-SCAM) that protects computers at individual client locations, but which constantly pools and analyzes information gathered from machines across a network in order to quickly detect patterns consistent with intrusion or attack, singular or coordinated. When a novel method of attack has been detected, the system distributes warnings and potential countermeasures to each individual machine on the network. Such a warning may potentially include a probability distribution of the likelihood of an intrusion or attack as well as the relative probabilistic likelihood that such potential intrusion possesses certain characteristics or typologies or even strategic objectives in order to best recommend and/or distribute to each machine the most befitting countermeasure(s) given all presently known particular data and associated predicted probabilistic information regarding the prospective intrusion or attack. If any systems are adversely affected, methods for repairing the damage are shared and redistributed throughout the network.

Claims (22)

1. A system that detects the state of a computer network, comprising:

a plurality of distributed agents disposed in said computer network, each said distributed agent comprising:

at least one sensor that analyzes network traffic data to passively collect, monitor, and aggregate data representative of activities of respective nodes within said computer network;

a distributed adaptive machine learning model that analyzes the aggregated data from the at least one sensor to develop activity models based on collected data and representative activities of the network in a normal state and activities of the computer network in an abnormal state as a result of at least one of intrusions, infections, scams, or suspicious activities in the computer network, wherein analysis of the aggregated data includes performing a pattern analysis on the aggregated data to identify patterns in the aggregated data representative of suspicious activities and providing adaptive rules and a probabilistic model for predicting existing threats, emerging threats, or anticipated threats to said computer network that are updated with relevance feedback, the distributed adaptive learning model further generating counteroffensive measures in response to a predicted existing threat, emerging threat, or anticipated threat to said computer network based on the relevance feedback, wherein the relevance feedback includes trial and error from previously delivered responses to previous threats and attacks on the computer network; and

means for communicating at least the aggregated data to other distributed agents on a peer-to-peer basis.

2. A system as in claim 1 , wherein the at least one sensor scans code on at least one node in the computer network for patterns that have previously been associated with viruses or malicious programming and checks incoming files to the at least one node against known viruses.

3. A system as in claim 1 , wherein the at least one sensor monitors code on the at least one node in the computer network for behavior or data traffic patterns consistent with viral infection.

4. A system as in claim 1 , wherein the at least one sensor monitors patterns of usage of at least one node in the computer network to identify patterns of usage consistent with a threat to the computer network.

5. A system as in claim 1 , wherein the at least one sensor uses natural language processing methods to analyze text for irregularities consistent with a non-human origin or to compare messages in the computer network to previously logged deceptions.

6. A system as in claim 1 , wherein the distributed adaptive learning model generates a bogus target for invoking attack on the bogus target and collects data related to the invoked attack for detecting a system infection.

7. A system as in claim 1 , further comprising a security network that is isolated from said computer network, wherein the distributed agents communicate with each other over the security network.

8. A system as in claim 1 , wherein each distributed agent shares responsibility for network traffic data analysis with at least one other distributed agent.

9. A system that detects the state of a computer network, comprising:

a plurality of distributed agents disposed in said computer network, each said distributed agent comprises at least one sensor that analyzes network traffic data to passively collect, monitor, and aggregate data representative of activities of respective nodes within said computer network and means for communicating at least the aggregated data to other distributed agents on a peer-to-peer basis; and

an adaptive machine learning model that analyzes the aggregated data from the at least one sensor to develop activity models based on collected data and representative activities of the network in a normal state and activities of the computer network in an abnormal state as a result of at least one of intrusions, infections, scams, or suspicious activities in the computer network, wherein analysis of the aggregated data includes performing a pattern analysis on the aggregated data to identify patterns in the aggregated data representative of suspicious activities and providing adaptive rules and a probabilistic model for predicting existing threats, emerging threats, or anticipated threats to said computer network that are updated with relevance feedback, the distributed adaptive learning model further generating counteroffensive measures in response to a predicted existing threat, emerging threat, or anticipated threat to said computer network based on the relevance feedback, wherein the relevance feedback includes trial and error from previously delivered responses to previous threats and attacks on the computer network.

10. A system as in claim 9 , wherein the at least one sensor scans code on at least one node in the computer network for patterns that have previously been associated with viruses or malicious programming and checks incoming files to the at least one node against known viruses.

11. A system as in claim 9 , wherein the at least one sensor monitors code on the at least one node in the computer network for behavior or data traffic patterns consistent with viral infection.

12. A system as in claim 9 , wherein the at least one sensor monitors patterns of usage of at least one node in the computer network to identify patterns of usage consistent with a threat to the computer network.

13. A system as in claim 9 , wherein the at least one sensor uses natural language processing methods to analyze text for irregularities consistent with a non-human origin or to compare messages in the computer network to previously logged deceptions.

14. A system as in claim 9 , wherein the distributed adaptive learning model generates a bogus target for invoking attack on the bogus target and collects data related to the invoked attack for detecting a system infection.

15. A system as in claim 9 , further comprising a security network that is isolated from said computer network, wherein the distributed agents communicate with each other over the security network.

16. A system as in claim 9 , wherein each distributed agent shares responsibility for network traffic data analysis with at least one other distributed agent.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2022
From: INVENTSHIP, LLC
To: CTD NETWORKS LLC
Reel/Frame 060776/0238 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2021
From: FRED HERZ PATENTS, LLC
To: INVENTSHIP, LLC
Reel/Frame 057028/0584 →
Continuity (6)
Continuation 14043567 · Oct 1, 2013
Continuation In Part 10746825 · Dec 24, 2003
Continuation In Part 10693149 · Oct 23, 2003
Provisional Application 61708304 · Oct 1, 2012
Provisional Application 60436363 · Dec 24, 2002
Related Publication 20170078317A1 · Mar 16, 2017
Cited By (16)
US 12,206,698 US 12,235,962 US 12,244,626 US 12,259,967 US 12,261,884 US 12,341,814 US 12,363,151 US 12,418,565 US 12,423,078 US 12,432,253 US 12,450,351 US 12,452,273 US 12,468,810 US 12,579,268 US 12,603,901 US 12,664,258