IP Library Granted Patent US 10,476,749
Granted Patent B2
US 10,476,749 · App. 15/477,603 · Granted Nov 12, 2019

Graph-based fusing of heterogeneous alerts

Inventors: Kenji Yoshihira (Princeton Junction, NJ); Zhichun Li (Princeton, NJ); Zhengzhang Chen (Princeton Junction, NJ); Haifeng Chen (West Windsor, NJ); Guofei Jiang (Princeton, NJ); LuAn Tang (Pennington, NJ)
Assignee: NEC Corporation
H04L41/12G06F21/552H04L41/142H04L41/145H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,476,749
App. No.
15/477,603
Granted
Nov 12, 2019
Kind
B2
Abstract

Methods and systems for reporting anomalous events include intra-host clustering a set of alerts based on a process graph that models states of process-level events in a network. Hidden relationship clustering is performed on the intra-host clustered alerts based on hidden relationships between alerts in respective clusters. Inter-host clustering is performed on the hidden relationship clustered alerts based on a topology graph that models source and destination relationships between connection events in the network. Inter-host clustered alerts that exceed a threshold level of trustworthiness are reported.

Claims (24)

1. A method for reporting anomalous events, comprising:

intra-host clustering a set of alerts based on a process graph that models states of process-level events in a network;

hidden relationship clustering the intra-host clustered alerts based on hidden relationships between alerts in respective clusters by clustering alerts together that are from a same user at a same host in the process graph within a threshold time period; and

inter-host clustering the hidden relationship clustered alerts based on a topology graph that models source and destination relationships between connection events in the network; and

reporting inter-host clustered alerts that exceed a threshold level of trustworthiness.

2. The method of claim 1 , wherein intra-host clustering comprises clustering alerts together that have a process distance that is below a process distance threshold.

3. The method of claim 2 , wherein the process distance is calculated as the shortest path between two different processes at a same host in the process graph.

4. The method of claim 1 , wherein inter-host clustering comprises clustering alerts together that have an edge between respective hosts in the topology graph and that occur within a threshold period of time.

5. The method of claim 1 , further comprising building the process graph and the topology graph based on received alerts.

6. The method of claim 5 , further comprising trimming elements from the process graph and the topology graph if said elements have a last-connection-time value older than a threshold period.

7. The method of claim 1 , further comprising computing a trustworthiness for inter-host clustered alerts by summing an alert trustworthiness of a representative alert of each process represented in the inter-host clustered alerts.

8. The method of claim 7 , further comprising, computing an alert trustworthiness of each representative alert as a product of an abnormality score provided by a detector that generated the representative alert and a weight for the detector.

9. The method of claim 8 , wherein the weight for the detector is computed as a ratio between a number of false alerts generated by the detector and a total number of alerts generated by the detector.

10. A system for reporting anomalous events, comprising:

a clustering module comprising a processor configured to perform intra-host clustering on a set of alerts based on a process graph that models states of process-level events in a network, to perform hidden relationship clustering on the intra-host clustered alerts based on hidden relationships between alerts in respective clusters by clustering alerts together that are from a same user at a same host in a threshold time period, and to perform inter-host clustering on the hidden relationship clustered alerts based on a topology graph that models source and destination relationships between connection events in the network; and

a user interface configured to report inter-host clustered alerts that exceed a threshold level of trustworthiness.

11. The system of claim 10 , wherein the clustering module is further configured to cluster alerts together that have a process distance that is below a process distance threshold.

12. The system of claim 11 , wherein the process distance is calculated as the shortest path between two different processes at a same host in the process graph.

13. The system of claim 10 , wherein the clustering module is further configured to cluster alerts together that have an edge between respective hosts in the topology graph and that occur within a threshold period of time.

14. The system of claim 10 , further comprising a blue print update module configured to build the process graph and the topology graph based on received alerts.

15. The system of claim 14 , wherein the blue print update module is further configured to trim elements from the process graph and the topology graph if said elements have a last-connection-time value older than a threshold period.

16. The system of claim 10 , wherein the clustering module is further configured to compute a trustworthiness for inter-host clustered alerts by summing an alert trustworthiness of a representative alert of each process represented in the inter-host clustered alerts.

17. The system of claim 16 , wherein the clustering module is further configured to compute an alert trustworthiness of each representative alert as a product of an abnormality score provided by a detector that generated the representative alert and a weight for the detector.

18. The system of claim 17 , wherein the weight for the detector is computed as a ratio between a number of false alerts generated by the detector and a total number of alerts generated by the detector.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2024
From: IP WAVE PTE LTD.
To: CLOUD BYTE LLC.
Reel/Frame 067944/0332 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2024
From: NEC ASIA PACIFIC PTE LTD.
To: IP WAVE PTE LTD.
Reel/Frame 066376/0276 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2023
From: NEC CORPORATION
To: NEC ASIA PACIFIC PTE LTD.
Reel/Frame 066124/0752 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2019
From: NEC LABORATORIES AMERICA, INC.
To: NEC CORPORATION
Reel/Frame 050498/0081 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2017
From: YOSHIHIRA, KENJI; LI, ZHICHUN; CHEN, ZHENGZHANG; CHEN, HAIFENG; JIANG, GUOFEI; TANG, LUAN
To: NEC LABORATORIES AMERICA, INC.
Reel/Frame 041830/0050 →
Continuity (3)
Continuation In Part 15098861 · Apr 14, 2016
Provisional Application 62317781 · Apr 4, 2016
Related Publication 20170288974A1 · Oct 5, 2017