IP Library Granted Patent US 10,558,799
Granted Patent B2
US 10,558,799 · App. 15/669,698 · Granted Feb 11, 2020

Detecting irregularities on a device

Inventor: Stephen Dodson (London, GB)
Assignee: Elasticsearch B.V.
G06F21/552G06F21/554G06F21/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,558,799
App. No.
15/669,698
Granted
Feb 11, 2020
Kind
B2
Abstract

A system and method for the detection of irregularities, such as fraud or malware, running on a device, is disclosed. The system comprises a monitoring program for reviewing data relating to operation of the device, a device profile including data items relating to typical operation of the device generated from messages relating to the device; and an alert module for generating an alert on detection of unusual activity relating to the device.

Claims (46)

1. A system for detection of irregularities of a device, the system comprising:

the device; a hardware processor; and a memory communicatively coupled with the hardware processor, the memory storing instructions which when executed by the hardware processor performs a method, the method comprising:

creating, by a monitoring program, a device baseline profile comprising data items relating to a typical operation of the device, the data items comprising:

(i) incoming ports associated with processes,

(ii) outgoing ports associated with the processes, and

(iii) Internet Protocol (IP) addresses associated with the processes;

storing, in a user profile database, the device baseline profile;

receiving, by the monitoring program, new ones of data items indicative of a current operation of the device;

determining, by the monitoring program, whether the new ones of data items deviate from the typical operation of the device by comparing the new ones of data items to the stored device baseline profile that comprises: (i) the incoming ports associated with the processes, (ii) the outgoing ports associated with the processes, and (iii) the IP addresses associated with the processes, the deviating from the typical operation of the device including continually accessing a new website;

based on the determining, updating, by the monitoring program, the stored device baseline profile to create an updated device baseline profile with the new ones of data items if the new ones of data items do not deviate from the typical operation of the device; and

based on the determining, generating, by an alert module, an alert if the new ones of data items do deviate from the typical operation of the device.

2. The system of claim 1 , wherein the deviating from the typical operation of the device further includes transferring unusual amounts of data.

3. The system of claim 1 , wherein the deviating from the typical operation of the device further includes connecting to an unexpected one of the IP addresses.

4. The system of claim 1 , wherein the deviating from the typical operation of the device further includes using an infrequently used one of the incoming ports and the outgoing ports.

5. The system of claim 1 , wherein the irregularities comprise at least one of malware and fraud.

6. A method for detection of irregularities of a device, the method comprising:

reviewing, by a monitoring program running on a hardware processor, data items of a device;

detecting, by the monitoring program, a plurality of the data items relating to a typical operation of the device;

creating, by the monitoring program, a device baseline profile including the plurality of the data items relating to the typical operation of the device, the plurality of the data items comprising:

(i) incoming ports associated with processes,

(ii) outgoing ports associated with the processes, and

(iii) Internet Protocol (IP) addresses associated with the processes;

receiving, by the monitoring program, new ones of data items indicative of a current operation of the device;

determining, by the monitoring program, whether the new ones of data items deviate from the typical operation of the device by comparing the new ones of data items to the stored device baseline profile that comprises: (i) the incoming ports associated with the processes, (ii) the outgoing ports associated with the processes, and (iii) the IP addresses associated with the processes, wherein the deviating from the typical operation of the device includes using an infrequently used one of the incoming ports and the outgoing ports;

based on the determining, updating, by the monitoring program, the device baseline profile to create an updated device baseline profile with the new ones of data items if the new ones of data items do not deviate from the typical operation of the device; and

based on the determining, generating an alert if the new ones of data items do deviate from the typical operation of the device.

7. The method of claim 6 , wherein the deviating from the typical operation of the device further includes transferring unusual amounts of data.

8. The method of claim 6 , wherein the deviating from the typical operation of the device further includes continually accessing a new website.

9. The method of claim 6 , wherein the deviating from the typical operation of the device further includes connecting to an unexpected one of the IP addresses.

10. The method of claim 6 , wherein the irregularities comprise malware.

11. The method of claim 6 , wherein the irregularities comprise fraud.

12. A method for detection of irregularities in a network, the network comprising communications connections between at least one server, a computer, and a device having a plurality of outgoing connections and a plurality of incoming connections, the device running a plurality of processes, the method comprising:

receiving, by a monitoring program running on the computer, data items relating to the network, the device, and messages exchanged within the network;

automatically reviewing, by the monitoring program, the received data items;

detecting a plurality of the data items relating to a typical operation of the device;

creating, by the monitoring program, and storing in a database a device baseline profile including the plurality of the data items relating to the typical operation of the device, the plurality of the data items comprising: (i) incoming ports associated with processes, (ii) outgoing ports associated with the processes, and (iii) Internet Protocol (IP) addresses associated with the processes;

receiving, by the monitoring program, new ones of data items indicative of a current operation of the device;

determining, by the monitoring program, whether the new ones of data items deviate from the typical operation of the device by comparing the new ones of data items to the stored device baseline profile that comprises: (i) the incoming ports associated with the processes, (ii) the outgoing ports associated with the processes, and (iii) the IP addresses associated with the processes, wherein the deviating from the typical operation of the device includes using an infrequently used one of the incoming ports and outgoing ports; and continually accessing a new website;

based on the determining, updating, by the monitoring program, the stored device baseline profile to create an updated device baseline profile with the new ones of data items if the new ones of data items do not deviate from the typical operation of the device; and

based on the determining, generating an alert if the new ones of data items do deviate from the typical operation of the device.

13. The method of claim 12 , wherein the deviating from the typical operation of the device further includes transferring unusual amounts of data or connecting to an unexpected one of the IP addresses.

14. The method of claim 12 , wherein the irregularities comprise at least one of malware and fraud.

15. The method of claim 12 , wherein the monitoring program uses data sources for the data items based on network flow traffic statistics through the network.

16. The method of claim 15 , wherein the data sources include proxy logs and NetFlow records which record the destination of data sent through the outgoing connections and record the source of data received through the incoming connections.

17. The method of claim 12 , wherein the monitoring program analyzes:

headers in the data items and headers in email messages sent through the network.

Assignments (3)
CHANGE OF NAME Recorded Apr 6, 2021
From: ELASTICSEARCH B.V.
To: ELASTICSEARCH B.V.
Reel/Frame 055843/0215 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2018
From: DODSON, STEPHEN
To: PRELERT LTD.
Reel/Frame 046101/0648 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2018
From: PRELERT LIMITED
To: ELASTICSEARCH B.V.
Reel/Frame 046101/0932 →
Priority Claims (1)
GB 1316319.1 · Sep 13, 2013 · national
Continuity (2)
Continuation 14484633 · Sep 12, 2014
Related Publication 20170329965A1 · Nov 16, 2017