IP Library Granted Patent US 10,476,754
Granted Patent B2
US 10,476,754 · App. 15/902,432 · Granted Nov 12, 2019

Behavior-based community detection in enterprise information networks

Inventors: Zhengzhang Chen (Princeton Junction, NJ); LuAn Tang (Pennington, NJ); Zhichun Li (Princeton, NJ); Cheng Cao (Bellevue, WA)
Assignee: NEC Corporation
H04L41/145G06F21/554H04L41/142H04L63/1416H04L63/1441H04L43/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,476,754
App. No.
15/902,432
Granted
Nov 12, 2019
Kind
B2
Abstract

Methods and systems for detecting host community include modeling a target host's behavior based on historical events recorded at the target host. One or more original peer hosts having behavior similar to the target host's behavior are found by determining a distance in a latent space that embeds the historical events between events of the target host and events of the one or more original peer hosts. A security management action is performed based on behavior of the target host and the determined one or more original peer hosts.

Claims (21)

1. A method for detecting host community, comprising:

embedding historical events, recorded at a target host, in a latent space using a negative sampling that approximates a maximized conditional probability that an event will occur at a target host;

modeling the target host's behavior based on the embedded historical events, wherein the target host is modeled as a context of process-level events and as a context of all hosts reached by network events of the target host and wherein each process-level event on the target host is modeled as a conditional probability of the target host given the event;

determining one or more original peer hosts having behavior similar to the target host's behavior by determining a distance in a latent space that embeds the historical events between events of the target host and events of the one or more original peer hosts; and

performing a security management action based on behavior of the target host and the determined one or more original peer hosts.

2. The method of claim 1 , wherein determining one or more peer hosts comprises clustering hosts based on distance in the latent space.

3. The method of claim 2 , wherein clustering comprises identifying a set of initial cluster centroids and iteratively updating the centroids after assigning hosts to a closest cluster.

4. The method of claim 1 , wherein performing the security management action comprises determining an anomaly score based on a comparison between behavior of one or more new peer hosts and behavior of the one or more original peer hosts.

5. The method of claim 1 , wherein performing the security management action comprises determining an anomaly score based on a similarity between new events recorded at the target host and new events recorded at the one or more original peer hosts.

6. The method of claim 1 , wherein performing the security action further comprises automatically performing at least one security action selected from the group consisting of shutting down devices, stopping or restricting certain types of network communication, raising alerts to system administrators, and changing a security policy level.

7. The method of claim 1 , wherein each network event is modeled as a conditional probability that one host issues a network event that connects to another host.

8. A system for detecting host community, comprising:

a host behavior module configured to embed historical events, recorded at a target host, in a latent space using a negative sampling that approximates a maximized conditional probability that an event will occur at the target host, and to model the target host's behavior based on the embedded historical events, to model the target host as a context of process-level events and as a context of all hosts reached by network events of the target host, and to model each process-level event on the target host as a conditional probability of the target host given the event;

a peer host module comprising a processor configured to determine one or more original peer hosts having behavior similar to the target host's behavior by determining a distance in a latent space that embeds the historical events between events of the target host and events of the one or more original peer hosts; and

a security module configured to perform a security management action based on behavior of the target host and the determined one or more original peer hosts.

9. The system of claim 8 , wherein the peer host module is further configured to cluster hosts based on distance in the latent space.

10. The system of claim 9 , wherein the peer host module is further configured to identify a set of initial cluster centroids and iteratively update the centroids after assigning hosts to a closest cluster.

11. The system of claim 8 , further comprising an anomaly score module configured to determine an anomaly score for use by the security module based on a comparison between behavior of one or more new peer hosts and behavior of the one or more original peer hosts.

12. The system of claim 8 , further comprising an anomaly score module configured to determine an anomaly score for use by the security module based on a similarity between new events recorded at the target host and new events recorded at the one or more original peer hosts.

13. The system of claim 8 , wherein the security module is further configured to automatically perform at least one security action selected from the group consisting of shutting down devices, stopping or restricting certain types of network communication, raising alerts to system administrators, and changing a security policy level.

14. The system of claim 8 , wherein the host behavior module is further configured to model each network event as a conditional probability that one host issues a network event that connects to another host.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2024
From: IP WAVE PTE LTD.
To: CLOUD BYTE LLC.
Reel/Frame 067944/0332 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2024
From: NEC ASIA PACIFIC PTE LTD.
To: IP WAVE PTE LTD.
Reel/Frame 066376/0276 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2023
From: NEC CORPORATION
To: NEC ASIA PACIFIC PTE LTD.
Reel/Frame 066124/0752 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2019
From: NEC LABORATORIES AMERICA, INC.
To: NEC CORPORATION
Reel/Frame 050498/0081 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 22, 2018
From: CHEN, ZHENGZHANG; TANG, LUAN; LI, ZHICHUN; CAO, CHENG
To: NEC LABORATORIES AMERICA, INC.
Reel/Frame 045005/0728 →
Continuity (4)
Continuation In Part 15098861 · Apr 14, 2016
Provisional Application 62463976 · Feb 27, 2017
Provisional Application 62148232 · Apr 16, 2015
Related Publication 20180183681A1 · Jun 28, 2018