IP Library Granted Patent US 10,735,448
Granted Patent B2
US 10,735,448 · App. 16/109,379 · Granted Aug 4, 2020

Network anomaly detection

Inventors: Maxim Kesin (Woodmere, NY); Samuel Jones (New York City, NY)
Assignee: Palantir Technologies Inc.
H04L63/1425G06N7/005H04L61/2007H04L63/083H04L63/12H04L63/1416H04L67/22H04L2463/143
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,735,448
App. No.
16/109,379
Granted
Aug 4, 2020
Kind
B2
Abstract

A security system detects anomalous activity in a network. The system logs user activity, which can include ports used, compares users to find similar users, sorts similar users into cohorts, and compares new user activity to logged behavior of the cohort. The comparison can include a divergence calculation. Origins of user activity can also be used to determine anomalous network activity. The hostname, username, IP address, and timestamp can be used to calculate aggregate scores and convoluted scores.

Claims (71)

1. A computer-implemented method for detecting an anomalous activity in a network, the method being implemented by one or more computer readable storage devices configured to store computer executable instructions, and by one or more hardware computer processors in communication with the one or more computer readable storage devices configured to execute the computer executable instructions, the method comprising:

logging, to the one or more computer readable storage devices, user activity for a plurality of users in the network;

sorting the plurality of users into a plurality of cohorts;

detecting a new activity by a first user of the plurality of users, wherein the first user is sorted into a first cohort of the plurality of cohorts;

determining a geographic region from which the new activity originated;

determining attack origin distribution data, wherein the attack origin distribution data includes statistical information of network attacks originating in a plurality of countries, and wherein the attack origin distribution data further includes at least a first probability that network attacks originate from the geographic region;

determining network activity origin distribution data, wherein the network activity origin distribution data is based on an analysis of origins of network activity over a period of time, and wherein the network activity origin distribution data further includes at least a second probability of network activity originating from the geographic region, wherein the network activity includes both malicious and non-malicious traffic;

determining a third probability of a network attack;

generating a statistical probability that the new activity is the network attack based at least in part on a combination of the first probability, the second probability, and the third probability; and

generating an indicator of a potential anomaly for display based at least in part on the statistical probability.

2. The method of claim 1 , wherein determining the statistical probability that the new activity is the network attack is further based, at least in part, on attack origin distribution data indicating geographic origin distribution statistics about a plurality of geographic regions where known network attacks have originated.

3. The method of claim 2 , further comprising:

receiving the attack origin distribution data for the plurality of countries; and

interpolating attack origin distribution data for a country not in the plurality of countries.

4. The method of claim 1 , further comprising:

comparing the geographic region to geographic origins of logged activity of the first user to generate a second comparison result; and

comparing the geographic region of the new activity to geographic origins of logged activity of the first cohort to generate a third comparison result;

wherein generating the indicator of the potential anomaly is further based, at least in part, on the second comparison result and the third comparison result.

5. The method of claim 1 , wherein the statistical probability exceeds a threshold probability, the method further comprising:

taking one or more initial network security measures in response to the statistical probability exceeding the threshold;

receiving a user confirmation that the new activity is anomalous; and

in response to receiving the user confirmation, taking one or more additional network security measures that are different from the one or more initial network security measures.

6. The method of claim 1 , wherein the second probability of the network activity originating from the geographic region is a fraction of the user activity from users of the first cohort that originated from the geographic region.

7. The computer-implemented method of claim 1 , wherein the combination of the first probability, the second probability, and the third probability is a result of a mathematical operation including the first probability, the second probability, and the third probability.

8. The computer-implemented method of claim 1 , wherein the combination of the first probability, the second probability, and the third probability includes the first probability divided by the second probability.

9. A computer system comprising:

one or more computer readable storage devices configured to store computer executable instructions; and

one or more hardware computer processors configured to execute the computer executable instructions in order to cause the computer system to:

log, to one or more computer readable storage devices, user activity for a plurality of users in a network;

sort the plurality of users into a plurality of cohorts;

detect a new activity by a first user of the plurality of users, wherein the first user is sorted into a first cohort of the plurality of cohorts;

determine a geographic region from which the new activity originated;

determine attack origin distribution data, wherein the attack origin distribution data includes statistical information of network attacks originating in a plurality of countries, and wherein the attack origin distribution data further includes at least a first probability that network attacks originate from the geographic region; and

determine network activity origin distribution data, wherein the network activity origin distribution data is based on an analysis of origins of network activity over a period of time, and wherein the network activity origin distribution data further includes at least a second probability that network activity through the network originated from the geographic region, wherein the network activity includes both malicious and non-malicious traffic;

determine a third probability of a network attack;

generate, a statistical probability that the new activity is the network attack based at least in part on a combination of the first probability, the second probability, and the third probability; and

generate an indicator of a potential anomaly for display based at least in part on the statistical probability.

10. The computer system of claim 9 , wherein determining the statistical probability that the new activity is the network attack is further based, at least in part, on attack origin distribution data indicating geographic origin distribution statistics about a plurality of geographic regions where known network attacks have originated.

11. The computer system of claim 10 , wherein the one or more hardware processors are further configured to cause the computer system to:

receive the attack origin distribution data for the plurality of countries; and

interpolate attack origin distribution data for a country not in the plurality of countries.

12. The computer system of claim 9 , wherein the one or more hardware processors are further configured to cause the computer system to:

compare the geographic region to geographic origins of logged activity of the first user to generate a second comparison result; and

compare the geographic region to geographic origins of logged activity of the first cohort to generate a third comparison result;

wherein generating the indicator of the potential anomaly is further based, at least in part, on the second comparison result and the third comparison result.

13. The computer system of claim 9 , wherein the statistical probability exceeds a threshold probability, and wherein the one or more hardware processors are further configured to cause the computer system to:

take one or more initial network security measures in response to the statistical probability exceeding the threshold;

receive a user confirmation that the new activity is anomalous; and

in response to receiving the user confirmation, take one or more additional network security measures that are different from the one or more initial network security measures.

14. The computer system of claim 9 , wherein the second probability of the network activity originating from the geographic region is a fraction of the user activity from users of the first cohort that originated from the geographic region.

15. A method for detecting anomalous network activity, the method comprising:

logging user activity for a plurality of users through a network;

sorting the plurality of users into a plurality of cohorts;

detecting a new activity by a first user of a first plurality of users, wherein the first user is sorted into a first cohort of the plurality of cohorts;

determining attack origin distribution data, wherein the attack origin distribution data includes statistical information of network attacks originating in a plurality of countries, and wherein the attack origin distribution data further includes at least a first probability of network attacks originate from the geographic region;

determining network activity origin distribution data, wherein the network activity origin distribution data is based on an analysis of origins of network activity over a period of time, and wherein the network activity origin distribution data further includes at least a second probability of network activity originating from the geographic region, wherein the network activity includes both malicious and non-malicious traffic;

determining a third probability of a network attack;

generating a statistical probability that the new activity is the network attack based at least in part on a combination of the first probability, the second probability, and the third probability; and

generating an indicator of a potential anomaly for display based at least in part on the statistical probability.

16. The method of claim 15 , wherein determining the statistical probability that the new activity is the network attack is further based, at least in part, on attack origin distribution data indicating geographic origin distribution statistics of network activity that are known to be network attacks.

17. The method of claim 16 , further comprising:

receiving the attack origin distribution data for the plurality of countries; and

interpolating attack origin distribution data for a country not in the plurality of countries.

18. The method of claim 15 , further comprising:

comparing the geographic region to geographic origins of logged activity of the first user to generate a second comparison result; and

comparing the geographic region to geographic origins of logged activity of the first cohort to generate a second comparison result;

wherein generating the indicator of the potential anomaly is further based, at least in part, on the second comparison result and a third comparison result.

19. The method of claim 15 , wherein the statistical probability exceeds a threshold probability, the method further comprising:

taking one or more initial network security measures in response to the statistical probability exceeding the threshold;

receiving a user confirmation that the new activity is anomalous; and

in response to receiving the user confirmation, taking one or more additional network security measures that are different from the one or more initial network security measures.

Assignments (8)
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2020
From: KESIN, MAXIM; JONES, SAMUEL
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 053029/0549 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
Continuity (6)
Continuation 15462540 · Mar 17, 2017
Continuation 15224443 · Jul 29, 2016
Continuation 14970317 · Dec 15, 2015
Provisional Application 62207297 · Aug 19, 2015
Provisional Application 62185453 · Jun 26, 2015
Related Publication 20190007441A1 · Jan 3, 2019
Cited By (7)
US 12,204,657 US 12,248,566 US 12,411,962 US 12,530,255 US 12,561,428 US 12,596,792 US 12,652,263