IP Library Granted Patent US 10,812,504
Granted Patent B2
US 10,812,504 · App. 16/120,745 · Granted Oct 20, 2020

Systems and methods for cyber intrusion detection and prevention

Inventors: Benjamin Smith (Toronto, CA); Mohan Rao (Mississauga, CA); Sylvain Crozon (Toronto, CA); Niranjan Mayya (Mississauga, CA)
Assignee: 1262214 B.C. UNLIMITED LIABILITY COMPANY
H04L63/1416G06F21/55H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,812,504
App. No.
16/120,745
Granted
Oct 20, 2020
Kind
B2
Abstract

Systems and methods for detecting cyber attacks on a computer network are provided. The system trains attack and detection models. The attack model is used to synthesize network traffic for transmission to a detection model. The detection model is used to make a determination as to whether an attack is occurring. The results of the determination are used as training data for the attack and detection models.

Claims (42)

1. A method of detecting cyber attacks in a computer network, the method comprising:

training an attack model using a first artificial neural network, said training said attack model being based on at least one of an attack database, previous network behavior, and previous network traffic patterns;

training a detection model using a second artificial neural network, said training said detection model being based on at least one of the previous network behavior and the previous network traffic patterns;

synthesizing, by an attack module, an attack vector based on the attack model;

transmitting the attack vector to a detection module;

determining, by the detection module, whether an attack is taking place;

updating at least one of the attack model and the detection model based on correctness of the determination made by the detection module; and

responsive to the determination of the detection module being correct, incrementing a detection model score.

2. The method of claim 1 , further comprising:

receiving network traffic at the detection module; and

outputting, by the detection module, an output vector based on the received network traffic.

3. The method of claim 2 , wherein the output vector indicates that an attack is taking place.

4. The method of claim 3 , wherein the output vector comprises an identity of a host executing an attack.

5. The method of claim 2 , wherein the output vector comprises a flag indicating the absence of an attack.

6. The method of claim 2 , further comprising:

receiving, at the detection module, application logs from at least one of an application running in the computer network and an application running in a distributed computing system.

7. The method of claim 1 , further comprising:

responsive to the determination of the detection module being incorrect, incrementing an attack model score.

8. The method of claim 7 , further comprising decrementing the detection model score.

9. The method of claim 1 , further comprising decrementing an attack model score.

10. A system for detecting cyber attacks on a computer network, the system comprising:

a processor;

a memory containing computer-readable instructions for execution by said processor, said instructions, when executed by said processor, causing the processor to:

train an attack model using a first artificial neural network, said training said attack model being based on at least one of an attack database, previous network behavior, and previous network traffic patterns;

train a detection model using a second artificial neural network, said training said detection model being based on at least one of the previous network behavior and the previous network traffic patterns;

synthesize, by an attack module, an attack vector based on the attack model;

transmit the attack vector to a detection module;

determine, by the detection module, whether an attack is taking place;

update at least one of the attack model and the detection model based on correctness of the determination made by the detection module; and

responsive to the determination of the detection module being correct, incrementing a detection model score.

11. The system of claim 10 , wherein the instructions further cause the processor to:

receive network traffic at the detection module; and

output, by the detection module, an output vector based on the received network traffic.

12. The system of claim 11 , wherein the output vector indicates that an attack is taking place.

13. The system of claim 12 , wherein the output vector comprises an identity of a host executing an attack.

14. The system of claim 11 , wherein the output vector comprises a flag indicating the absence of an attack.

15. The system of claim 11 , wherein the instructions further cause the processor to:

receive, at the detection module, application logs from at least one of an application running in the computer network and an application running in a distributed computing system.

16. The system of claim 10 , wherein the instructions further cause the processor to:

responsive to the determination of the detection module being incorrect, incrementing an attack model score.

17. The system of claim 16 , wherein the instructions further cause the processor to decrement the detection model score.

18. The system of claim 10 , wherein the instructions further cause the processor to decrement an attack model score.

Assignments (7)
PATENT SECURITY AGREEMENT Recorded Feb 4, 2025
From: ARCTIC WOLF NETWORKS, INC.
To: BLUE OWL TECHNOLOGY FINANCE CORP., AS COLLATERAL AGENT
Reel/Frame 070110/0881 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2022
From: SMITH, BENJAMIN; RAO, MOHAN; CROZON, SYLVAIN; MAYYA, NIRANJAN
To: RANK SOFTWARE INC.
Reel/Frame 062107/0939 →
RELEASE OF SECURITY INTEREST Recorded Sep 30, 2022
From: GOLUB CAPITAL LLC
To: ARCTIC WOLF NETWORKS, INC.
Reel/Frame 061277/0161 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 2, 2020
From: 1262214 B.C. UNLIMITED LIABILITY COMPANY
To: ARCTIC WOLF NETWORKS, INC.
Reel/Frame 053964/0530 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2020
From: RANK SOFTWARE INC.
To: 1262214 B.C. UNLIMITED LIABILITY COMPANY
Reel/Frame 053727/0295 →
SECURITY INTEREST Recorded Aug 31, 2020
From: ARCTIC WOLF NETWORKS, INC.
To: GOLUB CAPITAL LLC, AS AGENT
Reel/Frame 053649/0580 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2019
From: SMITH, BENJAMIN; RAO, MOHAN; CROZON, SYLVAIN; MAYYA, NIRANJAN
To: RANK SOFTWARE INC.
Reel/Frame 049774/0400 →
Continuity (2)
Provisional Application 62554698 · Sep 6, 2017
Related Publication 20190075123A1 · Mar 7, 2019