IP Library Granted Patent US 11,005,868
Granted Patent B2
US 11,005,868 · App. 16/138,553 · Granted May 11, 2021

Methods, systems, and media for detecting anomalous network activity

Inventors: Sherin M. Mathews (Santa Clara, CA); Vaisakh Shaj (Kollam, IN); Sriranga Seetharamaiah (Bangalore, IN); Carl D. Woodward (Santa Clara, CA); Kantheti VVSMB Kumar (Bangalore, IN)
Assignee: McAfee, LLC
H04L63/1425G06N3/02G06N20/00H04L41/0893H04L41/142H04L41/145H04L43/045H04L61/6068H04L63/1441G06F16/9024
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,005,868
App. No.
16/138,553
Granted
May 11, 2021
Kind
B2
Abstract

Methods, systems, and media for detecting anomalous network activity are provided. In some embodiments, a method for detecting anomalous network activity is provided, the method comprising: receiving information indicating network activity, wherein the information includes IP addresses corresponding to devices participating in the network activity; generating a graph representing the network activity, wherein each node of the graph indicates an IP address of a device; generating a representation of the graph, wherein the representation of the graph reduces a dimensionality of information indicated in the graph; identifying a plurality of clusters of network activity based on the representation of the graph; determining that at least one cluster corresponds to anomalous network activity; and in response to determining that the at least one cluster corresponds to anomalous network activity, causing a network connection of at least one device included in the at least one cluster to be blocked.

Claims (35)

1. A method for detecting anomalous network activity, comprising:

receiving information indicating network activity on a network, wherein the information includes a plurality of IP addresses corresponding to a plurality of devices participating in the network activity and information relating to packets transmitted between devices included in the plurality of devices participating in the network activity;

generating, by a hardware processor, a weighted directed graph representing the network activity, wherein the weighted directed graph has a plurality of nodes and has an edge between two of the plurality of nodes, wherein each node of the graph indicates an IP address of a device participating in the network activity, and wherein the edge has at least three weights represented as a vector, wherein the weights include a number of connections between the two of the plurality of nodes, an average number of bytes per packet sent between the two of the plurality of nodes, and a number of ports scanned;

generating a representation of the graph representing the network activity, wherein the representation of the graph representing the network activity reduces a dimensionality of information indicated in the graph representing the network activity;

identifying a plurality of clusters of network activity based on the representation of the graph representing the network activity;

determining that at least one cluster of the plurality of clusters corresponds to anomalous network activity; and

in response to determining that the at least one cluster of the plurality of clusters corresponds to anomalous network activity, causing a network connection of at least one device included in the at least one cluster to be blocked.

2. The method of claim 1 , wherein the graph representing the network activity is generated using a subset of the plurality of IP addresses, wherein the subset of the plurality of IP addresses corresponds to a group of IP addresses having the most network connections and wherein the subset of the plurality of IP addresses contains fewer than all of the plurality of IP addresses.

3. The method of claim 1 , wherein identifying the plurality of clusters of network activity is based on a machine learning classifier.

4. The method of claim 1 , wherein identifying the plurality of clusters of network activity is based on a neural network.

5. The method of claim 1 , wherein generating the representation of the graph representing the network activity comprises applying a t-Stochastic Neighbor Embedding (t-SNE) technique to the graph representing the network activity.

6. A system for detecting anomalous network activity, the system comprising:

a memory; and

a hardware processor coupled to the memory that is configured to:

receive information indicating network activity on a network, wherein the information includes a plurality of IP addresses corresponding to a plurality of devices participating in the network activity and information relating to packets transmitted between devices included in the plurality of devices participating in the network activity;

generate a weighted directed graph representing the network activity, wherein the weighted directed graph has a plurality of nodes and has an edge between two of the plurality of nodes, wherein each node of the graph indicates an IP address of a device participating in the network activity, and wherein the edge has at least three weights represented as a vector, wherein the weights include a number of connections between the two of the plurality of nodes, an average number of bytes per packet sent between the two of the plurality of nodes, and a number of ports scanned;

generate a representation of the graph representing the network activity, wherein the representation of the graph representing the network activity reduces a dimensionality of information indicated in the graph representing the network activity;

identify a plurality of clusters of network activity based on the representation of the graph representing the network activity;

determine that at least one cluster of the plurality of clusters corresponds to anomalous network activity; and

in response to determining that the at least one cluster of the plurality of clusters corresponds to anomalous network activity, cause a network connection of at least one device included in the at least one cluster to be blocked.

7. The system of claim 6 , wherein the graph representing the network activity is generated using a subset of the plurality of IP addresses, wherein the subset of the plurality of IP addresses corresponds to a group of IP addresses having the most network connections and wherein the subset of the plurality of IP addresses contains fewer than all of the plurality of IP addresses.

8. The system of claim 6 , wherein identifying the plurality of clusters of network activity is based on a machine learning classifier.

9. The system of claim 6 , wherein identifying the plurality of clusters of network activity is based on a neural network.

10. The system of claim 6 , wherein generating the representation of the graph representing the network activity comprises applying a t-Stochastic Neighbor Embedding (t-SNE) technique to the graph representing the network activity.

11. A non-transitory computer-readable medium containing computer-executable instructions that, when executed by a processor, cause the processor to perform a method for detecting anomalous network activity, the method comprising:

receiving information indicating network activity on a network, wherein the information includes a plurality of IP addresses corresponding to a plurality of devices participating in the network activity and information relating to packets transmitted between devices included in the plurality of devices participating in the network activity;

generating a weighted directed graph representing the network activity, wherein the weighted directed graph has a plurality of nodes and has an edge between two of the plurality of nodes, wherein each node of the graph indicates an IP address of a device participating in the network activity, and wherein the edge has at least three weights represented as a vector, wherein the weights include a number of connections between the two of the plurality of nodes, an average number of bytes per packet sent between the two of the plurality of nodes, and a number of ports scanned;

generating a representation of the graph representing the network activity, wherein the representation of the graph representing the network activity reduces a dimensionality of information indicated in the graph representing the network activity;

identifying a plurality of clusters of network activity based on the representation of the graph representing the network activity;

determining that at least one cluster of the plurality of clusters corresponds to anomalous network activity; and

in response to determining that the at least one cluster of the plurality of clusters corresponds to anomalous network activity, causing a network connection of at least one device included in the at least one cluster to be blocked.

12. The non-transitory computer-readable medium of claim 11 , wherein the graph representing the network activity is generated using a subset of the plurality of IP addresses, wherein the subset of the plurality of IP addresses corresponds to a group of IP addresses having the most network connections and wherein the subset of the plurality of IP addresses contains fewer than all of the plurality of IP addresses.

13. The non-transitory computer-readable medium of claim 11 , wherein identifying the plurality of clusters of network activity is based on a machine learning classifier.

14. The non-transitory computer-readable medium of claim 11 , wherein identifying the plurality of clusters of network activity is based on a neural network.

15. The non-transitory computer-readable medium of claim 11 , wherein generating the representation of the graph representing the network activity comprises applying a t-Stochastic Neighbor Embedding (t-SNE) technique to the graph representing the network activity.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2018
From: MATHEWS, SHERIN M.; SHAJ, VAISAKH; SEETHARAMAIAH, SRIRANGA; WOODWARD, CARL D.; KUMAR, KANTHETI VVSMB
To: MCAFEE, LLC
Reel/Frame 047551/0838 →
Continuity (1)
Related Publication 20200099708A1 · Mar 26, 2020
Cited By (1)
US 12,675,792