IP Library Granted Patent US 11,509,670
Granted Patent B2
US 11,509,670 · App. 16/202,217 · Granted Nov 22, 2022

Detecting anomalous network activity

Inventor: Dustin Myers (Alexandria, VA)
Assignee: Rapid7, Inc.
H04L63/1425G06F17/11
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,509,670
App. No.
16/202,217
Granted
Nov 22, 2022
Kind
B2
Abstract

Methods and systems for detecting anomalous network activity. The system may receive network metadata regarding activity on a network and generate at least one of a z-score and a directionality magnitude related to the network activity. The system may then issue an alert upon detecting an anomaly exists on the network based upon at least one of the generated z-score exceeding a z-score threshold and the generated directionality magnitude deviating from a baseline directionality magnitude.

Claims (41)

1. A method comprising:

performing, by a computing system implemented by one or more processors configured to execute instructions stored on a memory:

receiving network metadata of a network comprising:

a number of bytes sent from a host device in the network, and

a number of bytes sent to the host device;

calculating a directionality magnitude based on a ratio between the number of bytes sent from the host device and the number of bytes received by the host device, wherein the directionality magnitude is positive or negative depending on whether more bytes are sent or received by the host device;

generating a z-score based on the network metadata and previously received network metadata that was received before the network metadata, wherein generating the z-score includes performing a logarithmic transformation on the network metadata;

detecting that an anomaly exists on the network based at least on the z-score exceeding a z-score threshold and the directionality magnitude deviating from a baseline directionality magnitude; and

performing at least one mitigation procedure to mitigate the anomaly upon detecting that the anomaly exists.

2. The method of claim 1 , wherein the network metadata includes at least one feature of a connection, wherein the at least one feature comprises at least one of a time of the connection, a type of the connection, a connection duration, or a connection byte count.

3. The method of claim 2 , further comprising the computing system:

detecting that the anomaly exists upon determining that a plurality of features deviate from a feature baseline.

4. The method of claim 3 , further comprising the computing system:

detecting that the anomaly exists upon determining that a number of the at least one feature deviating from feature baselines exceed a feature threshold.

5. The method of claim 2 , further comprising the computing system:

suppressing an alert upon determining that a number of the at least one feature deviating from feature baselines is below a feature threshold.

6. The method of claim 1 , wherein the z-score is a directionality magnitude z-score.

7. A system comprising:

a computing system implemented by one or more processors and a memory that stores instructions executable by the one or more processors to:

receive, via an interface of the computing system, network metadata of a network including:

a number of bytes sent from a host device in the network, and

a number of bytes sent to the host device;

calculate a directionality magnitude based on a ratio between the number of bytes sent from the host device and the number of bytes received by the host device, wherein the directionality magnitude is positive or negative depending on whether more bytes are sent or received by the host device;

generate a z-score based on the network metadata and previously received network metadata that was received before the network metadata, wherein the generation of the z-score includes performing a logarithmic transformation on the network metadata;

detect that an anomaly exists on the network based at least on the z-score exceeding a z-score threshold and the directionality magnitude deviating from a baseline directionality magnitude; and

perform at least one mitigation procedure to mitigate the anomaly upon detecting that the anomaly exists.

8. The system of claim 7 , wherein the network metadata includes at least one feature of a connection, wherein the at least one feature comprises at least one of a time of the connection, a type of the connection, a connection duration, or a connection byte count.

9. The system of claim 8 , wherein the computing system is configured to detect that the anomaly exists upon determining that a plurality of features deviate from a feature baseline.

10. The system of claim 9 , wherein the computing system is configured to detect that the anomaly exists upon determining that a number of the at least one feature deviating from feature baselines exceed a feature threshold.

11. The system of claim 8 , wherein the computing system is configured to is configured to suppress an alert upon determining that a number of the at least one feature deviating from feature baselines is below a feature threshold.

12. The system of claim 7 , wherein the z-score is a directionality magnitude z-score.

13. A method comprising:

performing, by a computing system implemented by one or more processors configured to execute instructions stored on a memory:

receiving, using an interface of the computing system, network metadata regarding activity on a network, the network metadata including:

a count of bytes sent from a host device in the network, and

a count of bytes received by the host device;

calculating a directionality magnitude based on a ratio between the number of bytes sent from the host device and the number of bytes received by the host device, wherein the directionality magnitude is positive or negative depending on whether more bytes are sent or received by the host device;

generating a z-score based on the network metadata and previously received network metadata that was received before the network metadata, wherein generating the z-score includes performing a logarithmic transformation on the network metadata;

retrieving a baseline directionality magnitude value from a database, wherein the baseline directionality magnitude value is based on previous behavior of the host device;

determining that an anomaly exists on the network based at least on the z-score exceeding a z-score threshold and the directionality magnitude deviating from the baseline directionality magnitude value; and

performing at least one mitigation procedure upon determining that the anomaly exists on the network.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2019
From: MYERS, DUSTIN
To: RAPID7, INC.
Reel/Frame 048420/0530 →
Continuity (1)
Related Publication 20200169575A1 · May 28, 2020