IP Library Granted Patent US 10,771,490
Granted Patent B2
US 10,771,490 · App. 16/202,282 · Granted Sep 8, 2020

Detecting anomalous network device activity

Inventor: Dustin Myers (Alexandria, VA)
Assignee: Rapid7, Inc.
H04L63/1425H04L43/045H04L43/062H04L63/1433H04L63/168H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,771,490
App. No.
16/202,282
Granted
Sep 8, 2020
Kind
B2
Abstract

Methods and systems for detecting anomalous network device activity. The system may include an interface for receiving an identification label associated with a host device and pre-existing traffic data associated with the host device. The system may further detect that the pre-existing traffic data associated with the host device is anomalous based on the identification label. The system may then issue an alert upon detecting that the pre-existing traffic data associated with the host device is anomalous.

Claims (29)

1. A method for detecting anomalous network device activity, the method comprising:

receiving, using an interface, pre-existing traffic data associated with a host device;

analyzing, using a processor executing instructions stored on a memory, the pre-existing traffic data associated with the host device;

assigning, using the processor, an identification label to the host device based on the pre-existing traffic data;

assigning an expected behavioral parameter to the host device based on the identification label;

detecting the pre-existing traffic data deviates from the expected behavioral parameter;

classifying the pre-existing traffic data as anomalous based on the data deviating from the expected behavioral parameter; and

issuing, using the processor, an alert upon classifying the pre-existing traffic data associated with the host device as anomalous.

2. The method of claim 1 wherein analyzing the pre-existing traffic data includes analyzing at least one of source connection metadata and destination connection metadata.

3. The method of claim 1 wherein the identification label is based on previously-labeled host devices so that similar host devices with respect to traffic data are similarly labeled.

4. The method of claim 1 wherein analyzing the pre-existing traffic data associated with the host device includes determining the host device is a destination address for a web connection, and assigning the identification label includes labeling the host device as a web server.

5. The method of claim 1 wherein the pre-existing traffic data includes communication ports used by the host device.

6. The method of claim 1 wherein the host device is selected from the group consisting of a computer, laptop, router, firewall, phone, and server.

7. The method of claim 1 wherein the host device is a medical monitoring device.

8. A system for detecting anomalous network device activity, the system comprising:

an interface for receiving at least pre-existing traffic data associated with a host device; and

a memory and a processor executing instructions stored on the memory to:

analyze the pre-existing traffic data associated with the host device;

assign an identification label to the host device based on the pre-existing traffic data;

assign an expected behavioral parameter to the host device based on the identification label;

detect the pre-existing traffic data deviates from the expected behavioral parameter;

classify the pre-existing traffic data as anomalous based on the data deviating from the expected behavioral parameter; and

issue an alert upon classifying the pre-existing traffic data associated with the host device as anomalous.

9. The system of claim 8 wherein the processor is configured to analyze the pre-existing traffic data by analyzing at least one of source connection metadata and destination connection metadata.

10. The system of claim 8 wherein the identification label is based on previously-labeled host devices so that similar host devices with respect to traffic data are similarly labeled.

11. The system of claim 8 wherein the processor is further configured to determine the host device is a destination address for a web connection based on the pre-existing traffic data, and label the host device as a web server.

12. The system of claim 8 wherein the pre-existing traffic data includes communication ports used by the host device.

13. The system of claim 8 wherein the host device is selected from the group consisting of a computer, laptop, router, firewall, phone, and server.

14. The system of claim 8 wherein the host device is a medical monitoring device.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2019
From: MYERS, DUSTIN
To: RAPID7, INC.
Reel/Frame 048420/0201 →