IP Library Granted Patent US 11,750,628
Granted Patent B2
US 11,750,628 · App. 16/221,647 · Granted Sep 5, 2023

Profiling network entities and behavior

Inventors: Paul Deardorff (Durham, NC); Jonathan Hart (Kernville, CA); Oriana Ott (Somerville, MA)
Assignee: Rapid7, Inc.
H04L63/1425G06F16/285G06F16/288H04L41/142H04L41/147H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,750,628
App. No.
16/221,647
Granted
Sep 5, 2023
Kind
B2
Abstract

Methods and systems for monitoring activity on a network. The system may first classify network activity data as being generated by a human actor or an automated process. Then, the system may assign a first behavioral profile to the entity based on the network activity data and detect anomalous activity associated with the entity.

Claims (28)

1. A method for monitoring activity on a network, the method comprising:

performing, by a processor executing instructions stored on a memory:

receiving network activity data at an interface, wherein

the network activity data indicates commands executed by one or more entities in the network, and

the network activity data comprises one or more logs summarizing event sources comprising Secure Shell (SSH) connections, TeleTYpe (TTY) events, terminal activity, and shell input;

classifying the network activity data as being generated by an entity selected from the group consisting of a human actor and an automated process based on an analysis of the network activity data with respect to a plurality of behavioral cues comprising an amount of typographical errors in the commands, average timing between keystrokes in the commands, timing of network events, and use of control characters in the commands, wherein

the classifying comprises:

comparing the average timing between keystrokes to a predetermined timing threshold, and

comparing the amount of typographical errors to a predetermined typographical error threshold, and

the analysis of the network activity data is a distributed process where the one or more logs are sent to a plurality of nodes that process and split the network activity data into sessions so that the network activity data is processed in parallel;

assigning a behavioral profile to the entity based on the entity classification and the network activity data, wherein

the behavioral profile is switchable between a reconnaissance profile, a network pivoting profile, an exploitation behavior profile, and a data exfiltration profile based on the plurality of behavioral cues provided by the entity;

detecting, based on additional network activity data received from the interface, that an activity of the entity deviates from an expected behavior of the entity based on the behavioral profile; and

in response to detecting that the activity of the entity deviates from the expected behavior of the entity, issuing an alert identifying the activity of the entity as an anomalous activity.

2. A system comprising:

a processor for executing instructions stored on a memory to:

receive, via an interface, network activity data of the network, wherein

the network activity data indicates commands executed by one or more entities in the network, and

the network activity data comprises one or more logs summarizing event sources comprising Secure Shell (SSH) connections, TeleTYpe (TTY) events, terminal activity, and shell input;

classify the network activity data as being generated by an entity selected from the group consisting of a human actor and an automated process based on an analysis of the network activity data with respect to a plurality of behavioral cues including an amount of typographical errors in the commands, average timing between keystrokes in the commands, timing of network events, and use of control characters in the commands, wherein

to classify the network activity data, the processor is configured to:

compare the average timing between keystrokes to a predetermined timing threshold, and

compare the amount of typographical errors to a predetermined typographical error threshold, and

the analysis of the network activity data is a distributed process where the one or more logs are sent to a plurality of nodes that process and split the network activity data into sessions so that the network activity data is processed in parallel;

assign a behavioral profile to the entity based on the entity classification and the network activity data, wherein

the behavioral profile is switchable between a reconnaissance profile, a network pivoting profile, an exploitation behavior profile, and a data exfiltration profile based on the plurality of behavioral cues provided by the entity;

detect, based on additional network activity data received from the interface, that an activity of the entity deviates from an expected behavior of the entity based on the behavioral profile; and

in response to the detection that the activity of the entity deviates from the expected behavior of the entity, issue an alert identifying the activity of the entity as an anomalous activity.

Assignments (4)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2019
From: DEARDORFF, PAUL; HART, JONATHAN; OTT, ORIANA
To: RAPID7, INC.
Reel/Frame 048422/0062 →
Continuity (1)
Related Publication 20200195670A1 · Jun 18, 2020