IP Library Granted Patent US 10,986,121
Granted Patent B2
US 10,986,121 · App. 16/392,381 · Granted Apr 20, 2021

Multivariate network structure anomaly detector

Inventors: Jack Stockdale (Cambridge, GB); Stephen Casey (Cambridge, GB); Anthony Preston (Berkshire, GB)
Assignee: Darktrace Limited
H04L63/145G06N20/00H04L43/12H04L63/1416H04L63/1425H04L63/1433H04L63/1491H04L63/20H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,986,121
App. No.
16/392,381
Granted
Apr 20, 2021
Kind
B2
Abstract

A multivariate anomaly detector can detect a cyber-attack using incremental malicious actions distributed across multiple devices in a network. A multivariate anomaly detector can collect input data describing communication connections between devices in the network. The multivariate anomaly detector can group the input data into a graph data batch based on a fixed batch increment of time to identify incremental actions. The multivariate anomaly detector can calculate a multivariate centrality score for two or more devices based on the graph data batch describing device centrality to the network. The multivariate anomaly detector can identify whether the two or more devices are in an anomalous state from normal device network interactions based on the multivariate centrality score to identify malicious activity distributed across multiple devices in the network. The multivariate anomaly detector can identify a cyber-attack upon identifying the incremental malicious actions distributed across multiple devices in the network.

Claims (41)

1. A method for a cyber threat defense system, comprising:

detecting a cyber-attack using incremental malicious actions distributed across multiple devices in a network;

collecting input data describing communication connections between devices in the network;

grouping the input data into a graph data batch based on a fixed batch increment of time to identify incremental actions;

calculating a multivariate centrality score for two or more devices based on the graph data batch describing device centrality to the network;

identifying whether the two or more devices are in an anomalous state from normal device network interactions based on the multivariate centrality score in order to identify the malicious activity distributed across multiple devices in the network; and

generating a notification about the cyber-attack using the incremental malicious actions distributed across multiple devices in the network.

2. The method for the cyber threat defense system of claim 1 , further comprising:

comparing the multivariate centrality score to a multivariate centrality score history to identify the malicious activity distributed across multiple devices in the network.

3. The method for the cyber threat defense system of claim 1 , further comprising:

generating a graph with nodes to represent devices in the network and edges of the graph to represent connections between the devices in the network.

4. The method for the cyber threat defense system of claim 3 , further comprising:

calculating the multivariate centrality score for two or more nodes representing two or more devices based on the graph data batch describing device centrality to the network using a different heuristic for each variate of the multivariate centrality score in order to identify at least a first node and a second node both acting in the anomalous state from the normal device network interactions.

5. The method for the cyber threat defense system of claim 1 , further comprising:

using the graph data batch to calculate a network binding score describing a connection density of a first node with other nodes in the network as a variate of the multivariate centrality score.

6. The method for the cyber threat defense system of claim 1 , further comprising:

using the graph data batch to calculate an eigenvector centrality score describing an influence of a first node on the network by weighting connections to other influential nodes as a variate of the multivariate centrality score.

7. The method for the cyber threat defense system of claim 1 , further comprising:

collecting a score history over a maturation period for each variate of the multivariate centrality score.

8. The method for the cyber threat defense system of claim 1 , further comprising:

computing a matrix of two-point correlations between each variate of the multivariate centrality score.

9. The method for the cyber threat defense system of claim 1 , further comprising:

using the graph data batch to calculate an access entropy score describing a diversity of visited nodes by a first node as a variate of the multivariate centrality score.

10. A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in the cyber threat defense system to instruct a computing device to perform the method of claim 1 .

11. A multivariate anomaly detector, comprising:

a cyber-threat module configured to detect a cyber-attack using incremental malicious actions distributed across multiple devices in a network;

an ingestion module configured to collect input data describing communication connections between devices in the network;

a batch module configured to group the input data from the ingestion module into a graph data batch based on a fixed batch increment of time to identify incremental actions;

a centrality processing module configured to calculate a multivariate centrality score for two or more devices based on the graph data batch describing device centrality to the network from the batch module;

an anomaly detector module configured to identify whether the two or more devices are in an anomalous state from normal device network interactions based on the multivariate centrality score in order to identify the malicious activity distributed across multiple devices in the network; and

a user interface module to generate a notification about the cyber-attack using the incremental malicious actions distributed across multiple devices in the network.

12. The multivariate anomaly detector of claim 11 , wherein the anomaly detector module is further configured to compare the multivariate centrality score to a multivariate centrality score history to identify the malicious activity distributed across multiple devices in the network.

13. The multivariate anomaly detector of claim 11 , further comprising:

a graph detection module configured to generate a graph with nodes to represent devices in the network and edges of the graph to represent connections between the devices in the network.

14. The multivariate anomaly detector of claim 13 , wherein the centrality processing module is further configured to calculate the multivariate centrality score for two or more nodes representing two or more devices based on the graph data batch describing device centrality to the network using a different heuristic for each variate of the multivariate centrality score in order to identify at least a first node and a second node both acting in the anomalous state from the normal device network interactions.

15. The multivariate anomaly detector of claim 11 , wherein the centrality processing module is further configured use the graph data batch to calculate a network binding score describing a connection density of a first node with other nodes in the network as a variate of the multivariate centrality score.

16. The multivariate anomaly detector of claim 11 , wherein the centrality processing module is further configured to use the graph data batch to calculate an eigenvector centrality score describing an influence of a first node on the network by weighting connections to other influential nodes as a variate of the multivariate centrality score.

17. The multivariate anomaly detector of claim 11 , wherein the anomaly detector module is further configured to collect a score history over a maturation period for each variate of the multivariate centrality score.

18. The multivariate anomaly detector of claim 11 , wherein the anomaly detector module is further configured to compute a matrix of two-point correlations between each variate of the multivariate centrality score.

19. The multivariate anomaly detector of claim 11 , wherein the anomaly detector module is further configured to feed an anomaly radius for the multivariate centrality score into a probabilistic distribution such as a one-tail Cauchy distribution to compute a survival probability.

20. The multivariate anomaly detector of claim 11 , wherein the centrality processing module is configured use the graph data batch to calculate an access entropy score describing a diversity of visited nodes by a first node as a variate of the multivariate centrality score.

Assignments (6)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
TERMINATION AND RELEASE OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 1, 2023
From: HSBC INNOVATION BANK LIMITED
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 065741/0608 →
CHANGE OF NAME Recorded Nov 3, 2021
From: DARKTRACE LIMITED
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 058011/0718 →
SECURITY INTEREST Recorded Jan 22, 2021
From: DARKTRACE LIMITED
To: SILICON VALLEY BANK
Reel/Frame 054996/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 23, 2019
From: STOCKDALE, JACK; CASEY, STEPHEN; PRESTON, ANTHONY
To: DARKTRACE LIMITED
Reel/Frame 048974/0921 →
Continuity (2)
Provisional Application 62796507 · Jan 24, 2019
Related Publication 20200244673A1 · Jul 30, 2020
Cited By (57)
US 50,632 US 12,196,437 US 12,197,299 US 12,197,508 US 12,210,324 US 12,229,156 US 12,231,255 US 12,231,496 US 12,235,617 US 12,270,560 US 12,271,163 US 12,273,215 US 12,292,720 US 12,299,155 US 12,333,657 US 12,339,825 US 12,341,624 US 12,346,381 US 12,349,027 US 12,367,443 US 12,372,955 US 12,379,718 US 12,386,827 US 12,393,611 US 12,395,818 US 12,399,467 US 12,399,475 US 12,400,035 US 12,405,581 US 12,406,193 US 12,412,003 US 12,432,277 US 12,474,679 US 12,481,259 US 12,506,768 US 12,523,975 US 12,523,999 US 12,529,491 US 12,530,255 US 12,541,182 US 12,542,830 US 12,554,687 US 12,556,893 US 12,572,267 US 12,578,696 US 12,579,874 US 12,597,772 US 12,598,207 US 12,664,444 US 12,669,790 US 12,687,827 US 12,687,831 US 12,688,437 US 12,699,367 US 12,699,732 US 12,711,287 US 12,711,288