IP Library Granted Patent US 11,586,962
Granted Patent B2
US 11,586,962 · App. 16/725,906 · Granted Feb 21, 2023

Adaptive device type classification

Inventors: Galina Alperovich (Saint Petersburg, RU); Dmitry Kuznetsov (Yekaterinburg, RU); Rajarshi Gupta (Los Altos, CA)
Assignee: Avast Software s.r.o.
G06N7/005G06N5/027G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,586,962
App. No.
16/725,906
Granted
Feb 21, 2023
Kind
B2
Abstract

Systems and methods for device type classification system include a rules engine and a machine learning engine. The machine learning engine can be trained using device type data from multiple networks. The machine learning engine and the rules engine can receive data for devices on a network at a first point in time. The data can be submitted to a rules engine and the machine learning engine, which each produce device type probabilities for devices on the network. The device type probabilities from the rules engine and the machine learning engine can be processed to determine device types for one or more devices on the network. As more data becomes available at later points in time, the additional data can be provided to the rules engine and the machine learning engine to update the device type determinations for the network.

Claims (86)

1. A method for classifying device types on a network, the method comprising:

training a machine learning model, comprising:

receiving device data from a plurality of devices on a plurality of networks;

determining a data set from the device data;

clustering the data set to produce a first set of clusters;

receiving labels for a set of largest clusters in the first set of clusters to produce a labeled data set;

training one or more classifiers of the machine learning model based on the labels to produce a classified data set and an unclassified data set; and

repeating, until a stopping condition is met, the operations of:

clustering the unclassified data set,

receiving labels for the largest clusters in the unclassified data set to produce a labeled data set,

training the one or more classifiers on a union of the labeled data set and one or more previously labeled data sets, and

submitting the data set to the one or more classifiers to produce an updated classified data set and an updated unclassified data set;

receiving, at a first point in time, first data about one or more devices on the network;

determining, by a rules engine, a first set of device type probabilities for the one or more devices based on the first data;

determining, using the machine learning model, a second set of device type probabilities for the one or more devices based on the first data; and

determining device types for the one or more devices based on the first set of device type probabilities and the second set of device type probabilities.

2. The method of claim 1 , further comprising:

receiving, at a second point in time, second data about the one or more devices on the network;

determining, by the rules engine, a third set of device type probabilities for the one or more devices based on the second data;

determining, using the machine learning model, a fourth set of device type probabilities for the one or more devices based on the second data; and

updating device types for the one or more devices based on the third set of device type probabilities and the fourth set of device type probabilities.

3. The method of claim 1 , wherein determining, using the machine learning model, the second set of device type probabilities for the one or more devices comprises:

providing a feature value extracted from the first data to a classifier for the feature, wherein the classifier is one of a plurality of classifiers for a plurality of features;

receiving a set of device probabilities from the classifier;

determining, based on the plurality of classifiers, a device type for a device of the one or more devices.

4. The method of claim 3 , wherein the set of device probabilities includes a probability value for each of a set of device types, the probability value indicating the probability of the device type based on the feature value.

5. The method of claim 3 , wherein each of the plurality of classifiers independently determines a corresponding set of device probabilities based on a combination of one or more features of the plurality of features, wherein the combination of one or more features provided to a corresponding classifier is different from the combination of one or more features provided to others of the plurality of classifiers.

6. The method of claim 1 , wherein determining the data set from the device data comprises determining a balanced dataset from the device data.

7. A device classification system comprising:

one or more processors; and

a machine-readable storage medium having stored thereon executable instructions that, when executed, cause the one or more processors to:

train a machine learning model, comprising:

receive device data from a plurality of devices on a plurality of networks;

determine a data set from the device data;

cluster the data set to produce a first set of clusters;

receive labels for a set of largest clusters in the first set of clusters to produce a labeled data set;

train one or more classifiers of the machine learning model based on the labels to produce a classified data set and an unclassified data set; and

repeat, until a stopping condition is met, the operations of:

cluster the unclassified data set,

receive labels for the largest clusters in the unclassified data set to produce a labeled data set,

train the one or more classifiers on a union of the labeled data set and one or more previously labeled data sets, and

submit the data set to the one or more classifiers to produce an updated classified data set and an updated unclassified data set;

receive, at a first point in time, first data about one or more devices on the network;

determine, by a rules engine, a first set of device type probabilities for the one or more devices based on the first data;

determine, using the machine learning model, a second set of device type probabilities for the one or more devices based on the first data; and

determine device types for the one or more devices based on the first set of device type probabilities and the second set of device type probabilities.

8. The device classification system of claim 7 , wherein the instructions further comprise instructions to cause the one or more processors to:

receive, at a second point in time, second data about the one or more devices on the network;

determine, by the rules engine, a third set of device type probabilities for the one or more devices based on the second data;

determine, using the machine learning model, a fourth set of device type probabilities for the one or more devices based on the second data; and

update device types for the one or more devices based on the third set of device type probabilities and the fourth set of device type probabilities.

9. The device classification system of claim 7 , wherein the instructions to determine, using the machine learning model, the second set of device type probabilities for the one or more devices comprise instructions to cause the one or more processors to:

provide a feature value extracted from the first data to a classifier for the feature, wherein the classifier is one of a plurality of classifiers for a plurality of features;

receive a set of device probabilities from the classifier;

determine, based on the plurality of classifiers, a device type for a device of the one or more devices.

10. The device classification system of claim 9 , wherein the set of device probabilities includes a probability value for each of a set of device types, the probability value indicating the probability of the device type based on the feature value.

11. The device classification system of claim 9 , wherein each of the plurality of classifiers independently determines a corresponding set of device probabilities based on a combination of one or more features of the plurality of features, wherein the combination of one or more features provided to a corresponding classifier is different from the combination of one or more features provided to others of the plurality of classifiers.

12. The device classification system of claim 7 , wherein the instructions to determine the data set from the device data comprise instructions to determine a balanced dataset from the device data.

13. A machine-readable storage medium having stored thereon executable instructions that, when executed, cause one or more processors to:

train a machine learning model, comprising:

receive device data from a plurality of devices on a plurality of networks;

determine a data set from the device data;

cluster the data set to produce a first set of clusters;

receive labels for a set of largest clusters in the first set of clusters to produce a labeled data set;

train one or more classifiers of the machine learning model based on the labels to produce a classified data set and an unclassified data set; and

repeat, until a stopping condition is met, the operations of:

cluster the unclassified data set,

receive labels for the largest clusters in the unclassified data set to produce a labeled data set,

train the one or more classifiers on a union of the labeled data set and one or more previously labeled data sets, and

submit the data set to the one or more classifiers to produce an updated classified data set and an updated unclassified data set;

receive, at a first point in time, first data about one or more devices on the network;

determine, by a rules engine, a first set of device type probabilities for the one or more devices based on the first data;

determine, using the machine learning model, a second set of device type probabilities for the one or more devices based on the first data; and

determine device types for the one or more devices based on the first set of device type probabilities and the second set of device type probabilities.

14. The machine-readable storage medium of claim 13 , wherein the instructions further comprise instructions to cause the one or more processors to:

receive, at a second point in time, second data about the one or more devices on the network;

determine, by the rules engine, a third set of device type probabilities for the one or more devices based on the second data;

determine, using the machine learning model, a fourth set of device type probabilities for the one or more devices based on the second data; and

update device types for the one or more devices based on the third set of device type probabilities and the fourth set of device type probabilities.

15. The machine-readable storage medium of claim 13 , wherein the instructions to determine, using the machine learning model, the second set of device type probabilities for the one or more devices comprise instructions to cause the one or more processors to:

provide a feature value extracted from the first data to a classifier for the feature, wherein the classifier is one of a plurality of classifiers for a plurality of features;

receive a set of device probabilities from the classifier;

determine, based on the plurality of classifiers, a device type for a device of the one or more devices.

16. The machine-readable storage medium of claim 15 , wherein the set of device probabilities includes a probability value for each of a set of device types, the probability value indicating the probability of the device type based on the feature value.

17. The device classification machine-readable storage medium of claim 15 , wherein each of the plurality of classifiers independently determines a corresponding set of device probabilities based on a combination of one or more features of the plurality of features, wherein the combination of one or more features provided to a corresponding classifier is different from the combination of one or more features provided to others of the plurality of classifiers.

18. The machine-readable storage medium of claim 13 , wherein the instructions to determine the data set from the device data comprise instructions to determine a balanced dataset from the device data.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: GEN DIGITAL AMERICAS S.R.O.
To: GEN DIGITAL INC.
Reel/Frame 071771/0767 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2025
From: AVAST SOFTWARE S.R.O.
To: GEN DIGITAL AMERICAS S.R.O.
Reel/Frame 071777/0341 →
RELEASE OF SECURITY INTEREST Recorded Mar 26, 2021
From: CREDIT SUISSE INTERNATIONAL, AS COLLATERAL AGENT
To: AVAST SOFTWARE, S.R.O.
Reel/Frame 055726/0435 →
SECURITY INTEREST Recorded May 6, 2020
From: AVAST SOFTWARE S.R.O.
To: CREDIT SUISSE INTERNATIONAL, AS COLLATERAL AGENT
Reel/Frame 052582/0285 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 23, 2019
From: ALPEROVICH, GALINA; KUZNETSOV, DMITRY; GUPTA, RAJARSHI
To: AVAST SOFTWARE S.R.O.
Reel/Frame 051359/0945 →