IP Library Granted Patent US 11,750,621
Granted Patent B2
US 11,750,621 · App. 16/831,197 · Granted Sep 5, 2023

Learning of malicious behavior vocabulary and threat detection through behavior matching

Inventors: Petr Somol (Marianske Lazne, CZ); Martin Kopp (Beround, CZ); Jan Kohout (Roudnice Nad Labem, CZ); Jan Brabec (Rakovnik, CZ); Marc René Jacques Marie Dupont (Prague, CZ); Cenek Skarda (Prague, CZ); Lukas Bajer (Somerset, WI); Danila Khikhlukha (Prague, CZ)
Assignee: Cisco Technology, Inc.
H04L63/14G06N3/045G06N3/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,750,621
App. No.
16/831,197
Granted
Sep 5, 2023
Kind
B2
Abstract

In one embodiment, a device obtains input features for a neural network-based model. The device pre-defines a set of neurons of the model to represent known behaviors associated with the input features. The device constrains weights for a plurality of outputs of the model. The device trains the neural network-based model using the constrained weights for the plurality of outputs of the model and by excluding the pre-defined set of neurons from updates during the training.

Claims (37)

1. A method comprising:

obtaining, by a device, input features for a neural network-based model;

pre-defining, by the device, a set of neurons of the model to represent known behaviors associated with the input features;

constraining, by the device, weights for a plurality of outputs of the model; and

training, by the device, the neural network-based model using the constrained weights for the plurality of outputs of the model, by including the pre-defined set of neurons in the neural network-based model, and by excluding the pre-defined set of neurons from being updated during the training.

2. The method as in claim 1 , wherein the weights for the plurality of outputs of the model are constrained to be binary or near-binary.

3. The method as in claim 1 , wherein the outputs represent malicious computer network conditions.

4. The method as in claim 1 , wherein the input features represent computer network events.

5. The method as in claim 1 , further comprising:

deploying, by the device, the trained neural network-based model for use to detect malicious computer network conditions in one or more computer networks.

6. The method as in claim 1 , wherein the neural network-based model comprises a generative adversarial network (GAN).

7. The method as in claim 1 , wherein the input features represent system log events.

8. The method as in claim 1 , wherein the input features represent code structures of an executable.

9. An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the network interfaces and configured to execute one or more processes; and

a memory configured to store a process executable by the processor, the process when executed configured to:

obtain input features for a neural network-based model;

pre-define a set of neurons of the model to represent known behaviors associated with the input features;

constrain weights for a plurality of outputs of the model; and

train the neural network-based model using the constrained weights for the plurality of outputs of the model, by including the pre-defined set of neurons in the neural network-based model, and by excluding the pre-defined set of neurons from being updated during the training.

10. The apparatus as in claim 9 , wherein the weights for the plurality of outputs of the model are constrained to be binary or near-binary.

11. The apparatus as in claim 9 , wherein the outputs represent malicious computer network conditions.

12. The apparatus as in claim 9 , wherein the input features represent computer network events.

13. The apparatus as in claim 9 , wherein the process when executed is further configured to:

deploy the trained neural network-based model for use to detect malicious computer network conditions in one or more computer networks.

14. The apparatus as in claim 9 , wherein the neural network-based model comprises a generative adversarial network (GAN).

15. The apparatus as in claim 9 , wherein the input features represent system log events.

16. The apparatus as in claim 9 , wherein the input features represent code structures of an executable.

17. A tangible, non-transitory, computer-readable medium storing program instructions that cause a device to execute a procedure comprising:

obtaining, by a device, input features for a neural network-based model;

pre-defining, by the device, a set of neurons of the model to represent known behaviors associated with the input features;

constraining, by the device, weights for a plurality of outputs of the model; and

training, by the device, the neural network-based model using the constrained weights for the plurality of outputs of the model, by including the pre-defined set of neurons in the neural network-based model, and by excluding the pre-defined set of neurons from being updated during the training.

18. The computer-readable medium as in claim 17 , wherein the weights for the plurality of outputs of the model are constrained to be binary or near-binary.

19. The computer-readable medium as in claim 17 , wherein the outputs represent malicious computer network conditions.

20. The computer-readable medium as in claim 17 , wherein the input features represent computer network events.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 26, 2020
From: SOMOL, PETR; KOPP, MARTIN; KOHOUT, JAN; BRABEC, JAN; DUPONT, MARC RENÉ JACQUES MARIE; SKARDA, CENEK; BAJER, LUKAS; KHIKHLUKHA, DANILA
To: CISCO TECHNOLOGY, INC.
Reel/Frame 052237/0573 →
Continuity (1)
Related Publication 20210306350A1 · Sep 30, 2021