IP Library Granted Patent US 11,314,789
Granted Patent B2
US 11,314,789 · App. 16/833,762 · Granted Apr 26, 2022

System and method for improved anomaly detection using relationship graphs

Inventor: Eithan Goldfarb (Ness Ziona, IL)
Assignee: COGNYTE TECHNOLOGIES ISRAEL LTD.
G06F16/288G06F16/29G06F16/9024
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,314,789
App. No.
16/833,762
Granted
Apr 26, 2022
Kind
B2
Abstract

An anomaly-detection system that gathers information relating to the relationships between entities and represents these relationships in a graph that interconnects each pair of related entities. The graph may represent a computer network, in which each node corresponds to a respective device in the network and each edge between two nodes indicates that the devices represented by the nodes exchanged communication with one another in the past. the system monitors each of the entities in the graph, by continually computing a single-entity anomaly score (SEAS) for the entity. If the SEAS exceeds a first threshold the system generates an alert. Otherwise, the system checks whether the SEAS exceeds a second, lower threshold. If so, the system computes a subgraph anomaly score (SAS) for the entity's subgraph. If the SAS exceeds a SAS threshold, an alert is generated. By computing the SAS in this manner resources are conserved.

Claims (51)

1. A system for monitoring a plurality of entities, the system comprising:

a communication interface; and

a processor, configured to:

obtain a graph that represents the entities by respective nodes and, via multiple edges, interconnects each pair of the nodes that represents a respective pair of the entities that are related to one another;

receive behavior-indicating data via the communication interface;

designate one or more of the entities as entities of interest (EOIs), which are represented in the graph by respective EOI-nodes of the nodes;

identify multiple EOI subgraphs of the graph, each of the EOI subgraphs corresponding to a respective one of the EOIs and including the EOI-node representing the respective one of the EOIs,

wherein each of the EOI subgraphs includes each one of the nodes that is connected to the EOI-node representing the respective one of the EOIs via M or fewer of the edges, and excludes each one of the nodes that is connected to the EOI-node representing the respective one of the EOIs via more than M of the edges, M being a first positive integer, and

wherein the particular one of the EOI subgraphs corresponds to a particular one of the EOIs, which is represented in the graph by a particular one of the EOI-nodes;

ascertain that the particular one of the nodes belongs to a particular one of the EOI subgraphs;

based on the behavior-indicating data, compute respective single-entity anomaly scores (SEASs) for the entities, each of the SEASs quantifying a first degree to which first behavior of a respective one of the entities is anomalous;

in response to any particular one of the SEASs, for any particular one of the entities, wherein the particular one of the entities is represented by a particular one of the nodes, exceeds a predefined SEAS threshold;

(i) identify a subgraph of the graph, which represents a subset of the entities that includes the particular one of the entities, wherein the subgraph is an SAS subgraph, and the SAS subgraph includes each one of the nodes that is connected to the particular one of the EOI-nodes via N or fewer of the edges and excludes each one of the nodes that is connected to the particular one of the EOI-nodes via more than N of the edges, N being a second positive integer, and

(ii) compute a subgraph anomaly score (SAS) that quantifies a second degree to which second behavior of the subset of the entities is anomalous;

in response to the ascertaining that the particular one of the nodes belongs to the particular one of the EOI subgraphs, compare the particular one of the SEASs to the predefined SEAS threshold; and

in response to the SAS exceeding a predefined SAS threshold, generate an alert.

2. The system according to claim 1 , wherein the processor is configured to obtain the graph by:

identifying each pair of the entities that are related to one another, and

in response to identifying each pair of the entities that are related to one another, constructing the graph.

3. The system according to claim 2 , wherein the processor is configured to identify each pair of the entities that are related to one another based on the pair having communicated with one another.

4. The system according to claim 1 , wherein behavior selected includes at least one of a communication-related behavior and a location-related behavior.

5. The system according to claim 1 , wherein the entities are respective devices in a computer network.

6. The system according to claim 5 , wherein behavior selected from the group of behaviors consisting of: the first behavior and the second behavior includes computational behavior.

7. The system according to claim 1 , wherein the entities are respective persons.

8. The system according to claim 7 , wherein behavior selected from the group of behaviors consisting of: the first behavior and the second behavior includes financial behavior.

9. The system according to claim 1 , and wherein the subgraph includes each one of the nodes that is connected to the particular one of the nodes via N or fewer of the edges and excludes each one of the nodes that is connected to the particular one of the nodes via more than N of the edges, N being a positive integer.

10. The system according to claim 1 ,

wherein the processor is further configured to:

compute respective other SASs for a plurality of other subgraphs of the graph, and

identify a number of the other SASs that exceed the predefined SAS threshold, and

wherein the processor is configured to generate the alert in response to the number.

11. A method for monitoring a plurality of entities, the method comprising:

obtaining a graph that represents the entities by respective nodes and, via multiple edges, interconnects each pair of the nodes that represents a respective pair of the entities that are related to one another;

receiving behavior-indicating data;

designating one or more of the entities as entities of interest (EOIs), which are represented in the graph by respective EOI-nodes of the nodes;

identifying multiple EOI subgraphs of the graph, each of the EOI subgraphs corresponding to a respective one of the EOIs and including the EOI-node representing the respective one of the EOIs,

wherein each of the EOI subgraphs includes each one of the nodes that is connected to the EOI-node representing the respective one of the EOIs via M or fewer of the edges, and excludes each one of the nodes that is connected to the EOI-node representing the respective one of the EOIs via more than M of the edges, M being a first positive integer, and

wherein the particular one of the EOI subgraphs corresponds to a particular one of the EOIs, which is represented in the graph by a particular one of the EOI-nodes;

ascertaining that the particular one of the nodes belongs to a particular one of the EOI subgraphs;

based on the behavior-indicating data, computing respective single-entity anomaly scores (SEASs) for the entities, each of the SEASs quantifying a first degree to which first behavior of a respective one of the entities is anomalous;

in response to any particular one of the SEASs, for any particular one of the entities, wherein the particular one of the entities is represented by a particular one of the nodes, and exceeding a predefined SEAS threshold:

(i) identifying a subgraph of the graph, which represents a subset of the entities that includes the particular one of the entities, wherein the subgraph is an SAS subgraph, and the subgraph includes each one of the nodes that is connected to the particular one of the EOI-nodes via N or fewer of the edges and excludes each one of the nodes that is connected to the particular one of the EOI-nodes via more than N of the edges, N being a positive integer, and

(ii) computing a subgraph anomaly score (SAS) that quantifies a second degree to which second behavior of the subset of the entities is anomalous;

in response to the ascertaining, comparing the particular one of the SEASs to the predefined SEAS threshold; and

in response to the SAS exceeding a predefined SAS threshold, generating an alert.

12. The method according to claim 11 , wherein obtaining the graph comprises obtaining the graph by:

identifying each pair of the entities that are related to one another, and

in response to identifying each pair of the entities that are related to one another, constructing the graph.

13. The method according to claim 12 , wherein identifying each pair of the entities that are related to one another comprises identifying each pair of the entities that are related to one another based on the pair having communicated with one another.

14. The method according to claim 11 , wherein behavior comprises at least one of a communication-related behavior and a location-related behavior.

15. The method according to claim 11 , wherein the entities are respective devices in a computer network.

Assignments (3)
CHANGE OF NAME Recorded Apr 20, 2022
From: VERINT SYSTEMS LTD.
To: COGNYTE TECHNOLOGIES ISRAEL LTD
Reel/Frame 059710/0753 →
CHANGE OF NAME Recorded Dec 23, 2021
From: VERINT SYSTEMS LTD.
To: COGNYTE TECHNOLOGIES ISRAEL LTD
Reel/Frame 060751/0532 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2020
From: GOLDFARB, EITHAN
To: VERINT SYSTEMS LTD.
Reel/Frame 053036/0160 →
Priority Claims (1)
IL 265849 · Apr 4, 2019 · national
Continuity (1)
Related Publication 20200320106A1 · Oct 8, 2020
Cited By (100)
US 12,206,696 US 12,244,621 US 12,261,866 US 12,267,345 US 12,284,197 US 12,309,181 US 12,309,182 US 12,309,185 US 12,309,236 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,381,901 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,272 US 12,452,279 US 12,457,231 US 12,463,994 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,489,771 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,511,110 US 12,513,221 US 12,526,297 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,932 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,931 US 12,706,932 US 12,706,933 US 12,706,980 US 12,712,897 US 12,719,896