IP Library Granted Patent US 11,921,846
Granted Patent B2
US 11,921,846 · App. 16/835,871 · Granted Mar 5, 2024

Automatic intrusion detection method and apparatus

Inventors: Stav Yanovsky Daye (Givatayim, IL); Ran Wolff (Geva-Carmel, IL)
Assignee: YAHOO ASSETS LLC
G06F21/552G06F18/214G06F18/22G06F21/55G06F21/6218G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,921,846
App. No.
16/835,871
Granted
Mar 5, 2024
Kind
B2
Abstract

Disclosed are systems and methods for improving interactions with and between computers in distributional similarity identification using randomized observations. In connection with an intrusion detection system monitoring a computing system, a pair of perturbed sample sets are generating using a pair of real sample set (or real observations) and a pair of random sample sets (of randomly-selected observations), and a similarity measuring representing a level of consistency in user behavior is determined. The systems improve the quality and accuracy of the similarity determination for use in intrusion detection.

Claims (32)

1. A method comprising:

receiving, at a computing device, a distributional similarity request associated with a pair of real sample sets, each real sample set of the pair comprising a number of real observations;

determining, via the computing device, a pair of random sample sets for the pair of real sample sets, the determination comprising, for a random sample set of the pair, selecting a number of random observations from a domain of observations corresponding to the pair of real sample sets;

determining, via the computing device, a pair of perturbed sample sets corresponding to the pair of real sample sets, a first perturbed sample set of the pair comprising a first one of the pair of real sample sets and a first one of the pair of random sample sets and a second perturbed sample set of the pair comprising a second one of the pair of real sample sets and a second one of the pair of random sample sets;

determining, via the computing device, a pair of probability distributions corresponding to the pair of perturbed sample sets, a first probability distribution of the pair corresponding to the first perturbed sample set and comprising a probability for each of the number of real and random observations in the first perturbed set, a second probability distribution of the pair corresponding to the second perturbed sample set and comprising a probability for the each of the number of real and random observations in the second perturbed set; and

automatically generating, via the computing device, a distributional similarity measure using the pair of probability distributions corresponding to the pair of perturbed sample sets, the distribution similarity measure corresponding to the pair of perturbed sample sets representing a degree of similarity between the pair of real sample sets associated with the distributional similarity request.

2. The method of claim 1 , further comprising:

communicating, via the computing device, the distribution similarity measure representing a degree of similarity between the pair of real sample sets in response to the request.

3. The method of claim 1 , the pair of real sample sets correspond to a pair of time periods and to a user account associated with a computing system being monitored by an intrusion detection system, the number of real observations of a first real sample set of the pair comprising information identifying each resource access request made by the user account in a first of the pair of time periods, the number of real observations of a second real sample set of the pair comprising information identifying each resource access request made by the user account in a second of the pair of time periods, and the similarity measure representing a level of similarity in access requests for user account and the pair of time periods.

4. The method of claim 3 , further comprising:

making, by the intrusion detection system, a comparison between the level of similarity and a threshold level of similarity; and

determining, by the intrusion detection system and based on the comparison, that the user account has been compromised using the comparison.

5. The method of claim 1 , the pair of real sample sets corresponding to a user of a computing system being monitored by an intrusion detection system, one real sample set of the pair comprising, as the number of real observations, a number of resource access requests made by the user account to the computing system being monitored by the intrusion detection system, another real sample set of the pair corresponding to a user group to which the user is assigned and comprising, as its number of real observations, the number of resource access requests of the group of users, and the similarity measure representing a level of similarity for the user's access requests relative to the user group's access request.

6. The method of claim 5 , further comprising:

making, by the intrusion detection system, a comparison between the level of similarity and a threshold level of similarity; and

determining, by the intrusion detection system and based on the comparison, that the user account has been compromised using the comparison.

7. A non-transitory computer-readable storage medium tangibly encoded with computer-executable instructions that when executed by a processor associated with a computing device perform a method comprising:

receiving a distributional similarity request identifying a pair of real sample sets, each real sample set of the pair comprising a number of real observations;

determining a pair of random sample sets for the pair of real sample sets, the determination comprising, for a random sample set of the pair, selecting a number of random observations from a domain of observations corresponding to the pair of real sample sets;

determining a pair of perturbed sample sets corresponding to the pair of real sample sets, a first perturbed sample set of the pair comprising a first one of the pair of real sample sets and a first one of the pair of random sample sets and a second perturbed sample set of the pair comprising a second one of the pair of real sample sets and a second one of the pair of random sample sets;

determining a pair of probability distributions corresponding to the pair of perturbed sample sets, a first probability distribution of the pair corresponding to the first perturbed sample set and comprising a probability for each of the number of real and random observations in the first perturbed set, a second probability distribution of the pair corresponding to the second perturbed sample set and comprising a probability for the each of the number of real and random observations in the second perturbed set; and

automatically generating a distributional similarity measure using the pair of probability distributions corresponding to the pair of perturbed sample sets, the distribution similarity measure corresponding to the pair of perturbed sample sets representing a degree of similarity between the pair of real sample sets associated the with distributional similarity request.

8. The non-transitory computer-readable storage medium of claim 7 , the pair of real sample sets correspond to a pair of time periods and to a user account associated with a computing system being monitored by an intrusion detection system, the number of real observations of a first real sample set of the pair comprising information identifying each resource access request made by the user account in a first of the pair of time periods, the number of real observations of a second real sample set of the pair comprising information identifying each resource access request made by the user account in a second of the pair of time periods, and the similarity measure representing a level of similarity in access requests for user account and the pair of time periods.

9. The non-transitory computer-readable storage medium of claim 7 , the pair of real sample sets corresponding to a user of a computing system being monitored by an intrusion detection system, one real sample set of the pair comprising, as the number of real observations, a number of resource access requests made by the user account to the computing system being monitored by the intrusion detection system, another real sample set of the pair corresponding to a user group to which the user is assigned and comprising, as its number of real observations, the number of resource access requests of the group of users, and the similarity measure representing a level of similarity for the user's access requests relative to the user group's access request.

10. A computing device comprising:

a processor;

a non-transitory storage medium for tangibly storing thereon program logic for execution by the processor, the program logic comprising:

receiving logic executed by the processor for receiving a distributional similarity request identifying a pair of real sample sets, each real sample set of the pair comprising a number of real observations;

determining logic executed by the processor for determining a pair of random sample sets for the pair of real sample sets, the determination comprising, for a random sample set of the pair, selecting a number of random observations from a domain of observations corresponding to the pair of real sample sets;

determining logic executed by the processor for determining a pair of perturbed sample sets corresponding to the pair of real sample sets, a first perturbed sample set of the pair comprising a first one of the pair of real sample sets and a first one of the pair of random sample sets and a second perturbed sample set of the pair comprising a second one of the pair of real sample sets and a second one of the pair of random sample sets;

determining logic executed by the processor for determining a pair of probability distributions corresponding to the pair of perturbed sample sets, a first probability distribution of the pair corresponding to the first perturbed sample set and comprising a probability for each of the number of real and random observations in the first perturbed set, a second probability distribution of the pair corresponding to the second perturbed sample set and comprising a probability for the each of the number of real and random observations in the second perturbed set; and

generating logic executed by the processor for automatically generating a distributional similarity measure using the pair of probability distributions corresponding to the pair of perturbed sample sets, the distribution similarity measure corresponding to the pair of perturbed sample sets representing a degree of similarity between the pair of real sample sets associated the with distributional similarity request.

Assignments (4)
PATENT SECURITY AGREEMENT (FIRST LIEN) Recorded Sep 29, 2022
From: YAHOO ASSETS LLC
To: ROYAL BANK OF CANADA, AS COLLATERAL AGENT
Reel/Frame 061571/0773 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2021
From: YAHOO AD TECH LLC (FORMERLY VERIZON MEDIA INC.)
To: YAHOO ASSETS LLC
Reel/Frame 058982/0282 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2020
From: OATH INC.
To: VERIZON MEDIA INC.
Reel/Frame 054258/0635 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2020
From: DAYE, STAV YANOVSKY; WOLFF, RAN
To: OATH INC.
Reel/Frame 052285/0196 →