IP Library Granted Patent US 11,423,146
Granted Patent B2
US 11,423,146 · App. 16/991,288 · Granted Aug 23, 2022

Provenance-based threat detection tools and stealthy malware detection

Inventors: Ding Li (Franklin Park, NJ); Xiao Yu (Princeton, NJ); Junghwan Rhee (Princeton, NJ); Haifeng Chen (West Windsor, NJ); Qi Wang (Urbana, IL)
G06F21/566G06F21/54G06F21/552G06K9/6257G06K9/6269G06K9/6296
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,423,146
App. No.
16/991,288
Granted
Aug 23, 2022
Kind
B2
Abstract

Systems and methods for a provenance based threat detection tool that builds a provenance graph including a plurality of paths using a processor device from provenance data obtained from one or more computer systems and/or networks; samples the provenance graph to form a plurality of linear sample paths, and calculates a regularity score for each of the plurality of linear sample paths using a processor device; selects a subset of linear sample paths from the plurality of linear sample paths based on the regularity score, and embeds each of the subset of linear sample paths by converting each of the subset of linear sample paths into a numerical vector using a processor device; detects anomalies in the embedded paths to identify malicious process activities, and terminates a process related to the embedded path having the identified malicious process activities.

Claims (36)

1. A computer implemented provenance-based threat detection method, comprising:

building a provenance graph including a plurality of paths using a processor device from provenance data obtained from one or more computer systems and/or networks, wherein the provenance graph is built by collecting the provenance data using hook functions that intercept operating system calls;

sampling the provenance graph to form a plurality of linear sample paths;

calculating a regularity score for each of the plurality of linear sample paths using a processor device;

selecting a subset of linear sample paths from the plurality of linear sample paths based on the regularity score;

embedding each of the subset of linear sample paths by converting each of the subset of linear sample paths into a numerical vector using a processor device;

detecting anomalies in the embedded paths to identify malicious process activities, wherein the anomalies in the embedded paths are detected using an anomaly detection model that is configured to identify malicious activity, wherein the anomaly detection model is selected from the group consisting of one-class support vector machine (OC-SVM) and Local Outlier Factor (LOF); and

terminating a process related to the embedded path having the identified malicious process activities.

2. The method as recited in claim 1 , wherein selecting a subset of linear sample paths addresses a dependency explosion problem.

3. The method as recited in claim 1 , wherein the anomaly detection model is trained using a benign training data set.

4. The method as recited in claim 3 , wherein embedding each of the plurality of paths is done using graph2vec or doc2vec.

5. A non-transitory computer readable storage medium comprising a computer readable program for a computer implemented provenance-based threat detection tool, wherein the computer readable program when executed on a computer causes the computer to perform the steps of:

building a provenance graph including a plurality of paths using a processor device from provenance data obtained from one or more computer systems and/or networks, wherein the provenance graph is built by collecting the provenance data using hook functions that intercept operating system calls;

sampling the provenance graph to form a plurality of linear sample paths;

calculating a regularity score for each of the plurality of linear sample paths using a processor device;

selecting a subset of linear sample paths from the plurality of linear sample paths based on the regularity score;

embedding each of the subset of linear sample paths by converting each of the subset of linear sample paths into a numerical vector using a processor device;

detecting anomalies in the embedded paths to identify malicious process activities, wherein the anomalies in the embedded paths are detected using an anomaly detection model that is configured to identify malicious activity, wherein the anomaly detection model is selected from the group consisting of one-class support vector machine (OC-SVM) and Local Outlier Factor (LOF); and

terminating a process related to the embedded path having the identified malicious process activities.

6. The method as recited in claim 5 , wherein selecting a subset of linear sample paths addresses a dependency explosion problem.

7. The computer readable program as recited in claim 5 , wherein the anomaly detection model is trained using a benign training data set.

8. The computer readable program as recited in claim 7 , wherein embedding each of the plurality of paths is done using graph2vec or doc2vec.

9. A system for provenance-based threat detection, comprising:

a computer system including:

random access memory configured to store a provenance-based threat detection tool;

one or more processor devices and an operating system having a kernel, wherein one or more hook functions operating in the kernel are configured to collect provenance data using the hook functions that intercept operating system calls; and

a database configured to store the provenance data collected by the one or more hook functions, wherein the provenance-based threat detection tool is configured to:

build a provenance graph including a plurality of paths using the one or more processor devices from provenance data obtained from the computer systems and/or a network;

sample the provenance graph to form a plurality of linear sample paths;

calculate a regularity score for each of the plurality of linear sample paths using the one or more processor devices;

select a subset of linear sample paths from the plurality of linear sample paths based on the regularity score;

embed each of the subset of linear sample paths by converting each of the subset of linear sample paths into a numerical vector using the one or more processor devices;

detect anomalies in the embedded paths to identify malicious process activities, wherein the anomalies in the embedded paths are detected using an anomaly detection model that is configured to identify malicious activity, wherein the anomaly detection model is selected from the group consisting of one-class support vector machine (OC-SVM) and Local Outlier Factor (LOF); and

terminate a process related to the embedded path having the identified malicious process activities.

10. The system as recited in claim 9 , wherein selecting a subset of linear sample paths addresses a dependency explosion problem.

11. The system as recited in claim 9 , wherein the anomaly detection model is trained using a benign training data set.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2022
From: NEC LABORATORIES AMERICA, INC.
To: NEC CORPORATION
Reel/Frame 060471/0165 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 12, 2020
From: LI, DING; YU, XIAO; RHEE, JUNGHWAN; CHEN, HAIFENG; WANG, QI
To: NEC LABORATORIES AMERICA, INC.
Reel/Frame 053470/0089 →
Continuity (2)
Provisional Application 62892036 · Aug 27, 2019
Related Publication 20210064751A1 · Mar 4, 2021
Cited By (3)
US 12,197,577 US 12,425,309 US 12,505,205