IP Library Granted Patent US 11,716,338
Granted Patent B2
US 11,716,338 · App. 17/104,190 · Granted Aug 1, 2023

System and method for determining a file-access pattern and detecting ransomware attacks in at least one computer network

Inventors: Eyal Elyashiv (Ramat Hasharon, IL); Eliezer Upfal (Providence, RI); Aviv Yehezkel (Ramat-Gan, IL)
Assignee: TWEENZNET LTD.
H04L63/1416G06N3/08H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,716,338
App. No.
17/104,190
Filed
Nov 25, 2020
Granted
Aug 1, 2023
Kind
B2
Art Unit
2434
USPC
726/23
Abstract

Systems and methods of determining file-access patterns in at least one computer network, the network comprising a file-access server, including training a first machine learning (ML) algorithm with a first training dataset comprising vectors representing network traffic such that the first ML algorithm learns to determine network characteristics associated with file-access traffic, determining, using the first ML algorithm, network characteristics based on highest interaction of traffic with the file-access server compared to other interactions in the at least one computer network, and determining file-access patterns in the at least one computer network based on the network characteristics associated with file-access traffic.

Claims (33)

1. A method of determining file-access patterns in at least one computer network, the network comprising a file-access server, the method comprising:

training, by a processor in communication with the computer network, a first machine learning (ML) algorithm with a first training dataset comprising vectors representing network traffic such that the first ML algorithm learns to determine network characteristics associated with file-access traffic;

using the first ML algorithm, determining, by the processor, network characteristics based on highest interaction of traffic with the file-access server compared to other interactions in the at least one computer network;

determining, by the processor, file-access patterns in the at least one computer network based on the network characteristics associated with file-access traffic;

training, by the processor, a second ML algorithm with a second training dataset comprising vectors representing network traffic such that the second ML algorithm identifies a file-access anomaly in the sampled network traffic based on the network characteristics learned by the first ML algorithm;

determining, by the processor, a normalized difference between a new input vector representing sampled network traffic and the vectors in the second training dataset, wherein the anomaly is identified when a normalized difference that is larger than difference between the new input vector and the vectors in the second training dataset is determined;

training, by the processor, a third ML algorithm with a third training dataset comprising vectors representing network traffic such that the third ML algorithm detects at least one ransom attack property based on at least one communication pattern in the anomaly sampled network traffic, when the third ML algorithm receives a new input vector not in the third training dataset and representing sampled network traffic; and

applying the third ML algorithm on the sampled network traffic,

wherein the at least one ransom attack property is determined based on highest interaction frequency with the file-access server.

2. The method of claim 1 , wherein the second ML algorithm comprises at least one of: an auto-encoder deep-learning network architecture and a generative adversarial network (GAN) architecture.

3. The method of claim 1 , wherein the second ML algorithm is trained for input reconstruction, and wherein the second ML algorithm outputs a larger normalized loss for anomaly input in file-access traffic than for file-access traffic without anomalies.

4. The method of claim 1 , further comprising applying an active learning mechanism to update at least one detection model based on a user feedback loop.

5. The method of claim 1 , further comprising normalizing, by the processor, a loss determined by the second ML algorithm based on the output of the first ML algorithm for the new input vector, wherein the output of the first ML algorithm is different from the output of the second ML algorithm for the second training dataset, and wherein the second ML algorithm is configured to allow a model trained in one installation to serve as a base model in another installation by normalizing the loss vectors of each installation.

6. The method of claim 1 , wherein the sampled network traffic is sampled on a network attached storage (NAS).

7. The method of claim 1 , wherein the sampled network traffic comprises vectors each representing a different time interval.

8. A device for determining file-access patterns in at least one computer network comprising a file-access server, the device comprising:

a memory, to store a first training dataset; and

a processor in communication with the computer network, wherein the processor is configured to:

train a first machine learning (ML) algorithm with a first training dataset comprising vectors such that the first ML algorithm learns network characteristics associated with file-access traffic, when the first ML algorithm receives input vectors representing sampled network traffic;

determine network characteristics associated with file-access traffic based on highest interaction of traffic with the file-access server compared to other interactions in the at least one computer network;

determine file-access patterns in the at least one computer network based on the network characteristics associated with file-access traffic;

train a second ML algorithm with a second training dataset comprising vectors such that the second ML algorithm identifies an anomaly in the sampled network traffic based on the learned network characteristics, when the second ML algorithm receives a new input vector representing sampled network traffic;

apply the second ML algorithm on the sampled network traffic;

determine a normalized difference between the new input vector and the vectors in the second training dataset, wherein a normalized difference that is larger than difference of the second training dataset corresponds to a file-access anomaly in the sampled network traffic;

train a third ML algorithm with a third training dataset comprising vectors such that the third ML algorithm detects at least one ransom attack property based on at least one communication pattern in the anomaly sampled network traffic, when the third ML algorithm receives a new input vector representing sampled network traffic; and

apply a third ML algorithm on the sampled network traffic,

wherein the at least one ransom attack property is determined based on highest interaction with the file-access server.

9. The device of claim 8 , wherein the second ML algorithm comprises at least one of: an auto-encoder deep-learning network architecture and a generative adversarial network (GAN) architecture.

10. The device of claim 8 , wherein the second ML algorithm is trained for input reconstruction, and wherein the second ML algorithm outputs a larger normalized loss for anomaly input in file-access traffic.

11. The device of claim 8 , wherein the processor is further configured to apply an active learning mechanism to update at least one detection model based on a user feedback loop.

12. The device of claim 8 , wherein the processor is further configured to normalize a loss determined by the second ML algorithm based on the output of the first ML algorithm for the new input vector being different from the output of the second ML algorithm for the second training dataset, wherein the second ML algorithm is configured to allow a model trained in one installation to serve as a base model in another installation by normalizing the loss vectors of each installation.

13. The device of claim 8 , wherein the sampled network traffic is sampled on a network attached storage (NAS).

14. The device of claim 8 , wherein the sampled network traffic comprises vectors each representing a different time interval.

Assignments (2)
SECURITY INTEREST Recorded Dec 18, 2024
From: TWEENZNET LTD.
To: HOFFMAN, CARL W
Reel/Frame 069621/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2022
From: ELYASHIV, EYAL; UPFAL, ELIEZER; YEHEZKEL, AVIV
To: TWEENZNET LTD.
Reel/Frame 059979/0367 →
Continuity (2)
Provisional Application 62940266 · Nov 26, 2019
Related Publication 20210160257A1 · May 27, 2021
Cited By (3)
US 12,229,261 US 12,621,313 US 12,689,579