IP Library › Granted Patent US 11,893,005
Granted Patent B2
US 11,893,005 · App. 17/144,829 · Granted Feb 6, 2024

Anomaly detection based on an event tree

Inventor: John Raymond Herrema, III (Palo Alto, CA)
Assignee: BlackBerry Limited
G06F16/2365
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,893,005
App. No.
17/144,829
Granted
Feb 6, 2024
Kind
B2
Abstract

Systems, methods, and software can be used for anomaly detection. In some aspect, a number of training events are obtained. A data structure represented by a decision tree is generated based on the number of training events. A to-be-scored event is obtained and a traversed path is determined for the to-be-scored event. An anomaly score is computed based on the traversed path and the to-be-scored event is determined to be an anomalous or normal event based on the anomaly score.

Claims (71)

1. A computer-implemented method, comprising:

obtaining a data structure represented by a decision tree, wherein the data structure represented by the decision tree is generated based on a plurality of training events, wherein each of the plurality of training events has a plurality of attributes, and wherein each of the plurality of attributes has an attribute value, wherein the decision tree comprises a plurality of event nodes comprising a root node, one or more non-leaf nodes, and one or more branches, and one or more leaf nodes, wherein each of the plurality of event nodes represents one of the plurality of attributes and one of a plurality of attribute values, wherein each of the one or more branches below a non-leaf node represents an attribute value of an attribute represented by the non-leaf node, wherein each of the plurality of attributes is associated with an importance level for detecting anomalies, wherein the one or more nodes are arranged in the decision tree based on the importance level of the plurality of attributes, and wherein a first node representing a first attribute having a first importance level is positioned at a higher layer than a second node representing a second attribute having a second importance level when the first importance level is more important than the second importance level;

obtaining a to-be-scored event, wherein the to-be-scored event has one or more attributes of the plurality of attributes and one or more attribute values;

determining a traversed path for the to-be-scored event by mapping the one or more attributes and the one or more attribute values of the to-be-scored event to the decision tree, wherein the mapping comprises:

determining whether the to-be-scored event has a first attribute value for the first attribute having the first importance level;

in response to determining that the to-be-scored event has the first attribute value for the first attribute having the first importance level, determining whether the first attribute value for the first attribute matches an attribute value of a branch associated with the root node;

in response to determining that the to-be-scored event has the first attribute value for the first attribute having the first importance level matches the attribute value of a branch associated with the root node, determining a child node associated with the branch as a first child node for the to-be-scored event;

determining whether the to-be-scored event has a second attribute value for the second attribute having the second importance level;

determining a second child node for the to-be-scored event based on matching the second attribute value for the second attribute having the second importance level with attribute values of child nodes of the first child node, wherein the second child node is a child node of the first child node;

determining whether the to-be-scored event has a third attribute value for a third attribute having a third importance level, wherein the second importance level is more important than the third importance level; and

determining a third child node for the to-be-scored event based on matching the third attribute value for the third attribute having the third importance level with attribute values of child nodes of the second child node, wherein the third child node is a child node of the second child node;

computing an anomaly score of the to-be-scored event based on the traversed path, wherein the computing the anomaly score comprises:

determining a path length of each node on the traversed path;

determining a path length of the to-be-scored event by summing the path length of each node on the traversed path; and

determining the anomaly score based on the path length of the to-be-scored event relative to an average path length;

determining whether the to-be-scored event is an anomalous event based on the anomaly score; and

identifying a compromised device based on the anomaly score.

2. The computer-implemented method of claim 1 , wherein each of the one or more leaf nodes or the one or more non-leaf nodes is associated with a permutation of attribute values occurring in the plurality of training events for one or more of the plurality of attributes.

3. The computer-implemented method of claim 2 , wherein each of the one or more non-leaf nodes is a parent node associated with at least one branch of the decision tree based on a number of child nodes associated with the parent node.

4. The computer-implemented method of claim 3 , wherein each of the one or more leaf nodes is a child node of a non-leaf node of the decision tree, wherein each of the one or more leaf nodes is associated with one branch of the decision tree, and wherein each of the one or more leaf nodes has no child node.

5. The computer-implemented method of claim 4 , wherein child nodes of a non-leaf node are associated with branches represented by different attribute values.

6. The computer-implemented method of claim 4 , wherein a child node of a non-leaf node represents a subset of training events mapped to a parent node of the child node.

7. The computer-implemented method of claim 2 , wherein a non-leaf node of the decision tree that represents an attribute having a highest importance level is a root node of the decision tree.

8. The computer-implemented method of claim 1 , wherein determining the traversed path for the to-be-scored event comprises:

determining a plurality of leaf nodes and non-leaf nodes in the decision tree that are mapped to the to-be-scored event based on the importance level of the one or more attributes of the to-be-scored event.

9. An electronic device, comprising:

a memory; and

at least one hardware processor communicatively coupled with the memory and configured to perform operations comprising:

obtaining a data structure represented by a decision tree, wherein the data structure represented by the decision tree is generated based on a plurality of training events, wherein each of the plurality of training events has a plurality of attributes, and wherein each of the plurality of attributes has an attribute value, wherein the decision tree comprises a plurality of event nodes comprising a root node, one or more non-leaf nodes, and one or more branches, and one or more leaf nodes, wherein each of the plurality of event nodes represents one of the plurality of attributes and one of a plurality of attribute values, wherein each of the one or more branches below a non-leaf node represents an attribute value of an attribute represented by the non-leaf node, wherein each of the plurality of attributes is associated with an importance level for detecting anomalies, wherein the one or more nodes are arranged in the decision tree based on the importance level of the plurality of attributes, and wherein a first node representing a first attribute having a first importance level is positioned at a higher layer than a second node representing a second attribute having a second importance level when the first importance level is more important than the second importance level;

obtaining a to-be-scored event, wherein the to-be-scored event has one or more attributes of the plurality of attributes and one or more attribute values;

determining a traversed path for the to-be-scored event by mapping the one or more attributes and the one or more attribute values of the to-be-scored event to the decision tree, wherein the mapping comprises:

determining whether the to-be-scored event has a first attribute value for the first attribute having the first importance level;

in response to determining that the to-be-scored event has the first attribute value for the first attribute having the first importance level, determining whether the first attribute value for the first attribute matches an attribute value of a branch associated with the root node;

in response to determining that the to-be-scored event has the first attribute value for the first attribute having the first importance level matches the attribute value of a branch associated with the root node, determining a child node associated with the branch as a first child node for the to-be-scored event;

determining whether the to-be-scored event has a second attribute value for the second attribute having the second importance level;

determining a second child node for the to-be-scored event based on matching the second attribute value for the second attribute having the second importance level with attribute values of child nodes of the first child node, wherein the second child node is a child node of the first child node;

determining whether the to-be-scored event has a third attribute value for a third attribute having a third importance level, wherein the second importance level is more important than the third importance level; and

determining a third child node for the to-be-scored event based on matching the third attribute value for the third attribute having the third importance level with attribute values of child nodes of the second child node, wherein the third child node is a child node of the second child node;

computing an anomaly score of the to-be-scored event based on the traversed path, wherein the computing the anomaly score comprises:

determining a path length of each node on the traversed path;

determining a path length of the to-be-scored event by summing the path length of each node on the traversed path; and

determining the anomaly score based on the path length of the to-be-scored event relative to an average path length;

determining whether the to-be-scored event is an anomalous event based on the anomaly score; and

identifying a compromised device based on the anomaly score.

10. The electronic device of claim 9 , wherein each of the one or more leaf nodes or the one or more non-leaf nodes is associated with a permutation of attribute values occurring in the plurality of training events for one or more of the plurality of attributes.

11. The electronic device of claim 10 , wherein each of the one or more non-leaf nodes is a parent node associated with at least one branch of the decision tree based on a number of child nodes associated with the parent node.

12. The electronic device of claim 11 , wherein each of the one or more leaf nodes is a child node of a non-leaf node of the decision tree, wherein each of the one or more leaf nodes is associated with one branch of the decision tree, and wherein each of the one or more leaf nodes has no child node.

13. The electronic device of claim 12 , wherein child nodes of a non-leaf node are associated with branches represented by different attribute values.

14. The electronic device of claim 12 , wherein a child node of a non-leaf node represents a subset of training events mapped to a parent node of the child node.

15. A non-transitory computer-readable medium containing instructions which, when executed, cause a computing device to perform operations comprising:

obtaining a data structure represented by a decision tree, wherein the data structure represented by the decision tree is generated based on a plurality of training events, wherein each of the plurality of training events has a plurality of attributes, and wherein each of the plurality of attributes has an attribute value, wherein the decision tree comprises a plurality of event nodes comprising a root node, one or more non-leaf nodes, and one or more branches, and one or more leaf nodes, wherein each of the plurality of event nodes represents one of the plurality of attributes and one of a plurality of attribute values, wherein each of the one or more branches below a non-leaf node represents an attribute value of an attribute represented by the non-leaf node, wherein each of the plurality of attributes is associated with an importance level for detecting anomalies, wherein the one or more nodes are arranged in the decision tree based on the importance level of the plurality of attributes, and wherein a first node representing a first attribute having a first importance level is positioned at a higher layer than a second node representing a second attribute having a second importance level when the first importance level is more important than the second importance level;

obtaining a to-be-scored event, wherein the to-be-scored event has one or more attributes of the plurality of attributes and one or more attribute values;

determining a traversed path for the to-be-scored event by mapping the one or more attributes and the one or more attribute values of the to-be-scored event to the decision tree, wherein the mapping comprises:

determining whether the to-be-scored event has a first attribute value for the first attribute having the first importance level;

in response to determining that the to-be-scored event has the first attribute value for the first attribute having the first importance level, determining whether the first attribute value for the first attribute matches an attribute value of a branch associated with the root node;

in response to determining that the to-be-scored event has the first attribute value for the first attribute having the first importance level matches the attribute value of a branch associated with the root node, determining a child node associated with the branch as a first child node for the to-be-scored event;

determining whether the to-be-scored event has a second attribute value for the second attribute having the second importance level;

determining a second child node for the to-be-scored event based on matching the second attribute value for the second attribute having the second importance level with attribute values of child nodes of the first child node, wherein the second child node is a child node of the first child node;

determining whether the to-be-scored event has a third attribute value for a third attribute having a third importance level, wherein the second importance level is more important than the third importance level; and

determining a third child node for the to-be-scored event based on matching the third attribute value for the third attribute having the third importance level with attribute values of child nodes of the second child node, wherein the third child node is a child node of the second child node;

computing an anomaly score of the to-be-scored event based on the traversed path, wherein the computing the anomaly score comprises:

determining a path length of each node on the traversed path;

determining a path length of the to-be-scored event by summing the path length of each node on the traversed path; and

determining the anomaly score based on the path length of the to-be-scored event relative to an average path length;

determining whether the to-be-scored event is an anomalous event based on the anomaly score; and

identifying a compromised device based on the anomaly score.

16. The non-transitory computer-readable medium of claim 15 , wherein each of the one or more leaf nodes or the one or more non-leaf nodes is associated with a permutation of attribute values occurring in the plurality of training events for one or more of the plurality of attributes.

17. The non-transitory computer-readable medium of claim 16 , wherein each of the one or more non-leaf nodes is a parent node associated with at least one branch of the decision tree based on a number of child nodes associated with the parent node.

18. The non-transitory computer-readable medium of claim 17 , wherein each of the one or more leaf nodes is a child node of a non-leaf node of the decision tree, wherein each of the one or more leaf nodes is associated with one branch of the decision tree, and wherein each of the one or more leaf nodes has no child node.

19. The non-transitory computer-readable medium of claim 18 , wherein child nodes of a non-leaf node are associated with branches represented by different attribute values.

20. The non-transitory computer-readable medium of claim 18 , wherein a child node of a non-leaf node represents a subset of training events mapped to a parent node of the child node.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2021
From: BLACKBERRY CORPORATION
To: BLACKBERRY LIMITED
Reel/Frame 055306/0188 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2021
From: HERREMA, JOHN RAYMOND, III
To: BLACKBERRY CORPORATION
Reel/Frame 055018/0531 →
Continuity (1)
Related Publication 20220222238A1 · Jul 14, 2022