IP Library Granted Patent US 12,153,669
Granted Patent B2
US 12,153,669 · App. 17/158,650 · Granted Nov 26, 2024

Cyber immunity system as a biological self-recognition model on operating systems

Inventors: Ohad Arnon (Beit Nir, IL); Dany Shapiro (Alfi Menashe, IL); Shiri Gaber (Beer Sheva, IL)
Assignee: EMC IP Holding Company LLC
G06F21/554G06F21/60G06N20/00G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,153,669
App. No.
17/158,650
Granted
Nov 26, 2024
Kind
B2
Abstract

One example method includes data protection operations including cyber security operations, threat detection operations, and other security operations. Normal device behavior is learned based on data collected by an anomaly detection engine operating in a kernel. The normal data is used to train a machine learning model. Threats are detected when the machine learning model indicates that new data points deviate from normal device behavior. Associated processes are stopped. This allows threats to be detected based on normal behavior rather than on unknown threat behavior.

Claims (36)

1. A method for detecting threats in a computing device that includes an operating system, the method comprising:

collecting data corresponding to a flow of the device, the flow including one or more data points corresponding to a behavior of the device;

organizing the collected data into pair data, wherein the pair data includes a process identifier and an action;

generating time series data from the pair data;

extracting features from the time series data;

inputting the features extracted from the time series data into time series models, wherein the time series models are configured to generate a predicted value for the features and each of the time series models corresponds to a feature;

determining residuals for each of the features by comparing the predicted values with actual values of the features;

inputting the residuals to a machine learning model to generate an output, wherein the output is a probability a threat is occurring, wherein the machine learning model configured to identify anomalous device behavior in the device and wherein the machine learning model is trained using data corresponding to normal device behavior;

identifying, using the process identifiers, one or more processes that contributed to the probability; and

stopping at least one process of the one or more processes that contributed to the probability when the output indicates a threat based on the detected anomalous device behavior.

2. The method of claim 1 , wherein the normal device behavior is learned from historical collected data that includes historical data corresponding to normal device behavior, further comprising includes generating time series data from the collected data.

3. The method of claim 2 , wherein the collected data is collected from system calls including one or more of process control data, device management data, file management data, communication data, and information maintenance data.

4. The method of claim 1 , further comprising training the machine learning model such that abnormal device behavior is determined to be the threat.

5. The method of claim 1 , further comprising further comprising identifying the one or more processes based on the corresponding residuals.

6. The method of claim 1 , further comprising verifying whether the threat is a real threat.

7. The method of claim 1 , wherein the machine learning model is configured to identify whether an attack is occurring based on an output of the machine learning model that represents a deviation from the normal device behavior.

8. The method of claim 1 , further comprising, wherein the threat is detected by an anomaly detection engine operating in a kernel of an operating system.

9. The method of claim 1 , wherein a process that contributes most to the probability is terminated.

10. The method of claim 1 , wherein the probability is associated with thresholds, wherein a first threshold is associated with generating a notification, wherein a second threshold is associated with terminating the process.

11. A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations for detecting threats in a computing device that includes an operating system, the operations comprising:

collecting data corresponding to a flow of the device, the flow including one or more data points corresponding to a behavior of the device;

organizing the collected data into pair data, wherein the pair data includes a process identifier and an action;

generating time series data from the pair data;

extracting features from the time series data;

inputting the features extracted from the time series data into time series models, wherein the time series models are configured to generate a predicted value for the features and each of the time series models corresponds to a feature;

determining residuals for each of the features by comparing the predicted values with actual value of the features;

inputting the residuals to a machine learning model to generate an output, wherein the output is a probability a threat is occurring, wherein the machine learning model configured to identify anomalous device behavior in the device and wherein the machine learning model is trained using data corresponding to normal device behavior;

identifying, using the process identifiers, one or more processes that contributed to the probability; and

stopping at least one process of the one or more processes that contributed to the probability when the indicates a threat based on the detected anomalous device behavior.

12. The non-transitory storage medium of claim 11 , wherein the normal device behavior is learned from historical collected data that includes historical data corresponding to normal device behavior, further comprising includes generating time series data from the collected data.

13. The non-transitory storage medium of claim 12 , wherein the collected data is collected from system calls including one or more of process control data, device management data, file management data, communication data, and information maintenance data.

14. The non-transitory storage medium of claim 11 , further comprising training the model such that abnormal device behavior is determined to be the threat.

15. The non-transitory storage medium of claim 11 , further comprising further comprising identifying the one or more processes based on the corresponding residuals.

16. The non-transitory storage medium of claim 11 , further comprising verifying whether the threat is a real threat.

17. The non-transitory storage medium of claim 11 , wherein the machine learning model is configured to identify whether an attack is occurring based on an output of the machine learning model that represents a deviation from the normal device behavior.

18. The non-transitory storage medium of claim 11 , wherein the threat is detected by an anomaly detection engine operating in a kernel of an operating system.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2021
From: ARNON, OHAD; SHAPIRO, DANY; GABER, SHIRI
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 055035/0980 →
Continuity (1)
Related Publication 20220237285A1 · Jul 28, 2022
Cited By (2)
US 12,566,850 US 12,613,958