IP Library Granted Patent US 12,225,027
Granted Patent B2
US 12,225,027 · App. 17/215,809 · Granted Feb 11, 2025

System and method for detection of abnormal device traffic behavior

Inventors: Evgeny Luk-Zilberman (Herzliya, IL); Gil Ben Zvi (Hod Hasharon, IL); Tom Hanetz (Tel Aviv, IL); Ron Shoham (Tel Aviv, IL); Yuval Friedlander (Petah-Tiqwa, IL)
Assignee: Armis Security Ltd.
H04L63/1425G06F16/285H04L63/1441G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,027
App. No.
17/215,809
Granted
Feb 11, 2025
Kind
B2
Abstract

A system and method for detecting abnormal device traffic behavior. The method includes creating a baseline clustering model for a device based on a training data set including traffic data for the device, wherein the baseline clustering model includes a plurality of clusters, each cluster representing a discrete state and including a plurality of first data points of the training data set; sampling a plurality of second data points with respect to windows of time in order to create at least one sample, each sample including at least a portion of the plurality of second data points, wherein the plurality of second data points are related to traffic involving the device; and detecting anomalous traffic behavior of the device based on the at least one sample and the baseline clustering model.

Claims (50)

1. A method, comprising:

creating a baseline clustering model specific to a device based on a training data set including traffic data for the device, wherein the baseline clustering model includes a plurality of clusters, each cluster of the plurality of clusters representing a discrete state and including a plurality of first data points of the training data set;

sampling a plurality of second data points with respect to windows of time thereby creating at least one sample, each sample of the at least one sample including at least a portion of the plurality of second data points, wherein the plurality of second data points are related to traffic involving the device;

calculating, for each second data point of the plurality of second data points in the at least one sample, a risk factor score based on a vector representation of the respective second data point in a traffic feature space and a proximity of the respective second data point to one of the plurality of clusters in the baseline clustering model specific to the device;

determining, for each second data point in the at least one sample, whether the respective second data point is an outlier based on the plurality of clusters in the baseline clustering model specific to the device;

detecting anomalous traffic behavior of the device by identifying a second data point in the at least one sample as an anomalous data point based on the risk factor score of that second data point and that second data point being a determined outlier;

updating the plurality of clusters of the baseline clustering model based on the at least one sample and the risk factor score for each second data point of each sample, wherein the updating comprises adding each sample having a high risk factor score as a new cluster to the plurality of clusters; and

performing at least one mitigation action based on the detected anomalous traffic behavior.

2. The method of claim 1 , wherein the detecting the anomalous traffic behavior further comprises:

for each second data point of each sample, determining whetherthe second data point is an outlier with respect to one of the plurality of clusters, wherein the anomalous traffic behavior is detected further based on at least one outlier second data point of the plurality of second data points.

3. The method of claim 1 , wherein the risk factor score for each second data point in the plurality of second data points is determined based on a vector representation of the second data point in a traffic feature space and a proximity of the second data point to one of the plurality of clusters.

4. The method of claim 3 , wherein the risk factor score is determined further based on a norm of the vector representation of the second data point, a length of a projection of the vector representation over a centroid of closest cluster of the plurality of clusters, and a length of the projection over a diagonal vector of the traffic feature space.

5. The method of claim 1 , wherein the updating the plurality of clusters further comprises:

integrating each sample having a risk factor score below a threshold into one of the plurality of clusters.

6. The method of claim 1 , wherein the detecting the anomalous traffic behavior further comprises:

comparing the risk factor score of each second data point of each sample to a threshold thereby determining whether the respective second data point for the risk factor score is high risk, wherein the respective second data point is high risk when the risk factor score for the respective second data point is above the threshold.

7. The method of claim 6 , further comprising:

updating the threshold based on the detected anomalous traffic behavior.

8. The method of claim 6 , wherein the threshold is a proportional value of a highest risk factor score among each second data point of each sample.

9. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

creating a baseline clustering model specific to a device based on a training data set including traffic data for the device, wherein the baseline clustering model includes a plurality of clusters, each cluster of the plurality of clusters representing a discrete state and including a plurality of first data points of the training data set;

sampling a plurality of second data points with respect to windows of time thereby creating at least one sample, each sample of the at least one sample including at least a portion of the plurality of second data points, wherein the plurality of second data points are related to traffic involving the device;

calculating, for each second data point of the plurality of second data points in the at least one sample, a risk factor score based on a vector representation of the respective second data point in a traffic feature space and a proximity of the respective second data point to one of the plurality of clusters in the baseline clustering model specific to the device;

determining, for each second data point in the at least one sample, whether the respective second data point is an outlier based on the plurality of clusters in the baseline clustering model specific to the device;

detecting anomalous traffic behavior of the device by identifying a second data point in the at least one sample as an anomalous data point based on the risk factor score of that second data point and that second data point being a determined outlier;

updating the plurality of clusters of the baseline clustering model based on the at least one sample and risk factor score for each second data point of each sample, wherein the updating includes adding each sample having a high risk factor score as a new cluster to the plurality of clusters; and

performing at least one mitigation action based on the detected anomalous traffic behavior.

10. The non-transitory computer readable medium of claim 9 , wherein the process further comprises:

for each second data point of each sample, determine whetherthe second data point is an outlier with respect to one of the plurality of clusters, wherein the anomalous traffic behavior is detected further based on at least one outlier second data point of the plurality of second data points.

11. A system for detecting abnormal device traffic behavior, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

create a baseline clustering model specific to a device based on a training data set including traffic data for the device, wherein the baseline clustering model includes a plurality of clusters, each cluster of the plurality of clusters representing a discrete state and including a plurality of first data points of the training data set;

sample a plurality of second data points with respect to windows of time thereby creating at least one sample, each sample of the at least one sample including at least a portion of the plurality of second data points, wherein the plurality of second data points are related to traffic involving the device;

calculate, for each second data point of the plurality of second data points in the at least one sample, a risk factor score based on a vector representation of the respective second data point in a traffic feature space and a proximity of the respective second data point to one of the plurality of clusters in the baseline clustering model specific to the device;

determine, for each second data point in the at least one sample, whether the respective second data point is an outlier based on the plurality of clusters in the baseline clustering model specific to the device;

detect anomalous traffic behavior of the device by identifying a second data point in the at least one sample as an anomalous data point based on the risk factor score of that second data point and that second data point being a determined outlier;

update the plurality of clusters of the baseline clustering model based on the at least one sample and the risk factor score for each second data point of each sample, wherein the update includes adding each sample having a high risk factor score as a new cluster to the plurality of clusters; and

performing at least one mitigation action based on the detected anomalous traffic behavior.

12. The system of claim 11 , wherein the system is further configured to:

for each second data point of each sample, determine whether the second data point is an outlier with respect to one of the plurality of clusters, wherein the anomalous traffic behavior is detected further based on at least one outlier second data point of the plurality of second data points.

13. The system of claim 11 , wherein the risk factor score for each second data point in the plurality of second data points is determined based on a vector representation of the second data point in a traffic feature space and a proximity of the second data point to one of the plurality of clusters.

14. The system of claim 11 , wherein the system is further configured to:

integrate each sample having a risk factor score below a threshold into one of the plurality of clusters.

15. The system of claim 11 , wherein the system is further configured to:

compare the risk factor score of each second data point of each sample to a threshold thereby determining whether the respective second data point for the risk factor score is high risk, wherein the respective second data point is high risk when the risk factor score for the respective second data point is above the threshold.

16. The system of claim 15 , wherein the system is further configured to:

update the threshold based on the detected anomalous traffic behavior.

17. The system of claim 15 , wherein the threshold is a proportional value of a highest risk factor score among each second data point of each sample.

18. The system of claim 13 , wherein the risk factor score is determined further based on a norm of the vector representation of the second data point, a length of a projection of the vector representation over a centroid of closest cluster of the plurality of clusters, and a length of the projection over a diagonal vector of the traffic feature space.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Apr 21, 2026
From: HERCULES CAPITAL, INC.
To: ARMIS SECURITY LTD; ARMIS INC.
Reel/Frame 075477/0965 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 5, 2024
From: ARMIS SECURITY LTD.
To: HERCULES CAPITAL, INC., AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 066740/0499 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 29, 2021
From: LUK-ZILBERMAN, EVGENY; BEN ZVI, GIL; HANETZ, TOM; SHOHAM, RON; FRIEDLANDER, YUVAL
To: ARMIS SECURITY LTD.
Reel/Frame 055755/0393 →
Continuity (1)
Related Publication 20220311789A1 · Sep 29, 2022
References Cited (31)
US 7508769B1 · Duffield et al. · 2009 [cited by applicant]
US 7512980B2 · Copeland et al. · 2009 [cited by applicant]
US 7921462B2 · Rooney et al. · 2011 [cited by applicant]
US 8392496B2 · Linden et al. · 2013 [cited by applicant]
US 9154982B2 · Chan et al. · 2015 [cited by applicant]
US 9692775B2 · Zhang · 2017 [cited by applicant]
US 9756067B2 · Boyadjiev · 2017 [cited by examiner]
US 10318886B2 · Baradaran et al. · 2019 [cited by applicant]
US 10909470B2 · Pietrobon et al. · 2021 [cited by applicant]
US 20160219067A1 · Han et al. · 2016 [cited by examiner]
US 20170124478A1 · Baradaran et al. · 2017 [cited by applicant]
US 20170208079A1 · Cammarota et al. · 2017 [cited by applicant]
US 20190116193A1 · Wang · 2019 [cited by examiner]
US 20190303710A1 · Saha et al. · 2019 [cited by applicant]
US 20190372934A1 · Yehudai · 2019 [cited by examiner]
US 20200106795A1 · Servajean · 2020 [cited by examiner]
US 20200112571A1 · Koral et al. · 2020 [cited by applicant]
US 20200120144A1 · Yadav · 2020 [cited by examiner]
US 20200379868A1 · Dherange et al. · 2020 [cited by applicant]
US 20210049270A1 · Urmanov · 2021 [cited by examiner]
US 20210064593A1 · Yeddu · 2021 [cited by examiner]
US 20210126931A1 · Babu · 2021 [cited by examiner]
US 20210133346A1 · Alsharif · 2021 [cited by examiner]
US 20210342207A1 · Oliveri · 2021 [cited by examiner]
US 20220086071A1 · Sivaraman · 2022 [cited by examiner]
CN 103368979B · 2015 [cited by applicant]
KR 100974888B1 · 2010 [cited by applicant]
International Search Report and Written Opinion of International Searching Authority for PCT/IB2022/052894, ISA/IL, Jerusalem, Israel, Dated: Jun. 27, 2022. [cited by applicant]
Andziński et al. Anomaly detection in DNS traffic, Clustering-based approach, Nov. 5, 2019, https://www.icann.org/sites/default/files/packages/ids-2019/05-andzinski-anomaly-detection-in-dns-traffic-11may19-en.pdf. [cited by applicant]
Rihan et al. Abnormal Network Traffic Detection based on Clustering and Classification Techniques: DoS Case Study, A Thesis Submitted in Partial Fulfillment of the Requirement for the Degree of Master in Information Tec… [cited by applicant]
Extended European Search Report, from the European Patent Office (EPO), Application No. EP 22779275.1, dated Jul. 8, 2024, 7 pages. [cited by applicant]
Cited By (4)
US 12,470,593 US 12,572,846 US 12,574,399 US 12,695,752