IP Library Granted Patent US 11,496,498
Granted Patent B2
US 11,496,498 · App. 17/221,475 · Granted Nov 8, 2022

Statistical analysis of network behavior using event vectors to identify behavioral anomalies using a composite score

Inventors: William Wright (Los Gatos, CA); George D. Kellerman (Louisville, KY)
Assignee: Webroot Inc.
H04L63/1425G06F21/552G06N7/005H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,496,498
App. No.
17/221,475
Granted
Nov 8, 2022
Kind
B2
Abstract

Examples of the present disclosure describe systems and methods for identifying anomalous network behavior. In aspects, a network event may be observed network sensors. One or more characteristics may be extracted from the network event and used to construct an evidence vector. The evidence vector may be compared to a mapping of previously-identified events and/or event characteristics. The mapping may be represented as one or more clusters of expected behaviors and anomalous behaviors. The mapping may be modeled using analytic models for direction detection and magnitude detection. One or more centroids may be identified for each of the clusters. A “best fit” may be determined and scored for each of the analytic models. The scores may be fused into single binocular score and used to determine whether the evidence vector is likely to represent an anomaly.

Claims (34)

1. A system for identifying anomalous network behavior, comprising:

at least a first processor; and

memory coupled to the at least one processor, the memory comprising computer executable instructions that, when executed by the at least one processor, performs a method for identifying anomalous network behavior, the method comprising:

receiving sensor data for an event representative of a network flow;

extracting characteristics of the sensor data and normalizing the data to generate an evidence vector for the event;

evaluating the evidence vector against a directional cluster mapping of previously observed events;

evaluating the evidence vector against a magnitude cluster mapping of previously observed events;

generating a composite score from the directional cluster mapping evaluation and the magnitude cluster mapping evaluation, the composite score representing a probability that the evidence vector for the event represents a network anomaly; and

comparing the probability with a threshold for identifying the network anomaly and, based said comparing, executing a network countermeasure.

2. The system of claim 1 , wherein the sensor data is stored in a sensor data store and the sensor data is aggregated over a time period for the network flow.

3. The system of claim 1 , wherein one or more of the extracted characteristics are predictive of whether the event is an anomaly.

4. The system of claim 1 , further comprising applying the evidence vector to an analytics model to provide directional cluster mapping representing an expected behavior comprising protocol vectors and comparing the evidence vector to the protocol vectors to identify the most similar protocol vector, the protocol vectors representing an expected network behavior.

5. The system of claim 1 , further comprising applying the evidence vector to an analytics model to provide magnitude cluster mapping representing an expected behavior comprising protocol vectors and comparing the evidence vector to the protocol vectors to identify the most similar protocol vector, the protocol vectors representing an expected network behavior.

6. The system of claim 1 , wherein generating the composite score further comprises applying contextual factors including trending anomalies.

7. The system of claim 1 , further comprising, providing the composite score to a policy engine to provide threat intelligence and the network countermeasure.

8. The system of claim 1 , further comprising executing machine learning to classify the event, modify the composite score, and determine the network countermeasure.

9. The system of claim 1 , further comprising training a model for determining expected network anomalies and emergent network behaviors.

10. The system of claim 1 , further comprising categorizing a behavior of the network anomaly using binocular fusion.

11. A method for identifying anomalous network behavior, comprising:

receiving sensor data for an event representative of a network flow;

extracting characteristics of the sensor data and normalizing the data to generate an evidence vector for the event;

evaluating the evidence vector against a directional cluster mapping of previously observed events;

evaluating the evidence vector against a magnitude cluster mapping of previously observed events;

generating a composite score from the directional cluster mapping evaluation and the magnitude cluster mapping evaluation, the composite score representing a probability that the evidence vector for the event represents a network anomaly; and

comparing the probability with a threshold for identifying the network anomaly and, based said comparing, executing a network countermeasure.

12. The method of claim 11 , wherein the sensor data is stored in a sensor data store and the sensor data is aggregated over a time period for the network flow.

13. The method of claim 11 , wherein one or more of the extracted characteristics are predictive of whether the event is an anomaly.

14. The method of claim 11 , further comprising applying the evidence vector to an analytics model to provide directional cluster mapping representing an expected behavior comprising protocol vectors and comparing the evidence vector to the protocol vectors to identify the most similar protocol vector, the protocol vectors representing an expected network behavior.

15. The method of claim 11 , further comprising applying the evidence vector to an analytics model to provide magnitude cluster mapping representing an expected behavior comprising protocol vectors and comparing the evidence vector to the protocol vectors to identify the most similar protocol vector, the protocol vectors representing an expected network behavior.

16. The method of claim 11 , wherein generating the composite score further comprises applying contextual factors including trending anomalies.

17. The method of claim 11 , further comprising, providing the composite score to a policy engine to provide threat intelligence and the network countermeasure.

18. The method of claim 11 , further comprising executing machine learning to classify the event, modify the composite score, and determine the network countermeasure.

19. The method of claim 11 , further comprising training a model for determining expected network anomalies and emergent network behaviors.

20. The method of claim 11 , further comprising categorizing a behavior of the network anomaly using binocular fusion.

Assignments (4)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2021
From: WRIGHT, WILLIAM; KELLERMAN, GEORGE D.
To: WEBROOT INC.
Reel/Frame 057146/0585 →
Continuity (4)
Continuation 16791658 · Feb 14, 2020
Continuation 15355561 · Nov 18, 2016
Provisional Application 62258380 · Nov 20, 2015
Related Publication 20210226972A1 · Jul 22, 2021
Cited By (34)
US 12,189,774 US 12,212,586 US 12,217,079 US 12,219,048 US 12,219,053 US 12,229,257 US 12,244,627 US 12,244,634 US 12,267,326 US 12,277,216 US 12,278,819 US 12,278,825 US 12,278,840 US 12,278,897 US 12,284,220 US 12,287,899 US 12,353,474 US 12,395,488 US 12,406,071 US 12,411,937 US 12,411,957 US 12,443,720 US 12,443,722 US 12,489,781 US 12,495,049 US 12,505,200 US 12,506,755 US 12,524,550 US 12,531,881 US 12,547,765 US 12,579,251 US 12,645,785 US 12,688,277 US 12,719,918