IP Library Granted Patent US 12,301,589
Granted Patent B2
US 12,301,589 · App. 17/332,346 · Granted May 13, 2025

Intrusion detection using machine learning

Inventors: Immanuel Savio Donbosco (Chennai, IN); Prerit Pathak (Jaipur, IN); Bijan Kumar Mohanty (Austin, TX); Hung Dinh (Austin, TX)
Assignee: Dell Products L.P.
H04L63/1416G06N5/04G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,589
App. No.
17/332,346
Granted
May 13, 2025
Kind
B2
Abstract

A method comprises collecting network data associated with data transmission in a computing environment. The method also comprises identifying, using one or more machine learning models, at least one intrusion type affecting the computing environment. The identification of the at least one intrusion type is based at least in part on the collected network data. In the method, one or more remedial communications addressing the at least one intrusion type are generated, and the one or more remedial communications are transmitted to a user.

Claims (47)

1. An apparatus comprising:

at least one processing platform comprising at least one processing device comprising a processor coupled to a memory;

said at least one processing platform being configured:

to collect network data associated with data transmission in a computing environment;

to identify, using one or more machine learning models, at least one intrusion type affecting the computing environment, wherein the identification of the at least one intrusion type is based at least in part on the collected network data, and wherein, in identifying the at least one intrusion type affecting the computing environment, said at least one processing platform is configured:

to input at least a portion of the collected network data to a first autoencoder, wherein the first autoencoder reduces dimensions of the portion of the collected network data from a first number of features to a second number of features and generates a first output based on the reduced dimensions; and

to input the first output based on the reduced dimensions to a second autoencoder, wherein the second autoencoder further reduces the dimensions of the portion of the collected network data from the second number of features to a third number of features and generates a second output based on the further reduced dimensions;

to generate one or more remedial communications addressing the at least one intrusion type; and

to transmit the one or more remedial communications to a user;

wherein the at least one intrusion type comprises an attack on at least a portion of the computing environment; and

wherein the one or more machine learning models are trained at least in part with training data indicating an absence of intrusions.

2. The apparatus of claim 1 wherein said at least one processing platform is configured to perform the identification of the at least one intrusion type and the generation of the one or more remedial communications as a real-time response to the collection of the network data.

3. The apparatus of claim 1 wherein the collected network data comprises at least one of connection data, traffic data and content data.

4. The apparatus of claim 3 wherein the collected network data further comprises one or more indications of at least one of protocol type, service type and one or more connection status flags.

5. The apparatus of claim 1 wherein, in collecting the network data, said at least one processing platform is configured to intercept one or more data packets comprising metadata corresponding to a live data transmission.

6. The apparatus of claim 1 wherein the one or more remedial communications comprise at least one of a name of the at least one intrusion type, a class of the at least one intrusion type and network location information associated with the at least one intrusion type.

7. The apparatus of claim 1 wherein the one or more remedial communications comprise one or more mitigation measures to at least one of curtail and prevent the at least one intrusion type.

8. The apparatus of claim 1 wherein the training data further comprises at least one of connection data, traffic data and content data.

9. The apparatus of claim 8 wherein said at least one processing platform is configured to reduce dimensions of the training data.

10. The apparatus of claim 8 wherein the training data further indicates identified intrusion types, and wherein the identified intrusion types and the absence of intrusions correspond to respective groupings of at least one of the connection data, the traffic data and the content data.

11. The apparatus of claim 1 wherein the at least one processing platform is further configured to input to the one or more machine learning models at designated intervals updated training data indicating the absence of intrusions.

12. The apparatus of claim 1 wherein the first output comprises the second number of features and the second output comprises the third number of features.

13. The apparatus of claim 12 wherein, in identifying the at least one intrusion type affecting the computing environment, said at least one processing platform is further configured to input the third number of features to a multiclass logistic classifier, the multiclass logistic classifier classifying the third number of features into the at least one intrusion type.

14. The apparatus of claim 13 wherein the at least one intrusion type comprises one of a denial of service (DOS) attack, a user to root (U2R) attack, a root to local (R2L) attack and a probing attack.

15. A method comprising:

collecting network data associated with data transmission in a computing environment;

identifying, using one or more machine learning models, at least one intrusion type affecting the computing environment, wherein the identification of the at least one intrusion type is based at least in part on the collected network data, and wherein identifying the at least one intrusion type affecting the computing environment comprises:

inputting at least a portion of the collected network data to a first autoencoder, wherein the first autoencoder reduces dimensions of the portion of the collected network data from a first number of features to a second number of features and generates a first output based on the reduced dimensions; and

inputting the first output based on the reduced dimensions to a second autoencoder, wherein the second autoencoder further reduces the dimensions of the portion of the collected network data from the second number of features to a third number of features and generates a second output based on the further reduced dimensions;

generating one or more remedial communications addressing the at least one intrusion type; and

transmitting the one or more remedial communications to a user;

wherein the at least one intrusion type comprises an attack on at least a portion of the computing environment;

wherein the one or more machine learning models are trained at least in part with training data indicating an absence of intrusions; and

wherein the method is performed by at least one processing platform comprising at least one processing device comprising a processor coupled to a memory.

16. The method of claim 15 further comprising inputting to the one or more machine learning models at designated intervals updated training data indicating the absence of intrusions.

17. The method of claim 15 wherein the first output comprises the second number of features and the second output comprises the third number of features.

18. The method of claim 17 wherein identifying the at least one intrusion type affecting the computing environment further comprises inputting the third number of features to a multiclass logistic classifier, the multiclass logistic classifier classifying the third number of features into the at least one intrusion type.

19. A computer program product comprising a non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing platform causes said at least one processing platform:

to collect network data associated with data transmission in a computing environment;

to identify, using one or more machine learning models, at least one intrusion type affecting the computing environment, wherein the identification of the at least one intrusion type is based at least in part on the collected network data, and wherein, in identifying the at least one intrusion type affecting the computing environment, the program code further causes said at least one processing platform:

to input at least a portion of the collected network data to a first autoencoder, wherein the first autoencoder reduces dimensions of the portion of the collected network data from a first number of features to a second number of features and generates a first output based on the reduced dimensions; and

to input the first output based on the reduced dimensions to a second autoencoder, wherein the second autoencoder further reduces the dimensions of the portion of the collected network data from the second number of features to a third number of features and generates a second output based on the further reduced dimensions;

to generate one or more remedial communications addressing the at least one intrusion type; and

to transmit the one or more remedial communications to a user;

wherein the at least one intrusion type comprises an attack on at least a portion of the computing environment; and

wherein the one or more machine learning models are trained at least in part with training data indicating an absence of intrusions.

20. The computer program product according to claim 19 wherein the first output comprises the second number of features and the second output comprises the third number of features.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (058014/0560) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0473 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057931/0392) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 062022/0382 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (057758/0286) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 061654/0064 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 058014/0560 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057758/0286 →
SECURITY INTEREST Recorded Oct 6, 2021
From: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 057931/0392 →
SECURITY AGREEMENT Recorded Oct 1, 2021
From: DELL PRODUCTS, L.P.; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 057682/0830 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 27, 2021
From: DONBOSCO, IMMANUEL SAVIO; PATHAK, PRERIT; MOHANTY, BIJAN KUMAR; DINH, HUNG
To: DELL PRODUCTS L.P.
Reel/Frame 056375/0256 →
Continuity (1)
Related Publication 20220385674A1 · Dec 1, 2022
References Cited (13)
US 9654485B1 · Neumann · 2017 [cited by examiner]
US 10916351B1 · Oh · 2021 [cited by examiner]
US 20220021695A1 · Papamartzivanos · 2022 [cited by examiner]
US 20220137611A1 · Naito · 2022 [cited by examiner]
US 20220385674A1 · Donbosco · 2022 [cited by examiner]
US 20240087674A1 · Gligorijevic · 2024 [cited by examiner]
Zeek, “Script Reference,” base/protocols/conn/main.zeek, Accessed May 7, 2021, 6 pages. [cited by applicant]
G. Saporito, “A Deeper Dive into the NSL-KDD Data Set,” https://towardsdatascience.com/a-deeper-dive-into-the-nsl-kdd-data-set-15c753364657, Sep. 16, 2019, 7 pages. [cited by applicant]
S. Rawat et al., “Intrusion Detection Systems Using Classical Machine Learning Techniques versus Integrated Unsupervised Feature Learning and Deep Neural Network,” Internet Technology Letters, Oct. 2020, 9 pages. [cited by applicant]
J. Juanchaiyaphum et al., “Symbolic Data Conversion Method Using the Knowledge-based Extraction in Anomaly Intrusion Detection System,” Journal of Theoretical and Applied Information Technology, vol. 65, No. 3, Jul. 31,… [cited by applicant]
V. Kumar et al, “K-Means Clustering Approach to Analyze NSL-KDD Intrusion Detection Dataset,” International Journal of Soft Computing and Engineering, vol. 3, No. 4, Sep. 2013, 4 pages. [cited by applicant]
Wikipedia, “WannaCry Ransomware Attack,” https://en.wikipedia.org/w/index.php?title=WannaCry_ransomware_attack&oldid=1016481123, Apr. 7, 2021, 19 pages. [cited by applicant]
Wikipedia, “Cryptovirology,” https://en.wikipedia.org/w/index.php?title=Cryptovirology&oldid=1015627672, Apr. 2, 2021, 4 pages. [cited by applicant]