IP Library › Granted Patent US 11,777,972
Granted Patent B2
US 11,777,972 · App. 17/389,159 · Granted Oct 3, 2023

Network security techniques comparing observed distributions to baseline distributions

Inventor: Matthew Lewis Jones (Boise, ID)
Assignee: Kount Inc.
H04L63/1425H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,777,972
App. No.
17/389,159
Granted
Oct 3, 2023
Kind
B2
Abstract

A method described herein involves various operations directed toward network security. The operations include accessing a traffic attribute describing a feature of network traffic. The operations further include determining a baseline distribution for the traffic attribute of a baseline set of transactions involving an online system over a baseline period and, additionally, determining an observed distribution for the traffic attribute of an observed set of transactions involving the online system over an observed period. Using the observed distribution and the baseline distribution, an attribute risk value for the traffic attribute is computed. The operations further include detecting that an anomaly exists in the traffic attribute of the observed set of transactions, based on the attribute risk value. Responsive to detecting the anomaly, an access control is implemented for access to the online system by additional transactions having a particular value in the traffic attribute meeting a pattern of the anomaly.

Claims (57)

1. A method comprising:

accessing a traffic attribute describing a characteristic of network traffic;

determining a baseline distribution of the traffic attribute over a baseline set of transactions involving an online system over a baseline period by applying a first filter with a first timescale and a second filter with a second timescale to the traffic attribute in the baseline set of transactions over a baseline period, wherein the first timescale is larger than the second timescale, and wherein determining the baseline distribution for the traffic attribute by applying the first filter with the first timescale comprises:

computing respective frequencies of one or more values of the traffic attribute at which the one or more values appear in the baseline set of transactions over the first timescale, and

computing, for the traffic attribute, a first mean of the frequencies;

determining an observed distribution of the traffic attribute over an observed set of transactions involving the online system over an observed period;

computing, using the observed distribution and the baseline distribution, an attribute risk value for the traffic attribute;

detecting that an anomaly exists in the traffic attribute of the observed set of transactions, based on the attribute risk value; and

implementing an access control for access to the online system by additional transactions having a particular value in the traffic attribute meeting a pattern of the anomaly.

2. The method of claim 1 , wherein determining the baseline distribution for the traffic attribute further comprises applying exponential smoothing to compute the first mean of the frequencies.

3. The method of claim 1 , wherein:

determining the baseline distribution for the traffic attribute further comprises:

computing respective frequencies of one or more values of the traffic attribute at which the one or more values appear in the baseline set of transactions over the second timescale; and

computing, for the traffic attribute, a second mean of the frequencies; and

computing the attribute risk value comprises comparing the observed distribution to a function of (i) the first mean of the frequencies and (ii) the second mean of the frequencies.

4. The method of claim 1 , wherein determining the observed distribution for the traffic attribute comprises computing, for a feature of the traffic attribute, a first mean frequency at which the feature appears in the observed set of transactions occurring over the first timescale.

5. The method of claim 4 , wherein determining the observed distribution for the traffic attribute further comprises applying exponential smoothing to compute the first mean frequency at which the feature appears in the observed set of transactions occurring over the first timescale.

6. The method of claim 4 , wherein:

determining the observed distribution for the traffic attribute further comprises computing, for the feature of the traffic attribute, a second mean frequency at which the feature appears in the observed set of transactions occurring over the second timescale; and

computing the attribute risk value comprises comparing the baseline distribution to a function of (i) the first mean frequency at which the feature appears in the observed set of transactions over the first timescale and (ii) the second mean frequency at which the feature appears in the observed set of transactions occurring over the second timescale.

7. The method of claim 1 , wherein detecting that the anomaly exists in the traffic attribute of the observed set of transactions comprises determining a combined risk value for the observed set of transactions, wherein the combined risk value is based on the attribute risk value aggregated with other attribute risk values.

8. The method of claim 1 , wherein computing, using the observed distribution and the baseline distribution, an attribute risk value for the traffic attribute comprises comparing the observed distribution to the baseline distribution.

9. The method of claim 1 , wherein implementing the access control comprises blocking the additional transactions.

10. The method of claim 1 , wherein implementing the access control comprises challenging one or more transactions associated with the traffic attribute by requesting additional authentication information to complete the one or more transactions.

11. A system comprising;

a processor; and

a non-transitory computer-readable medium comprising instructions that are executable by the processor to cause the processor to perform operations comprising:

accessing a traffic attribute describing a characteristic of network traffic;

determining a baseline distribution for the traffic attribute of a baseline set of transactions involving an online system, by applying a first filter with a first timescale and a second filter with a second timescale to the traffic attribute in the baseline set of transactions over a baseline period, wherein the first timescale is larger than the second timescale, and wherein determining the baseline distribution for the traffic attribute by applying the first filter with the first timescale comprises:

computing respective frequencies of one or more values of the traffic attribute at which the one or more values appear in the baseline set of transactions over the first timescale, and

computing, for the traffic attribute, a first mean of the frequencies;

determining an observed distribution for the traffic attribute of an observed set of transactions involving the online system over an observed period;

computing, using the observed distribution and the baseline distribution, an attribute risk value for the traffic attribute;

detecting that an anomaly exists in the traffic attribute of the observed set of transactions, based on the attribute risk value; and

implementing an access control for access to the online system by additional transactions having a particular value in the traffic attribute meeting a pattern of the anomaly.

12. The system of claim 11 , wherein determining the baseline distribution for the traffic attribute further comprises:

applying exponential smoothing to compute the first mean of the frequencies.

13. The system of claim 12 , wherein determining the observed distribution for the traffic attribute comprises computing additional respective frequencies of one or more values of the traffic attribute in the observed set of transactions.

14. The system of claim 11 , wherein detecting that the anomaly exists in the traffic attribute of the observed set of transactions comprises determining a combined risk value for the observed set of transactions, wherein the combined risk value is based on the attribute risk value aggregated with other attribute risk values.

15. The system of claim 11 , wherein computing, using the observed distribution and the baseline distribution, an attribute risk value for the traffic attribute comprises comparing the observed distribution to the baseline distribution.

16. A non-transitory computer-readable storage medium having program code that is executable by a processor device to cause the processing device to perform operations comprising;

accessing a traffic attribute describing a characteristic of network traffic;

determining a baseline distribution for the traffic attribute of a baseline set of transactions involving an online system, by applying a first filter with a first timescale and a second filter with a second timescale to the traffic attribute in the baseline set of transactions over a baseline period, wherein the first timescale is larger than the second timescale, and wherein determining the baseline distribution for the traffic attribute by applying the first filter with the first timescale comprises:

computing respective frequencies of one or more values of the traffic attribute at which the one or more values appear in the baseline set of transactions over the first timescale, and

computing, for the traffic attribute, a first mean of the frequencies;

determining an observed distribution for the traffic attribute of an observed set of transactions involving the online system over an observed period;

computing, using the observed distribution and the baseline distribution, an attribute risk value for the traffic attribute;

detecting that an anomaly exists in the traffic attribute of the observed set of transactions, based on the attribute risk value; and

implementing an access control for access to the online system by additional transactions having a particular value in the traffic attribute meeting a pattern of the anomaly.

17. The non-transitory computer-readable storage medium of claim 16 , wherein:

determining the baseline distribution for the traffic attribute further comprises:

applying exponential smoothing to compute the first mean of the frequencies; and

determining the observed distribution for the traffic attribute comprises computing additional respective frequencies of one or more values of the traffic attribute in the observed set of transactions.

18. The non-transitory computer-readable storage medium of claim 16 , wherein detecting that the anomaly exists in the traffic attribute of the observed set of transactions comprises determining a combined risk value for the observed set of transactions, wherein the combined risk value is based on the attribute risk value aggregated with other attribute risk values.

19. The non-transitory computer-readable storage medium of claim 18 , wherein detecting that the anomaly exists in the traffic attribute of the observed set of transactions further comprises:

determining that the combined risk value meets a combined threshold; and

comparing the attribute risk value to a threshold risk attribute, based on the combined risk value meeting the combined threshold.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2023
From: JONES, MATTHEW LEWIS
To: KOUNT INC.
Reel/Frame 064472/0763 →
Continuity (2)
Provisional Application 63059606 · Jul 31, 2020
Related Publication 20220038481A1 · Feb 3, 2022
Cited By (3)
US 12,430,646 US 12,455,978 US 12,737,766