IP Library › Granted Patent US 12,284,193
Granted Patent B2
US 12,284,193 · App. 17/459,298 · Granted Apr 22, 2025

Proactive identification of potential security threats on residential gateway devices

Inventors: Dileep Devaraj (Bangalore, IN); Chetan Kumar Viswanath Gubbi (Bangalore, IN); Nitoo Mishra (Bangalore, IN)
Assignee: ARRIS ENTERPRISES LLC
H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,284,193
App. No.
17/459,298
Filed
Aug 27, 2021
Granted
Apr 22, 2025
Kind
B2
Art Unit
2499
USPC
726/23
Abstract

A system and a method are provided for an external server for use with a first network device and an external network. The external server contains: a memory having a priori data stored therein, the a priori data includes a plurality of potential security attack signatures; and a processor configured to execute instructions stored on the memory to cause the external server to: monitor the first network device for actions on the first network device; identify an action on the first network device that matches one of the plurality of potential security attack signatures of the a priori data; and notify the first network device that the action is a potential security attack.

Claims (49)

1. An external server for use with a first network device and an external network, said external server comprising:

a memory having a priori data stored therein, the a priori data includes a plurality of security attack signatures, each of which includes a respective plurality of data values; and

a processor configured to execute instructions stored on said memory to cause said external server to:

train a supervised machine learning algorithm of a machine learning program stored in the memory based on the a priori data that includes one or more at risk parameters that are indicators of attempted security attacks and one or more benign parameters that are indicators of benign communications;

receive, from the first network device, first data that is an indicator of a benign communication, the indicator not having been previously identified or associated with security attacks;

generate one or more signatures based on the first data indicative of the benign communication;

store the one or more signatures as part of the a priori data stored on the memory;

receive from the first network device unlabeled data that has not been previously identified as one of the plurality of security attack signatures;

process by an unsupervised machine learning process, performed by the processor, the unlabeled data for pattern identification;

monitor the first network device for actions on the first network device by collecting a number of data parameters of the unlabeled data from the first network device;

identify an action of the actions on the first network device when a number m of the number of data parameters matches at least the number m of the plurality of data values of one of the plurality of security attack signatures of the a priori data; and

notify the first network device that the action is a security attack, wherein m is greater than or equal to a predetermined threshold number n;

send a remediation instruction to the first network device based on a type of the security attack to cause the first network device to perform one or more prevention or mitigation actions;

label the unlabeled data based on the pattern identification and additional data received from the unsupervised machine learning process for storage as part of the a priori data stored on the memory so as to train the supervised machine learning algorithm, wherein the additional data is one or more new data patterns that are also one or more signatures of one or more security attacks discovered by performing the unsupervised machine learning process; and

send the labeled data to the supervised machine learning process for additional learning.

2. The external server of claim 1 , wherein said processor is configured to execute instructions stored on said memory to additionally cause said external server to update the a priori data based on the action on the first network device that matches the one of the plurality of security attack signatures of the a priori data.

3. The external server of claim 1 , wherein one of the plurality of security attack signatures is based on an action on a second network device and is associated with a degradation of service provided by the second network device.

4. A method of using an external server with a first network device and an external network, said method comprising:

storing, into a memory, a priori data including a plurality of security attack signatures, each of which includes a respective plurality of data values;

training a supervised machine learning algorithm of a machine learning program stored in the memory based on the a priori data that includes one or more at risk parameters that are indicators of attempted security attacks and one or more benign parameters that are indicators of benign communications;

receiving, from the first network device, first data that is an indicator of a benign communication, the indicator not having been previously identified or associated with security attacks;

generating one or more signatures based on the first data indicative of the benign communication;

storing the one or more signatures as part of the a priori data stored on the memory;

receiving from the first network device unlabeled data that has not been previously identified as one of the plurality of security attack signatures;

processing by an unsupervised machine learning process, performed by the processor, the unlabeled data for pattern identification;

monitoring, via a processor configured to execute instructions stored on the memory, the first network device for actions on the first network device by collecting a number of data parameters of the unlabeled data from the first network device;

identifying, via the processor, an action of the actions on the first network device when a number m of the number of data parameters matches at least the number m of the plurality of data values of one of the plurality of security attack signatures of the a priori data; and

notifying, via the processor, the first network device that the action is a security attack, wherein m is greater than or equal to a predetermined threshold number n; and

sending a remediation instruction to the first network device based on a type of the security attack to cause the first network device to perform one or more prevention or mitigation actions;

labeling the unlabeled data based on the pattern identification and additional data received from the unsupervised machine learning process for storage as part of the a priori data stored on the memory so as to train the supervised machine learning algorithm, wherein the additional data is one or more new data patterns that are also one or more signatures of one or more security attacks discovered by performing the unsupervised machine learning process; and

sending the labeled data to the supervised machine learning process for additional learning.

5. The method of claim 4 , further comprising updating, via the processor, the a priori data based on the action on the first network device that matches the one of the plurality of security attack signatures of the a priori data.

6. The method of claim 4 , wherein one of the plurality of security attack signatures is based on an action on a second network device and is associated with a degradation of service provided by the second network device.

7. A non-transitory, computer-readable media having computer-readable instructions stored thereon, the computer-readable instructions being capable of being read by an external server with a first network device and an external network, wherein the computer-readable instructions are capable of instructing the external server to perform the method comprising:

storing, into a memory, a priori data including a plurality of security attack signatures, each of which includes a respective plurality of data values;

training a supervised machine learning algorithm of a machine learning program stored in the memory based on the a priori data that includes one or more at risk parameters that are indicators of attempted security attacks and one or more benign parameters that are indicators of benign communications;

receiving, from the first network device, first data that is an indicator of a benign communication, the indicator not having been previously identified or associated with security attacks;

generating one or more signatures based on the first data indicative of the benign communication;

storing the one or more signatures as part of the a priori data stored on the memory;

receiving from the first network device unlabeled data that has not been previously identified as one of the plurality of security attack signatures;

processing by an unsupervised machine learning process, performed by the processor, the unlabeled data for pattern identification;

monitoring, via a processor configured to execute instructions stored on the memory, the first network device for actions on the first network device by collecting a number of data parameters of the unlabeled data from the first network device;

identifying, via the processor, an action of the actions on the first network device when a number m of the number of data parameters matches at least the number m of the plurality of data values of one of the plurality of security attack signatures of the a priori data;

notifying, via the processor, the first network device that the action is a security attack, wherein m is greater than or equal to a predetermined threshold number n;

sending a remediation instruction to the first network device based on a type of the security attack to cause the first network device to perform one or more prevention or mitigation actions;

labeling the unlabeled data based on the pattern identification and additional data received from the unsupervised machine learning process for storage as part of the a priori data stored on the memory so as to train the supervised machine learning algorithm, wherein the additional data is one or more new data patterns that are also one or more signatures of one or more security attacks discovered by performing the unsupervised machine learning process; and

sending the labeled data to the supervised machine learning process for additional learning.

8. The non-transitory, computer-readable media of claim 7 , wherein the computer-readable instructions are capable of instructing the external server to perform the method further comprising updating, via the processor, the a priori data based on the action on the first network device that matches the one of the plurality of security attack signatures of the a priori data.

9. The non-transitory, computer-readable media of claim 7 , wherein the computer-readable instructions are capable of instructing the external server to perform the method wherein one of the plurality of security attack signatures is based on an action on a second network device and is associated with a degradation of service provided by the second network device.

Assignments (8)
RELEASE OF SECURITY INTEREST AT REEL/FRAME 059350/0743 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA)
Reel/Frame 074594/0156 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS AT REEL/FRAME NO. 59710/0506 Recorded Jan 9, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA)
Reel/Frame 074282/0522 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 059350/0921 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069743/0704 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
SECURITY INTEREST Recorded Mar 9, 2022
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: WILMINGTON TRUST
Reel/Frame 059710/0506 →
TERM LOAN SECURITY AGREEMENT Recorded Mar 8, 2022
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059350/0921 →
ABL SECURITY AGREEMENT Recorded Mar 8, 2022
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 059350/0743 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2021
From: DEVARAJ, DILEEP; GUBBI, CHETAN KUMAR VISWANATH; MISHRA, NITOO
To: ARRIS ENTERPRISES LLC
Reel/Frame 057312/0006 →
Continuity (2)
Provisional Application 63125644 · Dec 15, 2020
Related Publication 20220191221A1 · Jun 16, 2022
References Cited (22)
US 10778699B1 · Bradley · 2020 [cited by examiner]
US 10880270B1 · Rigor · 2020 [cited by examiner]
US 10893058B1 · Casaburi · 2021 [cited by examiner]
US 11019076B1 · Jakobsson · 2021 [cited by examiner]
US 11528292B1 · Thanos · 2022 [cited by examiner]
US 11886582B1 · Abdallah · 2024 [cited by examiner]
US 20180152471A1 · Jakobsson · 2018 [cited by examiner]
US 20180191773A1 · O'Connell · 2018 [cited by examiner]
US 20190052672A1 · Kumar · 2019 [cited by examiner]
US 20190068616A1 · Woods · 2019 [cited by examiner]
US 20190095618A1 · Lim · 2019 [cited by examiner]
US 20190199745A1 · Jakobsson · 2019 [cited by examiner]
US 20190347413A1 · Dubrovsky · 2019 [cited by examiner]
US 20190394216A1 · Kondamuri · 2019 [cited by examiner]
US 20200076831A1 · Baughman · 2020 [cited by examiner]
US 20200110873A1 · Rosendahl · 2020 [cited by examiner]
US 20200344251A1 · Jeyakumar · 2020 [cited by examiner]
US 20200389486A1 · Jeyakumar · 2020 [cited by examiner]
US 20210194924A1 · Heinemeyer · 2021 [cited by examiner]
US 20210243226A1 · El Gamal · 2021 [cited by examiner]
US 20210250368A1 · Hearty · 2021 [cited by examiner]
US 20220114490A1 · Das · 2022 [cited by examiner]
Cited By (1)
US 12,664,203