IP Library Granted Patent US 12,556,553
Granted Patent B2
US 12,556,553 · App. 17/663,883 · Granted Feb 17, 2026

Network security and related apparatuses, methods, and security systems

Inventors: Matthew W. Anderson (Idaho Falls, ID); Brandon S. Biggs (Idaho Falls, ID); Matthew R. Sgambati (Rigby, ID); Kyle S. Staples (Ammon, ID); Jared C. Wadsworth (Idaho Falls, ID)
Assignee: Battelle Energy Alliance, LLC
H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,553
App. No.
17/663,883
Filed
May 18, 2022
Granted
Feb 17, 2026
Kind
B2
Art Unit
2437
USPC
726/22
Abstract

Network security and related apparatuses, methods, and security systems are disclosed. An apparatus includes a variational autoencoder trained to reconstruct a benign packet flow representation of a benign packet flow corresponding to a benign stream of packets. The processing circuitry is configured to apply a packet flow representation of a packet flow corresponding to a received stream of packets to the variational autoencoder to generate a reconstructed packet flow representation. The packet flow representation includes one or more of a determined transfer entropy corresponding to the received stream of packets, flow derived metadata, or a Granger causality of the packet flow. The processing circuitry is also configured to determine a reconstruction loss of the reconstructed packet flow representation and determine whether the received stream of packets is anomalous responsive to the determined reconstruction loss.

Claims (40)

1 . An apparatus, comprising:

an input terminal configured to receive a stream of packets from a network; and

processing circuitry implementing a variational autoencoder trained to reconstruct a benign packet flow representation of a benign packet flow corresponding to a benign stream of packets, the processing circuitry configured to:

apply a packet flow representation of a packet flow corresponding to the received stream of packets to the variational autoencoder to generate a reconstructed packet flow representation, the packet flow representation comprising one or more of a determined transfer entropy corresponding to the received stream of packets or a Granger causality of the packet flow;

determine a reconstruction loss of the reconstructed packet flow representation based, at least in part, on the determined transfer entropy corresponding to the received stream of packets or the determined Granger causality of the packet flow; and

determine whether the received stream of packets is anomalous responsive to the determined reconstruction loss.

2 . The apparatus of claim 1 , wherein the variational autoencoder includes an input layer, an encoder layer, a latent layer, a decoder layer, and an output layer, the encoder layer configured to compress the packet flow representation into a latent space corresponding to the latent layer, the latent space corresponding to a random multivariable normal distribution, the decoder layer configured to generate the reconstructed packet flow representation responsive to information sampled from the latent space.

3 . The apparatus of claim 1 , wherein the processing circuitry is further configured to deliver the received stream of packets to a destination device responsive to a determination that the received stream of packets is not anomalous.

4 . The apparatus of claim 1 , wherein the processing circuitry is further configured to block the received stream of packets from a destination device for the received stream of packets responsive to a determination that the received stream of packets is anomalous.

5 . The apparatus of claim 1 , wherein the processing circuitry is configured to determine the packet flow representation responsive to the stream of packets itself.

6 . The apparatus of claim 1 , wherein the processing circuitry is configured to determine the packet flow representation responsive to summarized data indicating the packet flow.

7 . A method of operating a security system, the method comprising:

training a variational autoencoder to reconstruct a benign packet flow representation of a benign packet flow corresponding to a benign stream of packets;

determining a packet flow representation of a packet flow corresponding to a received stream of packets, the packet flow representation comprising one or more of a determined transfer entropy corresponding to the received stream of packets or a Granger causality of the packet flow;

applying the packet flow representation to the trained variational autoencoder to generate a reconstructed packet flow representation;

determining a reconstruction loss of the reconstructed packet flow representation based, at least in part, on the determined transfer entropy corresponding to the received stream of packets or the determined Granger causality of the packet flow; and

determining whether the received stream of packets is anomalous responsive to the reconstructed loss.

8 . The method of claim 7 , further comprising blocking the received stream of packets from delivery to a destination device responsive to a determination that the received stream of packets is anomalous.

9 . The method of claim 7 , further comprising delivering the received stream of packets to a destination device responsive to a determination that the received stream of packets is not anomalous.

10 . The method of claim 7 , wherein training the variational autoencoder comprises determining the benign packet flow representation of the benign packet flow responsive to the benign stream of packets itself.

11 . The method of claim 7 , wherein training the variational autoencoder comprises determining the benign packet flow representation responsive to summarized data indicating the benign packet flow.

12 . The method of claim 7 , wherein determining the packet flow representation comprises determining the packet flow representation of the packet flow responsive to the received stream of packets itself.

13 . The method of claim 7 , wherein determining the packet flow representation comprises determining the packet flow representation responsive to summarized data indicating the packet flow.

14 . The method of claim 7 , wherein training the variational autoencoder includes:

feeding the benign packet flow representation to the variational autoencoder;

building a directed acyclic graph hierarchy;

encoding the benign packet flow representation, by a separate encoder layer, responsive to latent dimension selection;

creating a latent distribution, using a random multivariable normal distribution, based on user-specified latent dimensions; and

decoding information sampled from the latent distribution to generate new examples from the latent distribution.

15 . A security system, comprising:

a destination device;

a network interface configured to receive a stream of packets from a network; and

processing circuitry configured to:

determine whether the received stream of packets is anomalous using a variational autoencoder trained to reconstruct a benign transfer entropy of a benign packet flow corresponding to a benign stream of packets; and

deliver the received stream of packets to the destination device responsive to a determination that the received stream of packets is not anomalous, the determination based, at least in part, on the benign transfer entropy of a benign packet flow corresponding to a benign stream of packets.

16 . The security system of claim 15 , wherein the processing circuitry is further configured to block the received stream of packets from delivery to the destination device responsive to a determination that the received stream of packets is anomalous.

17 . The security system of claim 15 , wherein the processing circuitry is further configured to determine a transfer entropy of a packet flow corresponding to the received stream of packets.

18 . The security system of claim 17 , wherein the processing circuitry is configured to determine the transfer entropy responsive to the received stream of packets itself.

19 . The security system of claim 17 , wherein the processing circuitry is configured to determine the transfer entropy responsive to summarization information indicating the packet flow.

20 . The security system of claim 17 , wherein the processing circuitry is configured to determine whether the received stream of packets is anomalous by applying the determined transfer entropy to the variational autoencoder and determining a reconstruction loss of the reconstructed transfer entropy relative to the determined transfer entropy.

Assignments (2)
CONFIRMATORY LICENSE Recorded Sep 21, 2022
From: BATTELLE ENERGY ALLIANCE/IDAHO NAT'L LAB
To: UNITED STATES DEPARTMENT OF ENERGY
Reel/Frame 061165/0993 →
NUNC PRO TUNC ASSIGNMENT Recorded Jun 6, 2022
From: ANDERSON, MATTHEW W.; BIGGS, BRANDON S.; SGAMBATI, MATTHEW R.; STAPLES, KYLE S.; WADSWORTH, JARED C.
To: BATTELLE ENERGY ALLIANCE, LLC
Reel/Frame 060114/0239 →
Continuity (1)
Related Publication 20230379345A1 · Nov 23, 2023
References Cited (46)
US 9032525B2 · Sallam · 2015 [cited by applicant]
US 9721099B2 · Sinclair et al. · 2017 [cited by applicant]
US 10021128B2 · McDougal · 2018 [cited by applicant]
US 10505956B1 · Pidathala et al. · 2019 [cited by applicant]
US 10523609B1 · Subramanian · 2019 [cited by applicant]
US 10581898B1 · Singh · 2020 [cited by applicant]
US 10609050B2 · Caspi et al. · 2020 [cited by applicant]
US 10685293B1 · Heimann et al. · 2020 [cited by applicant]
US 10848519B2 · Howard et al. · 2020 [cited by applicant]
US 10880328B2 · Farhady et al. · 2020 [cited by applicant]
US 11227162B1 · Lu · 2022 [cited by examiner]
US 11537902B1 · Aydore · 2022 [cited by examiner]
US 11556644B1 · Zeppenfeld et al. · 2023 [cited by applicant]
US 11657269B2 · Che · 2023 [cited by examiner]
US 20070112824A1 · Lock et al. · 2007 [cited by applicant]
US 20140095425A1 · Sipple · 2014 [cited by examiner]
US 20180103302A1 · Bell · 2018 [cited by examiner]
US 20190044964A1 · Chari et al. · 2019 [cited by applicant]
US 20190132334A1 · Johns et al. · 2019 [cited by applicant]
US 20190166144A1 · Mirsky et al. · 2019 [cited by applicant]
US 20190228312A1 · Andoni · 2019 [cited by examiner]
US 20190272375A1 · Chen · 2019 [cited by applicant]
US 20190294729A1 · Jiang et al. · 2019 [cited by applicant]
US 20200076840A1 · Peinador et al. · 2020 [cited by applicant]
US 20200076841A1 · Hajimirsadeghi et al. · 2020 [cited by applicant]
US 20200076842A1 · Zhou et al. · 2020 [cited by applicant]
US 20200092311A1 · Avrahami et al. · 2020 [cited by applicant]
US 20200104498A1 · Smith et al. · 2020 [cited by applicant]
US 20200134423A1 · Shinde et al. · 2020 [cited by applicant]
US 20200175161A1 · Giaconi · 2020 [cited by applicant]
US 20200218806A1 · Cho · 2020 [cited by applicant]
US 20200257985A1 · West · 2020 [cited by examiner]
US 20200274787A1 · Dasgupta et al. · 2020 [cited by applicant]
US 20200280573A1 · Johnson et al. · 2020 [cited by applicant]
US 20200364338A1 · Ducau et al. · 2020 [cited by applicant]
US 20210048993A1 · Burke · 2021 [cited by applicant]
US 20210099474A1 · Huang · 2021 [cited by examiner]
US 20220070195A1 · Sern · 2022 [cited by examiner]
US 20220172050A1 · Dalli · 2022 [cited by examiner]
US 20220358214A1 · Anderson et al. · 2022 [cited by applicant]
US 20230027149A1 · Kuan · 2023 [cited by examiner]
US 20230224277A1 · Tarighat · 2023 [cited by examiner]
US 20240086527A1 · Rosen et al. · 2024 [cited by applicant]
WO 2020159439A1 · 2020 [cited by applicant]
An, J., et al., “Variational Autoencoder Based Anomaly Detection Using Reconstruction Probability,” Special Lecture on IE, Dec. 27, 2015, pp. 18. [cited by applicant]
Artuso, F., et al., “In Nomine Function: Naming Functions in Stripped Binaries with Neural Networks,” Machine Learning, Feb. 4, 2021, pp. 15. [cited by applicant]