IP Library Granted Patent US 12,438,891
Granted Patent B1
US 12,438,891 · App. 17/676,022 · Granted Oct 7, 2025

Anomaly detection based on ensemble machine learning model

Inventors: Sudhakar Muddu (Cupertino, CA); Christos Tryfonas (San Francisco, CA); Joseph Auguste Zadeh (Sunnyvale, CA); Alexander Beebe Bond (Union City, CA); Ashwin Athalye (San Jose, CA)
H04L63/1416G06F3/0482G06F3/0484G06F3/04842G06F3/04847G06F16/24578G06F16/254G06F16/285G06F16/444G06F16/9024G06F40/134G06N5/022G06N5/04G06N7/01G06N20/00G06N20/20G06V10/225H04L41/0893H04L41/145H04L41/22H04L43/00H04L43/045H04L43/062H04L43/20H04L63/06H04L63/1408H04L63/1425H04L63/1433H04L63/1441H04L63/20H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,891
App. No.
17/676,022
Granted
Oct 7, 2025
Kind
B1
Abstract

A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.

Claims (58)

1. A method comprising:

receiving, by a computer system, event data associated with an entity on a computer network;

analyzing, by the computer system, the event data;

generating, by the computer system, a plurality of feature scores for the entity based on a result of analyzing the event data;

creating, by the computer system, an entity profile uniquely associated with the entity, the entity profile including the plurality of feature scores for the entity;

accessing the entity profile to read the plurality of features scores for the entity;

processing the plurality of feature scores for the entity, accessed from the entity profile, by using a plurality of machine-learning models;

generating a plurality of intermediate anomaly scores for the entity, each based on processing of a respective one of the plurality of feature scores of the entity using a respective one of the plurality of machine-learning models;

processing the plurality of intermediate anomaly scores for the entity according to an ensemble learning model;

generating an anomaly score for the entity based on processing the plurality of intermediate anomaly scores for the entity according to the ensemble learning model; and

detecting an anomaly associated with the entity in response to determining that the anomaly score for the entity satisfies a specified criterion.

2. The method of claim 1 , wherein the detected anomaly is indicative of a malware communication.

3. The method of claim 1 , wherein each of the plurality of feature scores is representative of a quantified evaluation of risk associated with the entity.

4. The method of claim 1 , wherein detecting the anomaly includes assigning the anomaly score based on a weighted combination of the plurality of feature scores.

5. The method of claim 1 , wherein generating a feature score of the plurality of feature scores includes:

processing the event data using a machine learning model, the machine learning model including:

model processing logic defining a process for assigning the feature score based on the event data; and

a model state defining a set of parameters for applying the model processing logic;

wherein the anomaly is detected in response to determining that the anomaly score satisfies the specified criterion.

6. The method of claim 1 , wherein detecting the anomaly includes:

determining a volume of event data associated with a communication between the entity and another entity;

using the ensemble-learning model if the volume of event data is determined to be at or above a threshold volume.

7. The method of claim 1 , wherein the event data is associated with a communication between an internal entity within a computer network and an external entity outside the computer network.

8. The method of claim 1 , wherein the event data includes an identifier associated with the entity, and wherein at least one feature score of the plurality of feature scores is indicative of a level of confidence that the identifier is machine generated.

9. The method of claim 1 , further comprising:

annotating, by the computer system, the detected anomaly with data from an external data source external to the computer network.

10. The method of claim 1 , further comprising:

outputting, by the computer system, via a user interface, an indication of the detected anomaly to a user.

11. The method of claim 1 , wherein the event data is timestamped machine data.

12. The method of claim 1 , wherein the event data include one or more of: domain name system (DNS) generated log data, firewall generated log data, or proxy generated log data.

13. The method of claim 1 , wherein detecting the anomaly includes processing the entity profile using an anomaly model.

14. A system comprising:

a processor; and

a memory having instructions stored therein, execution of which by the processor causes the system to:

receive event data associated with an entity on a computer network;

analyze the event data;

generate a plurality of feature scores for the entity based on a result of analyzing the event data;

creating, by the computer system, an entity profile uniquely associated with the entity, the entity profile including the plurality of feature scores for the entity;

accessing the entity profile to read the plurality of features scores for the entity;

processing the plurality of feature scores for the entity, accessed from the entity profile, by using a plurality of machine-learning models;

generating a plurality of intermediate anomaly scores for the entity, each based on processing of a respective one of the plurality of feature scores for the entity using a respective one of the plurality of machine-learning models;

processing the plurality of intermediate anomaly scores for the entity according to an ensemble-learning model;

generating an anomaly score for the entity based on processing the plurality of intermediate anomaly scores for the entity according to the ensemble-learning model; and

detecting an anomaly associated with the entity in response to determining that the anomaly score for the entity satisfies a specified criterion.

15. The system of claim 14 , wherein the detected anomaly is indicative of a malware communication.

16. The system of claim 14 , wherein each of the plurality of feature scores is representative of a quantified evaluation of risk associated with the particular entity.

17. A non-transitory machine-readable storage medium containing instructions, execution of which by a computer system causes the computer system to perform operations comprising:

receiving event data associated with an entity on a computer network;

analyzing the event data;

generating a plurality of feature scores for the entity based on a result of analyzing the event data;

creating, by the computer system, an entity profile uniquely associated with the entity, the entity profile including the plurality of feature scores for the entity;

accessing the entity profile to read the plurality of features scores for the entity;

processing the plurality of feature scores for the entity, accessed from the entity profile, by using a plurality of machine-learning models;

generating a plurality of intermediate anomaly scores for the entity, each based on processing of a respective one of the plurality of feature scores for the entity using a respective one of the plurality of machine-learning models;

processing the plurality of intermediate anomaly scores for the entity according to an ensemble-learning model;

generating an anomaly score for the entity based on processing the plurality of intermediate anomaly scores for the entity according to the ensemble-learning model; and

detecting an anomaly associated with the entity in response to determining that the anomaly score for the entity satisfies a specified criterion.

18. The non-transitory machine-readable storage medium of claim 17 , such that detecting the anomaly includes assigning the anomaly score based on a weighted combination of the plurality of feature scores.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069826/0065 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2022
From: MUDDU, SUDHAKAR; TRYFONAS, CHRISTOS; ZADEH, JOSEPH AUGUSTE; BOND, ALEXANDER BEEBE; ATHALYE, ASHWIN
To: SPLUNK INC.
Reel/Frame 059132/0859 →
Continuity (3)
Continuation 16503181 · Jul 3, 2019
Continuation 14929183 · Oct 30, 2015
Provisional Application 62212541 · Aug 31, 2015
References Cited (108)
US 7555523B1 · Hartmann · 2009 [cited by applicant]
US 8555388B1 · Wang et al. · 2013 [cited by applicant]
US 9015843B2 · Griffin et al. · 2015 [cited by applicant]
US 9027127B1 · Soldo et al. · 2015 [cited by applicant]
US 9055012B2 · Ehrlich et al. · 2015 [cited by applicant]
US 9166999B1 · Kulkarni et al. · 2015 [cited by applicant]
US 9202052B1 · Fang et al. · 2015 [cited by applicant]
US 9231962B1 · Yen et al. · 2016 [cited by applicant]
US 9356950B2 · Mssamsetty et al. · 2016 [cited by applicant]
US 9407652B1 · Kesin et al. · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9558346B1 · Kolman et al. · 2017 [cited by applicant]
US 9729549B2 · Davis et al. · 2017 [cited by applicant]
US 9860257B1 · Kumar et al. · 2018 [cited by applicant]
US 10009358B1 · Xie et al. · 2018 [cited by applicant]
US 10015182B1 · Shintre et al. · 2018 [cited by applicant]
US 10069849B2 · Muddu et al. · 2018 [cited by applicant]
US 10389738B2 · Muddu · 2019 [cited by examiner]
US 10771345B1 · Louca et al. · 2020 [cited by applicant]
US 20050278703A1 · Lo et al. · 2005 [cited by applicant]
US 20060288415A1 · Wong · 2006 [cited by applicant]
US 20100241828A1 · Yu et al. · 2010 [cited by applicant]
US 20110055921A1 · Narayanaswamy et al. · 2011 [cited by applicant]
US 20110202391A1 · Fogel et al. · 2011 [cited by applicant]
US 20120180126A1 · Liu et al. · 2012 [cited by applicant]
US 20120254398A1 · Thomas et al. · 2012 [cited by applicant]
US 20130133052A1 · Davis et al. · 2013 [cited by applicant]
US 20130152057A1 · Ke et al. · 2013 [cited by applicant]
US 20130191887A1 · Davis et al. · 2013 [cited by applicant]
US 20130318236A1 · Coates et al. · 2013 [cited by applicant]
US 20130318604A1 · Coates et al. · 2013 [cited by applicant]
US 20140074817A1 · Neels et al. · 2014 [cited by applicant]
US 20140101763A1 · Harlacher · 2014 [cited by examiner]
US 20140122501A1 · Shen · 2014 [cited by examiner]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140222997A1 · Mermoud et al. · 2014 [cited by applicant]
US 20140282871A1 · Rowland et al. · 2014 [cited by applicant]
US 20150040231A1 · Oliphant et al. · 2015 [cited by applicant]
US 20150047026A1 · Neil et al. · 2015 [cited by applicant]
US 20150121518A1 · Shmueli et al. · 2015 [cited by applicant]
US 20150205954A1 · Jou et al. · 2015 [cited by applicant]
US 20150229662A1 · Hitt et al. · 2015 [cited by applicant]
US 20150235154A1 · Utschig · 2015 [cited by applicant]
US 20150244732A1 · Golshan et al. · 2015 [cited by applicant]
US 20150256413A1 · Du et al. · 2015 [cited by applicant]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150355957A1 · Steiner et al. · 2015 [cited by applicant]
US 20150373039A1 · Wang · 2015 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20150379083A1 · Lang et al. · 2015 [cited by applicant]
US 20150379425A1 · Dirac et al. · 2015 [cited by applicant]
US 20150379428A1 · Dirac et al. · 2015 [cited by applicant]
US 20160034529A1 · Nguyen et al. · 2016 [cited by applicant]
US 20160057159A1 · Yin et al. · 2016 [cited by applicant]
US 20160078361A1 · Brueckner et al. · 2016 [cited by applicant]
US 20160132787A1 · Drevo et al. · 2016 [cited by applicant]
US 20160147583A1 · Ben Simhon et al. · 2016 [cited by applicant]
US 20160191559A1 · Mhatre et al. · 2016 [cited by applicant]
US 20160219066A1 · Vasseur et al. · 2016 [cited by applicant]
US 20160253232A1 · Puri et al. · 2016 [cited by applicant]
US 20160269424A1 · Chandola et al. · 2016 [cited by applicant]
US 20160300142A1 · Feller et al. · 2016 [cited by applicant]
US 20160321265A1 · Cevahir · 2016 [cited by applicant]
US 20160330226A1 · Chen et al. · 2016 [cited by applicant]
US 20160358099A1 · Sturlaugson et al. · 2016 [cited by applicant]
US 20160358103A1 · Bowers et al. · 2016 [cited by applicant]
US 20160359872A1 · Yadav et al. · 2016 [cited by applicant]
US 20170048270A1 · Boyadjiev et al. · 2017 [cited by applicant]
US 20170063886A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063887A1 · Iliofotou et al. · 2017 [cited by applicant]
US 20170063888A1 · Zadeh et al. · 2017 [cited by applicant]
US 20170063889A1 · Iliofotou et al. · 2017 [cited by applicant]
US 20170063890A1 · Tryfonas et al. · 2017 [cited by applicant]
US 20170063894A1 · Tryfonas et al. · 2017 [cited by applicant]
US 20170063909A1 · Tryfonas et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170126712A1 · Crabtree et al. · 2017 [cited by applicant]
US 20170134415A1 · Tryfonas et al. · 2017 [cited by applicant]
US 20170192782A1 · Valentine et al. · 2017 [cited by applicant]
US 20170192872A1 · Awad et al. · 2017 [cited by applicant]
US 20170279844A1 · Bower et al. · 2017 [cited by applicant]
US 20170288979A1 · Yoshihira et al. · 2017 [cited by applicant]
US 20170295193A1 · Yang et al. · 2017 [cited by applicant]
US 20170324759A1 · Puri et al. · 2017 [cited by applicant]
US 20170353480A1 · Gao et al. · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180054452A1 · Muddu et al. · 2018 [cited by applicant]
US 20180198805A1 · Vejman et al. · 2018 [cited by applicant]
US 20180219888A1 · Apostolopoulos · 2018 [cited by applicant]
US 20180219894A1 · Crabtree et al. · 2018 [cited by applicant]
US 20180288079A1 · Muddu et al. · 2018 [cited by applicant]
US 20180302423A1 · Muddu et al. · 2018 [cited by applicant]
US 20180351981A1 · Muddu et al. · 2018 [cited by applicant]
US 20180367551A1 · Muddu et al. · 2018 [cited by applicant]
US 20190124104A1 · Apostolopoulos · 2019 [cited by applicant]
US 20190327251A1 · Muddu et al. · 2019 [cited by applicant]
US 20200021607A1 · Muddu et al. · 2020 [cited by applicant]
US 20200228558A1 · Apostolopoulos · 2020 [cited by applicant]
US 20230053182A1 · Bertiger et al. · 2023 [cited by applicant]
US 20230308464A1 · Dong et al. · 2023 [cited by applicant]
WO 2016163903A1 · 2016 [cited by applicant]
“Palantir Cyber Intelligence: An End-to-End Analysis and Knowledge Management Platform”, http://web.archive.org/web/20140821212114/http://www.palantir.com/wp-assets/wp-content/uploads/2014/03/Solution-Overview_palantier… [cited by applicant]
“Palantir Cybermesh”, retrieved online via url: http://web.archive.org/web/20140821212016/http://www.palantir.com/wp-assets/media/capabilites-perspectives/Palantir-Cybermesh.pdf, Aug. 21, 2014, 5 pages. [cited by applicant]
“Palantir Technologies, Product Brochure for “Palantir Cyber,” 9 pages, 2013”. [cited by applicant]
Boora, N.K. , et al., “Efficient Algorithms for Intrusion Detection”, In: Ghosh R.K., Mohanty H. (eds) Distributed computing and Internet Technology; ICDCIT 2004; Lecture Notes in Computer Science, vol. 3347; Springer, … [cited by applicant]
Ranshous, Stephen , et al., “Anomaly detection in dynamic networks: a survey”, WIREs Computational Statistics; vol. 7, May/Jun. 2015, pp. 223-247. [cited by applicant]
Non Final Office Action for U.S. Appl. No. 17/745,482 issued Jul. 19, 2024. [cited by applicant]
Cited By (1)
US 1,142,410