IP Library › Granted Patent US 12,141,284
Granted Patent B2
US 12,141,284 · App. 17/710,935 · Granted Nov 12, 2024

Method for detecting anomalies in an information system, computer program and system for detecting anomalies implementing such a method

Inventors: Mahamadou Salissou Aboubacar Alka (Mantes-la-Jolie, FR); Béranger Guedou (Mantes-la-Jolie, FR)
Assignee: BULL SAS
G06F21/566G06N3/045G06N3/08G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,141,284
App. No.
17/710,935
Granted
Nov 12, 2024
Kind
B2
Abstract

A method, system and computer program, implemented by a computer, for detecting anomalies in an information system (IS) including a detection phase for an entity of the IS and at a time window, called a current unitary window. The detection phase includes generating a digital signature, called a unitary signature, representative of a behavior of the entity during the current unitary window based on data relative to the entity and collected during the current unitary window. The detection phase also includes calculating an anomaly score, associated with the entity for the current unitary window, based on the unitary signature and a digital signature, called a reference. The reference is previously calculated for the entity and is representative of the activity of the entity over a period preceding the current unitary window. Each digital signature is generated using a generator based on previously trained deep learning Siamese neural networks.

Claims (71)

1. A computer implemented method for detecting anomalies in an information system (IS), comprising several computer entities, said computer implemented method comprising:

at least one iteration of a detection phase for at least one entity of said several computer entities of said IS and at least one time window,

wherein said at least one time window comprises a current unitary window,

wherein said detection phase comprises

 collecting data related to an activity of said at least one entity during said current unitary window;

 constructing a data set associated with said current unitary window based on the data collected during a window comprising said current unitary window,

wherein said data set comprises an observation and said window is an observation window,

 generating a unitary digital signature representative of a behavior of said at least one entity during said current unitary window based on said observation; and,

 calculating an anomaly score, associated with said at least one entity for said current unitary window based on

said unitary digital signature, and

a reference digital signature, wherein said reference digital signature is previously calculated for said at least one entity and is representative of the activity of said at least one entity over a period preceding said current unitary window,

wherein said period is a reference period,

wherein said unitary digital signature and said reference digital signature are generated using a generator based on deep learning Siamese neural networks and

wherein, for the unitary digital signature, the anomaly score is calculated using

Z 0 =( d 0 −MEAN)/STD

where

d 0 is a distance between the reference digital signature and the unitary digital signature;

MEAN is an average of distances between the reference digital signature and each unitary digital signature associated with said each unitary window of said reference period, and

STD is a standard deviation of the distances between the reference digital signature and said each unitary digital signature associated with said each unitary window of said reference period.

2. The computer implemented method according to claim 1 , wherein the reference period comprises several unitary windows preceding the current unitary window, and wherein said method further comprises generating the reference digital signature comprising

for said each unitary window of said several unitary windows of the reference period, generating, by the generator, a unitary digital signature based on the observation associated with said each unitary window, and

calculating said reference digital signature based on said unitary digital signature that is generated for each unitary window, by averaging all of said unitary digital signature from said each unitary window of said several unitary windows.

3. The computer implemented method according to claim 1 , wherein the detection phase further comprises updating the reference digital signature with the unitary digital signature associated with the current unitary window for a new iteration of said detection phase for a subsequent unitary window.

4. The computer implemented method according to claim 1 , wherein the observation window is equal to the current unitary window, and wherein the observation associated with the current unitary window is constructed based on said data collected only during the current unitary window.

5. The computer implemented method according to claim 1 , wherein the observation window is a sliding time window comprising the current unitary window and at least one unitary window preceding in time said current unitary window, wherein the observation associated with the current unitary window is constructed based on said data collected during said current unitary window and said at least one unitary window.

6. The computer implemented method according to claim 1 , wherein said collecting data comprises a collection of one or more values for one or more predefined parameters.

7. The computer implemented method according to claim 6 , further comprising aggregating, for at least one parameter of said one or more predefined parameters, several values of said one or more values collected during the current unitary window.

8. The computer implemented method according to claim 1 , further comprising a learning phase of the deep learning Siamese neural networks with a base of learning observations, prior to the detection phase.

9. The computer implemented method according to claim 8 , wherein the deep learning Siamese neural networks are trained using a Contrastive Loss optimization function.

10. The computer implemented method according to claim 8 , wherein the deep learning Siamese neural networks are trained using a Triplet Loss optimization function.

11. A computer program comprising instructions executable by a computer device which, when executed, implement a computer implemented method for detecting anomalies in an information system (IS), comprising several computer entities, said computer implemented method comprising:

at least one iteration of a detection phase for at least one entity of said several computer entities of said IS and at least one time window,

wherein said at least one time window comprises a current unitary window,

wherein said detection phase comprises

 collecting data related to an activity of said at least one entity during said current unitary window;

 constructing a data set associated with said current unitary window based on the data collected during a window comprising said current unitary window,

wherein said data set comprises an observation and said window is an observation window,

 generating a unitary digital signature representative of a behavior of said at least one entity during said current unitary window based on said observation; and,

 calculating an anomaly score, associated with said at least one entity for said current unitary window based on

said unitary digital signature, and

a reference digital signature, wherein said reference digital signature is previously calculated for said at least one entity and is representative of the activity of said at least one entity over a period preceding said current unitary window,

wherein said period is a reference period,

wherein said unitary digital signature and said reference digital signature are generated using a generator based on deep learning Siamese neural networks and

wherein, for the unitary digital signature, the anomaly score is calculated using

Z 0 =( d 0 −MEAN)/STD

where

d 0 is a distance between the reference digital signature and the unitary digital signature;

MEAN is an average of distances between the reference digital signature and each unitary digital signature associated with said each unitary window of said reference period, and

STD is a standard deviation of the distances between the reference digital signature and said each unitary digital signature associated with said each unitary window of said reference period.

12. An anomaly detection system in an information system (IS), then anomaly detection system comprising:

means configured for implementing a method for detecting said anomalies in said information system (IS), said method comprising

at least one iteration of a detection phase for at least one entity of said information system (IS) and for at least one time window,

wherein said at least one time window comprises a current unitary window,

wherein said detection phase comprises

collecting data related to an activity of said at least one entity during said current unitary window;

constructing a data set associated with said current unitary window based on said data collected during a window comprising said current unitary window,

wherein said data set comprises an observation and said window is an observation window,

generating a unitary digital signature representative of a behavior of said at least one entity during said current unitary window based on said observation; and,

calculating an anomaly score, associated with said at least one entity for said current unitary window based on

said unitary digital signature, and

a reference digital signature, wherein said reference digital signature is previously calculated for said at least one entity and is representative of the activity of said at least one entity over a period preceding said current unitary window,

 wherein said period is a reference period,

wherein said unitary digital signature and said reference digital signature are generated using a generator based on deep learning Siamese neural networks and

wherein, for the unitary digital signature, the anomaly score is calculated using

Z 0 =( d 0 −MEAN)/STD

where

d 0 is a distance between the reference digital signature and the unitary digital signature;

MEAN is an average of distances between the reference digital signature and each unitary digital signature associated with said each unitary window of said reference period, and

STD is a standard deviation of the distances between the reference digital signature and said each unitary digital signature associated with said each unitary window of said reference period.

13. The anomaly detection system according to claim 12 , wherein said at least one entity comprises several computer entities.

14. The anomaly detection system according to claim 13 , wherein at least one computer entity of the several computer entities is a physical machine, or a virtual machine, or a physical user account, or a functional user account.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 8, 2022
From: ABOUBACAR ALKA, MAHAMADOU SALISSOU; GUEDOU, BÉRANGER
To: BULL SAS
Reel/Frame 059551/0823 →
Priority Claims (1)
EP 21305423 · Apr 1, 2021 · regional
Continuity (1)
Related Publication 20220318388A1 · Oct 6, 2022