IP Library Granted Patent US 12,341,792
Granted Patent B2
US 12,341,792 · App. 17/947,684 · Granted Jun 24, 2025

Statistical analysis of network behavior using event vectors to identify behavioral anomalies using a composite score

Inventors: William Wright (Los Gatos, CA); George D. Kellerman (Louisville, KY)
Assignee: OPEN TEXT INC.
H04L63/1425G06F21/552G06N7/01H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,341,792
App. No.
17/947,684
Granted
Jun 24, 2025
Kind
B2
Abstract

Examples of the present disclosure describe systems and methods for identifying anomalous network behavior. In aspects, a network event may be observed network sensors. One or more characteristics may be extracted from the network event and used to construct an evidence vector. The evidence vector may be compared to a mapping of previously-identified events and/or event characteristics. The mapping may be represented as one or more clusters of expected behaviors and anomalous behaviors. The mapping may be modeled using analytic models for direction detection and magnitude detection. One or more centroids may be identified for each of the clusters. A “best fit” may be determined and scored for each of the analytic models. The scores may be fused into single binocular score and used to determine whether the evidence vector is likely to represent an anomaly.

Claims (29)

1. A system for identifying anomalous network behavior, comprising:

at least a first processor; and

memory coupled to the at least one processor, the memory comprising computer executable instructions that, when executed by the at least one processor, perform:

receiving sensor data for an event representative of a network flow;

extracting characteristics of the sensor data and normalizing the sensor data to generate an evidence vector for the event;

determining a candidate network anomaly by applying the evidence vector to a data analytics model, wherein the determining comprises:

applying the evidence vector to a directional cluster mapping to determine a directional cluster mapping result;

applying the evidence vector to a magnitude cluster mapping to determine a magnitude cluster mapping result; and

combining the directional cluster mapping result and the magnitude cluster mapping result to determine a composite score for the evidence vector, wherein the composite score indicates the probability of the evidence vector representing an anomaly with respect to the event.

2. The system of claim 1 , wherein the sensor data is stored in a sensor data store and the sensor data is aggregated over a time period for the network flow.

3. The system of claim 1 , wherein one or more of the extracted characteristics are predictive of whether the event is the anomaly.

4. The system of claim 1 , wherein comparing the evidence vector to the one or more prototype vectors further comprises comparing the evidence vector to one or more directional clusters to determine a degree of directional anomaly.

5. The system of claim 1 , wherein comparing the evidence vector to the one or more prototype vectors further comprises comparing the evidence vector to one or more magnitude clusters to determine a degree of magnitude anomaly.

6. The system of claim 1 , further comprising executing machine learning to classify the event and determine a network countermeasure for the event.

7. The system of claim 1 , further comprising training a model for determining expected network anomalies and emergent network behaviors.

8. The system of claim 1 , further comprising categorizing a behavior of the network anomaly using binocular fusion.

9. A method for identifying anomalous network behavior, comprising:

receiving sensor data for an event representative of a network flow;

extracting characteristics of the sensor data and normalizing the sensor data to generate an evidence vector for the event;

determining a candidate network anomaly by applying the evidence vector to a data analytics model, wherein the determining comprises:

applying the evidence vector to a directional cluster mapping to determine a directional cluster mapping result;

applying the evidence vector to a magnitude cluster mapping to determine a magnitude cluster mapping result; and

combining the directional cluster mapping result and the magnitude cluster mapping result to determine a composite score for the evidence vector, wherein the composite score indicates the probability of the evidence vector representing an anomaly with respect to the event.

10. The method of claim 9 , wherein the sensor data is stored in a sensor data store and the sensor data is aggregated over a time period for the network flow.

11. The method of claim 9 , wherein one or more of the extracted characteristics are predictive of whether the event is the anomaly.

12. The method of claim 9 , wherein comparing the evidence vector to the one or more prototype vectors further comprises comparing the evidence vector to one or more directional clusters to determine a degree of directional anomaly.

13. The method of claim 9 , further comprising executing machine learning to classify the event and determine a network countermeasure for the event.

14. The method of claim 9 , further comprising training a model for determining expected network anomalies and emergent network behaviors.

15. The method of claim 9 , further comprising categorizing a behavior of the network anomaly using binocular fusion.

Assignments (4)
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jul 6, 2023
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 064351/0178 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2023
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 064167/0129 →
CERTIFICATE OF CONVERSION Recorded Jun 29, 2023
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 064176/0622 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2022
From: WRIGHT, WILLIAM; KELLERMAN, GEORGE D.
To: WEBROOT INC.
Reel/Frame 061249/0766 →
Continuity (5)
Continuation 17221475 · Apr 2, 2021
Continuation 16791658 · Feb 14, 2020
Continuation 15355561 · Nov 18, 2016
Provisional Application 62258380 · Nov 20, 2015
Related Publication 20230070519A1 · Mar 9, 2023
References Cited (6)
US 8402540B2 · Kapoor · 2013 [cited by examiner]
US 9324022B2 · Williams, Jr. · 2016 [cited by examiner]
US 9679243B2 · Zou · 2017 [cited by examiner]
US 10063575B2 · Vasseur · 2018 [cited by examiner]
US 20130218816A1 · Yu · 2013 [cited by examiner]
US 20160359740A1 · Parandehgheibi · 2016 [cited by examiner]