IP Library Granted Patent US 12,493,750
Granted Patent B2
US 12,493,750 · App. 18/025,916 · Granted Dec 9, 2025

Detecting apparatus, training apparatus, detecting method, training method, detecting program, and training program

Inventor: Yuki Yamanaka (Musashino, JP)
Assignee: NTT, Inc.
G06F40/40G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,493,750
App. No.
18/025,916
Granted
Dec 9, 2025
Kind
B2
Abstract

A detection device includes: an encoding unit that converts one packet to be detected into one fixed-length vector by using natural language processing technology; and a detection unit that detects presence or absence of an abnormality in the packet to be detected based on the fixed-length vector converted by the encoding unit using a detection model.

Claims (22)

1 . A detection device, comprising:

a memory; and

a processor coupled to the memory and programmed to execute perform a process comprising:

applying a pretrained language model to a packet to be detected to produce a fixed-length vector that represents features of an internal byte sequence in the packet to be detected; and

detecting presence or absence of an abnormality in the packet to be detected by applying a pretrained detection model to the fixed-length vector, wherein:

the pretrained detection model is one of a variational auto encoder (VAE), an auto encoder (AE), and a local outlier factor (LoF);

training data for the pretrained detection model is a set of normal fixed-length vectors; and

the normal fixed-length vectors are produced by applying the pretrained language model to normal packets.

2 . The detection device of claim 1 , wherein the detecting presence or absence of an abnormality in the packet to be detected includes detecting the abnormality of the packet to be detected when a pattern of the fixed-length vector is different from patterns of the normal fixed-length vectors.

3 . The detection device of claim 1 , wherein the detecting presence or absence of an abnormality in the packet to be detected includes (i) obtaining an abnormality degree with respect to the fixed-length vector and (ii) detecting an abnormality of the packet to be detected when the abnormality degree exceeds a predetermined threshold value.

4 . A detection method executed by a detection device, the detection method comprising:

applying a pretrained language model to a packet to be detected to produce a fixed-length vector that represents features of an internal byte sequence in the packet to be detected; and

detecting presence or absence of an abnormality in the packet to be detected based by applying a pretrained detection model to the fixed-length vector, wherein:

the pretrained detection model is one of a variational auto encoder (VAE), an auto encoder (AE), and a local outlier factor (LoF);

training data for the pretrained detection model is a set of normal fixed-length vectors; and

the normal fixed-length vectors are produced by applying the pretrained language model to normal packets.

5 . A computer-readable recording medium storing computer executable instructions which, when executed by a processor, cause the processor to perform a process comprising:

applying a pretrained language model to a packet to be detected to produce a fixed-length vector that represents features of an internal byte sequence in the packet to be detected; and

detecting presence or absence of an abnormality in the packet to be detected based by applying a pretrained detection model to the fixed-length vector, wherein:

the pretrained detection model is one of a variational auto encoder (VAE), an auto encoder (AE), and a local outlier factor (LoF);

training data for the pretrained detection model is a set of normal fixed-length vectors; and

the normal fixed-length vectors are produced by applying the pretrained language model to normal packets.

Assignments (2)
CHANGE OF NAME Recorded Aug 20, 2025
From: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
To: NTT, INC.
Reel/Frame 072556/0180 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 13, 2023
From: YAMANAKA, YUKI
To: NIPPON TELEGRAPH AND TELEPHONE CORPORATION
Reel/Frame 062959/0342 →
Continuity (1)
Related Publication 20230334262A1 · Oct 19, 2023
References Cited (17)
US 20190362057A1 · Keret · 2019 [cited by examiner]
US 20200204590A1 · Whitham · 2020 [cited by examiner]
US 20200285737A1 · Kraus · 2020 [cited by examiner]
US 20210271755A1 · Yamanaka · 2021 [cited by applicant]
CN 111144470A · 2020 [cited by applicant]
WO 2019245006A1 · 2019 [cited by applicant]
Eric L. Goodman, et al., “Packet2Vec: Utilizing Word2Vec for Feature Extraction in Packet Data”, arxiv.org, Cornell University Library, Apr. 29, 2020, XP081655129, 16 pages. [cited by applicant]
Xiaoyan Zhuo, et al., “Network Intrusion Detection using Word Embeddings”, 2017 IEEE International Conference on Big Data (BIGDATA), Dec. 11, 2017 (Retrieved on Jan. 12, 2018), XP033298828, 10 pages. [cited by applicant]
Mamoru Mimura, et al., “Reading Network Packets as a Natural Language for Intrusion Detection”, National Defense Academy, Mar. 21, 2018, XP047466168, 12 pages. [cited by applicant]
“Download Wireshark”, Available Online at: https://www.wireshark.org/download.html, Retrieved on Aug. 3, 2020, 4 pages. [cited by applicant]
“Zeek”, Available Online at: URL:http://www.3gpp.org/ftp//Specs/archive/29_series/29.165/29165-f60.zip, Retrieved on Aug. 3, 2020, 11 pages. [cited by applicant]
Mikolov et al., “Efficient Estimation of Word Representations in Vector Space”, Computer Science, Computation and Language, arXiv:1301.3781, Available Online at: https://arxiv.org/abs/1301.3781, Retrieved on Sep. 8, 202… [cited by applicant]
Le et al., “Distributed Representations of Sentences and Documents”, Computer Science, Computation and Language, arXiv:1405.4053, Available Online at: https://arxiv.org/abs/1405.4053, Retrieved on Sep. 8, 2020, 2 pages. [cited by applicant]
Peters et al., “Deep contextualized word representations”, Computer Science, Computation and Language, arXiv:1802.05365, Available Online at: https://arxiv.org/abs/1802.05365, Retrieved on Sep. 8, 2020, 2 pages. [cited by applicant]
Furata et al., “Proposal of the System to Select Targets to Preserve Using Machine Learning”. 2018 Symposium on Cryptography and Information Security Proposed Method, Jan. 23-26, 2018, 9 pages. [cited by applicant]
International Search Report and Written Opinion mailed on Feb. 2, 2021, received for PCT Application PCT/JP2020/035631, filed on Sep. 18, 2020, 8 pages including English Translation. [cited by applicant]
Shuyuan Zhao, et al., “Towards Unknown Traffic Identification via Embeddings and Deep Autoencoders”, 2019 26th International Conference on Telecommunications (ICT), IEEE, Apr. 8, 2019, 5 pages, XP033596512. [cited by applicant]