IP Library Granted Patent US 12,225,024
Granted Patent B2
US 12,225,024 · App. 18/352,490 · Granted Feb 11, 2025

Methods and apparatus for monitoring network events for intrusion detection

Inventors: Geoffrey Ryan Salmon (East York, CA); Hazem Mohamed Ahmed Soliman (Toronto, CA); Mohan Rao (Mississaugua, CA)
Assignee: Arctic Wolf Networks, Inc.
H04L63/1416H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,225,024
App. No.
18/352,490
Granted
Feb 11, 2025
Kind
B2
Abstract

A first dataset that includes an indication of a plurality of network events associated with a time-period is received. For each time sub-period from a plurality of time sub-periods that together span the time-period and to generate a second dataset, a value for each network event from the plurality of network events that occur within that time sub-period is summed. A discrete Fourier transform is performed based on the second dataset to generate a third dataset that includes an indication of a plurality of frequency ranges and a plurality of magnitude values for the plurality of frequency ranges. Each frequency from the plurality of frequencies ranges is associated with a magnitude value from the plurality of magnitude values. A set of candidate frequencies from the plurality of frequencies determined to potentially cause periodic behavior is identified based on the plurality of frequency ranges and the plurality of magnitude values.

Claims (72)

1. A method, comprising:

converting, via a processor, a plurality of sets of events associated with a first device into a time series, each set of events from the plurality of sets of events associated with the first device and a second device from a plurality of second devices that is different for remaining sets of events from the plurality of sets of events and does not include the first device;

performing, via the processor, a discrete Fourier transform based on the time series to generate an output, wherein performing the discrete Fourier transform includes:

normalizing the time series to generate a normalized time series;

calculating, using the normalized time series, a linear regression fit that includes indication of a slope and an intercept;

subtracting the slope and the intercept from the normalized time series to generate a modified normalized time series;

applying a hamming window to the normalized time series to generate an input; and

generating the output based on inputting the input to the discrete Fourier transform;

identifying, via the processor and based on the output, an attribute associated with an event from a set of events from the plurality of sets of events that is predicted to cause a periodic behavior; and

sending, via the processor, a signal to cause an output including representation of the attribute.

2. The method of claim 1 , wherein the output is associated with a plurality of frequencies, the method further comprising:

selecting a set of candidate frequencies from the plurality of frequencies that are potentially exhibiting periodic behavior; and

determining, to generate a set of correlation values, a correlation value between each set of events from the plurality of sets of events and each candidate frequency from the set of candidate frequencies,

the attribute further identified based on the set of correlation values.

3. The method of claim 1 , wherein each set of events from the plurality of sets of events is associated with at least one of a destination location for the second device associated with that set of network events or a network protocol for the second device associated with that set of network events.

4. The method of claim 1 , wherein each event for each set of events from the plurality of sets of events is associated with a start time, an end time, a value indicating significance of that event, and a plurality of attributes.

5. The method of claim 1 , wherein:

each event for each set of events from the plurality of sets of events is associated with a start time, an end time, a value indicating significance of that event, and a plurality of attributes,

the converting the plurality of sets of events into the time series is based on the value for each event from each set of events from the plurality of sets of events, the start time for each event from each set of events from the plurality of sets of events, and the end time for each event form each set of events from the plurality of sets of events.

6. The method of claim 1 , wherein the plurality of sets of events is a plurality of sets of network events, each set of network events from the plurality of sets of network events is associated with an internet protocol (IP) address for the second device associated with that set of network events.

7. The method of claim 1 , wherein the plurality of sets of events is a plurality of sets of network events, and each network event for each set of network events from the plurality of sets of network events is associated with a value that represents an amount of data transferred between the first device and the second device associated with that set of network events.

8. The method of claim 1 , wherein:

the plurality of sets of events is a plurality of sets of network events,

the plurality of sets of network events are from a time period,

the time series is associated with a plurality of time sub-periods that together span the time period, and

converting the plurality of sets of network events into the time series includes, for each time sub-period from the plurality of time sub-periods, determining a summation value that is to be associated with that time sub-period based on a summation of all values associated with network events from the plurality of sets of network events that occur within that time sub-period.

9. The method of claim 1 , wherein the output is associated with a plurality of frequencies, the method further comprising:

applying a blurring filter to the output to generate a blurred output, the blurred output associated with the plurality of frequencies and a plurality of blurred magnitude values, each frequency from the plurality of frequencies associated with a blurred magnitude value from the plurality of magnitude values;

identifying a set of blurred magnitude values from the plurality of blurred magnitudes values that are associated with a set of frequencies from the plurality of frequencies;

performing at least one significance test based on the set of blurred magnitude values to identify a subset of frequencies from the set of frequencies; and

removing at least one harmonic frequency from the subset of frequencies to generate a set of candidate frequencies,

the identifying the attribute further based on the set of candidate frequencies.

10. The method of claim 9 , wherein:

each blurred magnitude value from the set of blurred magnitude values is larger than a first blurred magnitude value included in the plurality of blurred magnitude values and a second blurred magnitude value included in the plurality of blurred magnitude values,

the frequency associated with each blurred magnitude value from the set of blurred magnitude values is more similar to the frequency associated with the first blurred magnitude value and the frequency associated with the second blurred magnitude value than remaining frequencies from the plurality of frequencies associated with remaining blurred magnitude values from the set of blurred magnitude values.

11. The method of claim 1 , wherein:

identifying the attribute includes using a greedy technique to find the attribute.

12. An apparatus, comprising:

a processor; and

a memory operatively coupled to the processor, the processor configured to:

receive a first dataset that includes an indication of a plurality of network events, each network event from the plurality of network events associated with a value indicating significance of that network event;

generate a second dataset based on the value indicating significance for each network event from the plurality of network events;

perform a discrete Fourier transform based on the second dataset to generate a third dataset that includes an indication of a plurality of frequency ranges; and

determine, based on a comparison between the plurality of frequency ranges and the first dataset, a set of attributes associated with a network event from the plurality of network events determined to cause a periodic behavior,

wherein the set of attributes is a first set of attributes determined at a first time, and the processor is further configured to:

fail to determine a second set of attributes determined to cause the periodic behavior at a second time prior to the first time, the second set of attributes including more attributes than the first set of attributes.

13. The apparatus of claim 12 , wherein each network event from the plurality of network events associated with a start time, an end time, and a plurality of attributes that includes the set of attributes, the plurality of network events including network events that occurred between a source device and a plurality of different destination devices.

14. The apparatus of claim 12 , wherein the processor is configured to generate the second dataset based on the first dataset by:

summing, for each time sub-period from a plurality of time sub-periods that together span a time period associated with the plurality of network events and to generate the second dataset, the value associated with each network event from the plurality of network events that occur within that time sub-period.

15. The apparatus of claim 12 , wherein performing the discrete Fourier transform based on the second dataset includes:

normalizing the second dataset to generate a normalized second dataset; and

performing the discrete Fourier transform using the normalized second dataset to generate the third dataset.

16. A method, comprising:

converting, via a processor, a plurality of sets of events associated with a first device into a time series, each set of events from the plurality of sets of events associated with the first device and a second device from a plurality of second devices that is different for remaining sets of events from the plurality of sets of events and does not include the first device;

normalizing, via the processor, the time series to generate a normalized time series;

performing, via the processor, a discrete Fourier transform based on providing the normalized time series as input to the discrete Fourier transform to generate an output;

identifying, via the processor and based on the output, an attribute associated with an event from a set of events from the plurality of sets of events that is predicted to cause a periodic behavior;

and sending, via the processor, a signal to cause an output including representation of the attribute.

17. The method of claim 16 , wherein the output is associated with a plurality of frequencies, the method further comprising:

applying a blurring filter to the output to generate a blurred output, the blurred output associated with the plurality of frequencies and a plurality of blurred magnitude values, each frequency from the plurality of frequencies associated with a blurred magnitude value from the plurality of magnitude values;

identifying a set of blurred magnitude values from the plurality of blurred magnitudes values that are associated with a set of frequencies from the plurality of frequencies;

performing at least one significance test based on the set of blurred magnitude values to identify a subset of frequencies from the set of frequencies; and

removing at least one harmonic frequency from the subset of frequencies to generate a set of candidate frequencies,

the identifying the attribute further based on the set of candidate frequencies.

18. The method of claim 17 , wherein:

each blurred magnitude value from the set of blurred magnitude values is larger than a first blurred magnitude value included in the plurality of blurred magnitude values and a second blurred magnitude value included in the plurality of blurred magnitude values,

the frequency associated with each blurred magnitude value from the set of blurred magnitude values is more similar to the frequency associated with the first blurred magnitude value and the frequency associated with the second blurred magnitude value than remaining frequencies from the plurality of frequencies associated with remaining blurred magnitude values from the set of blurred magnitude values.

19. The method of claim 16 , wherein in response to normalizing, via the processor, the time series to generate a normalized time series, the method further comprises:

calculating, using the normalized time series, a linear regression fit that includes indication of a slope and an intercept;

subtracting the slope and the intercept from the normalized time series to generate a modified normalized time series; and

applying a hamming window to the normalized time series to generate the input.

20. The method of claim 16 , wherein each set of events from the plurality of sets of events is associated with at least one of a destination location for the second device associated with that set of network events or a network protocol for the second device associated with that set of network events.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Feb 4, 2025
From: ARCTIC WOLF NETWORKS, INC.
To: BLUE OWL TECHNOLOGY FINANCE CORP., AS COLLATERAL AGENT
Reel/Frame 070110/0881 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2023
From: SALMON, GEOFFREY RYAN; SOLIMAN, HAZEM MOHAMED AHMED; RAO, MOHAN
To: ARCTIC WOLF NETWORKS, INC.
Reel/Frame 064299/0803 →
Continuity (2)
Continuation 18056840 · Nov 18, 2022
Related Publication 20240171595A1 · May 23, 2024
References Cited (44)
US 10069849B2 · Muddu et al. · 2018 [cited by applicant]
US 10122738B2 · Sun et al. · 2018 [cited by applicant]
US 10264007B2 · Fehrman · 2019 [cited by applicant]
US 10645100B1 · Wang et al. · 2020 [cited by applicant]
US 10757136B2 · Fridman et al. · 2020 [cited by applicant]
US 10805326B1 · Wang · 2020 [cited by examiner]
US 11258825B1 · Yang · 2022 [cited by examiner]
US 11336681B2 · Singh et al. · 2022 [cited by applicant]
US 11463331B1 · Arlitt · 2022 [cited by examiner]
US 20130262352A1 · Sung · 2013 [cited by examiner]
US 20140331280A1 · Porras · 2014 [cited by examiner]
US 20160134641A1 · Hu et al. · 2016 [cited by applicant]
US 20160147585A1 · Konig · 2016 [cited by examiner]
US 20160173516A1 · Raugas et al. · 2016 [cited by applicant]
US 20170063921A1 · Fridman et al. · 2017 [cited by applicant]
US 20170244731A1 · Hu et al. · 2017 [cited by applicant]
US 20180176238A1 · Nos et al. · 2018 [cited by applicant]
US 20190124099A1 · Matselyukh · 2019 [cited by examiner]
US 20190132224A1 · Verma · 2019 [cited by examiner]
US 20190311297A1 · Gapper · 2019 [cited by examiner]
US 20200304529A1 · Fehrman et al. · 2020 [cited by applicant]
US 20210110033A1 · Noeth et al. · 2021 [cited by applicant]
US 20220318118A1 · Adamson · 2022 [cited by examiner]
WO 2022140794 · 2022 [cited by applicant]
WO WO2022140794A1 · 2022 [cited by applicant]
Gove Robert et al: “Visual!zing Automatically Detected Periodic Netvvork Activity”, 20i 8 IEEE Symposium on Visuauzation for Cyber Security {V?zsec), ?EEE, Oct. 22, 2018 (Oct. 22, 2018), pp. i -8, XP03354729i, DOI: iO. … [cited by examiner]
Aboutanios, et al., Iterative Frequency Estimation by Interpolation on Fourier Coefficients, IEEE Transactions on signal processing, Mar. 2005, pp. 1237-1242. [cited by applicant]
Assadhan, et al., An Efficient Method to Detect Periodic Behavior in Botnet Traffic by Analyzing Control Plane Traffic, Journal of Advanced Research, Jul. 2014, pp. 435-448. [cited by applicant]
Gomes, Efficient Detection of Malware Beaconing, Doctoral dissertation, Dublin, National College of Ireland, 2018-2019, 16 pages. [cited by applicant]
Kobayashi, et al., Mining causality of network events in log data, IEEE Transactions on Network and Service Management, Nov. 2017, pp. 53-67. [cited by applicant]
Lupari, Detecting Anomalies in TLS Traffic Using Encrypted Traffic Analysis, May 2021, 95 pages. [cited by applicant]
Shalaginov, et al., Malware Beaconing Detection by Mining Large-scale DNS Logs for Targeted Attack Identification, International Journal of Computer and Systems Engineering, Mar. 2016, pp. 743-755. [cited by applicant]
Apruzzese, Giovanni et al., “Identifying malicious hosts involved in periodic communications”, 2017 IEEE 16th International Symposium on Network Computing and Applications (NCA), IEEE Oct. 30, 2017, pp. 1-8. [cited by applicant]
De Vries, Johannes et al., “Systems for Detecting Advanced Persistent Threats: A Development Roadmap using Intelligent Data Analysis”, 2012 International Conference on Cyber Security, IEEE, pp. 54-61. [cited by applicant]
Ergene, Mehmet, “Implementing RITA in Azure Sentinel using KQL”, accessed at https://posts.bluraven.io/implementing-rita-using-kql-8ccb0ee8eeae on Apr. 12, 2024, published Jul. 21, 2021, 7 pages. [cited by applicant]
Gove, Robert et al., “Visualizing Automatically Detected Periodic Network Activity”, 2018 IEEE Symposium on Visualization for Cyber Security (VIZSEC), IEEE, Oct. 22, 2018, pp. 1-8. [cited by applicant]
Liu, Zhicheng et al., “CCGA: Clustering and Capturing Group Activities for DGA-Based Botnets Detection”, 2019 18th IEEE International Conference On Trust, Security And Privacy In Computing And Communications/13th IEEE I… [cited by applicant]
Manzoor, Emaad et al., “Fast Memory-efficient Anomaly Detection in Streaming Heterogeneous Graphs”, KDD '16, Aug. 13-17, 2016, San Francisco, CA, 10 pages. [cited by applicant]
S. Kobayashi, K. Otomo, K. Fukuda and H. Esaki, “Mining Causality of Network Events in Log Data,” in IEEE Transactions on Network and Service Management, vol. 15, No. 1 (Mar. 2018), pp. 53-67. [cited by applicant]
Yan, Guanghua, “AULD: Large Scale Suspicious DNS Activities Detection via Unsupervised Learning in Advanced Persistent Threats”, Sensors 2019, 19, 3180, 18 pages. [cited by applicant]
Yessine Borchani, Barac, “Advanced malicious beaconing detection through AI”, Network Security, Mar. 2020, pp. 8-14. [cited by applicant]
Extended Search Report in EP Application No. 23210335.8, dated Apr. 9, 2024, 9 pages. [cited by applicant]
Apruzzese et al., “Identifying malicious hosts involved in periodic communications”, 2017 IEEE 16th International Symposium on Network Computing and Applications (NCA), IEEE, Oct. 30, 2017, pp. 1-8. [cited by applicant]
Extended Search Report in EP 23210335.8, dated Apr. 9, 2024, 9 pages. [cited by applicant]