IP Library Granted Patent US 12,363,157
Granted Patent B2
US 12,363,157 · App. 18/387,322 · Granted Jul 15, 2025

Cyber security appliance for an operational technology network

Inventors: Simon Fellows (Cambridge, GB); Jack Stockdale (Cambridge, GB)
Assignee: Darktrace Holdings Limited
H04L63/1441G06F3/04842G06F3/0486G06F16/2455G06F18/23G06F18/232G06F21/36G06F21/554G06F21/556G06F40/40G06N20/00G06N20/10G06V30/10H04L41/22H04L43/045H04L51/212H04L51/224H04L51/42H04L63/0209H04L63/0428H04L63/101H04L63/14H04L63/1416H04L63/1425H04L63/1433H04L63/1483H04L63/20G06N20/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,363,157
App. No.
18/387,322
Granted
Jul 15, 2025
Kind
B2
Abstract

A cyber security appliance has one or more modules to interact with entities in an operational technology network and potentially in an informational technology network. The operational technology module can reference various machine-learning models trained on a normal pattern of life of users, devices, and/or controllers of the operational technology network. A comparator module cooperates with the operational technology module to compare the received data on the operational technology network to the normal pattern of life of any of the users, devices, and controllers to detect anomalies in the normal pattern of life for these entities in order to detect a cyber threat. An autonomous response module can be programmed to respond to counter the detected cyber threat.

Claims (55)

1. A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in a computing device, to cause the computing device to perform operations as follows, comprising:

providing a cyber security appliance to defend an operational technology network;

receiving data on the operational technology network from i) a set of probes, ii) by passive traffic ingestion through a location within the network, and iii) any combination of both:

referencing at least two or more of

i) one or more machine-learning models, that are trained on a normal pattern of life of users of the operational technology network,

ii) one or More machine-learning models that are trained on a normal pattern of life of devices in the operational technology network, and

iii) one or more machine-learning models that are trained on a normal pattern of life of controllers in the operational technology network;

comparing the received data on the operational technology network to the normal pattern of life of any of the users, devices, and controllers to detect anomalies in the normal pattern of life for these entities in order to detect a cyber threat; and

taking a response to counter the cyber threat based on the comparison with an autonomous response module.

2. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

programming the autonomous response module i) to merely make a suggested response to take to counter the cyber threat that will be presented for explicit authorization when the cyber threat is detected or ii) to autonomously take a response to counter the cyber threat without a need for a human to approve the response when the cyber threat is detected.

3. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

programming in different subsets or zones within the operational technology network, where in these different subsets and zones, permissions for the autonomous response module to autonomously take the response to counter the cyber threat without a need for a human to approve the response when the cyber threat is detected can differ.

4. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

monitoring data from an informational technology network in order to analyze and integrate both activities occurring in the operational technology network as well as activities occurring in the informational technology network at a same time when analyzing the detected anomalies in the normal pattern of life in order to detect the cyber threat.

5. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

displaying metrics, alerts, and events of both the operational technology network in light of activities occurring in information technology network on a common display screen to allow a viewer

i) to visually contextualize the metrics, alerts, and/or events occurring in the operational technology network in light of the activities occurring in the information technology network on the common display screen,

and then ii) to confirm the detected cyber threat.

6. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

examining various fields and other header information in communications to determine whether that communication is headed to a specific operational technology component that exists beyond an endpoint gateway to operational technology components beyond that Internet Protocol address of the endpoint gateway, where the operational technology components do not have an IP address, and then display both components of an information technology network with IP addresses and identifiable operational technology network without IP addresses on a common display screen to allow a viewer to see both the components of the information technology network and components of the operational technology network on the common display screen.

7. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

using a graphical user interface to show, in real time, i) components of the operational technology network and components of an information technology network and ii) detailed data flows and commands that those network components are receiving when an abnormal behavior is detected.

8. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

comparing a chain of one or more of the detected anomalies by referencing one or more machine-learning models trained on, at least, the cyber threat.

9. The non-transitory computer readable medium storing computer readable code operable of claim 1 , when executed by the one or more processing apparatuses in the computing device, to cause the computing device to perform further operations as follows, comprising:

where once the normal pattern of life has been learned by the models, then the operational technology module can readily identify the anomalies in the normal pattern of life; and thus, unusual behaviors from the devices, users, or controllers of the operational technology network.

10. A cyber security appliance, comprising:

a processor and a memory, which further comprise:

an operational technology module configured to receive data on an operational technology network from i) a set of probes, iI) by passive traffic ingestion through a

location within the network, and iii) any combination of both, where the operational technology module is also configured to reference at least two of

i) one or more machine-learning models, using machine-learning and artificial intelligence (AI) algorithms, that are trained on a normal pattern of life of users of the operational technology network,

ii) one or More machine-learning models, using machine-learning and AI algorithms, that are trained on a normal pattern of life of devices in the operational technology network, and

iii) one or more machine-learning models, using machine-learning and AI algorithms, that are trained on a normal pattern of life of controllers in the operational technology network;

a comparator module configured to cooperate with the operational technology module to compare the received data on the operational technology network to the normal pattern of life of any of the users, devices, and controllers to detect anomalies in the normal pattern of life for these entities in order to detect a cyber threat; and

an autonomous response module configured to respond to counter the cyber threat, and a user interface to program the autonomous response module.

11. The cyber security appliance of claim 10 , where the autonomous response module is configured to i) to merely make a suggested response to take to counter the cyber threat that will be presented for explicit authorization when the cyber threat is detected or ii) to autonomously take a response to counter the cyber threat without a need for a human to approve the response when the cyber threat is detected.

12. The cyber security appliance of claim 10 , where the user interface is further configured to program in different configurations for subsets of, or zones, within the operational technology network, wherein these different subsets and zones, permissions for the autonomous response module to autonomously take the response to counter the cyber threat without a need for a human to approve the response i) when the cyber threat is detected, can differ in each different zone and ii) a range of allowed responses can also differ in each different zone, iii) and a set of allowed responses can also differ in each different zone, and iv) any combination of these.

13. The cyber security appliance of claim 10 , where the cyber security appliance containing the autonomous response module, the operational technology module, and the comparator module can be constructed for installation in an industrial environment with a protective housing and cooling components to allow the cyber security appliance to be installed in more hazardous locations where dust, moisture, temperature, and vibration require ruggedization.

14. The cyber security appliance of claim 10 , further comprising:

an informational technology module configured to monitor data from an informational technology network in order to analyze and integrate both activities occurring in the operational technology network as well as activities occurring in the informational technology network at a same time when analyzing the detected anomalies in the normal pattern of life in order to detect the cyber threat.

15. The cyber security appliance of claim 10 , further comprising:

where once the normal pattern of life has been learned by the models, then the operational technology module can readily identify the anomalies in the normal pattern of life; and thus, unusual behaviors from the devices, users, or controllers of the operational technology network.

16. The cyber security appliance of claim 10 , further comprising:

a graphical user interface is configured to display metrics, alerts, and events of both the operational technology network in light of activities occurring in an information technology network on a common display screen to allow a viewer

i) to visually contextualize the metrics, alerts, and/or events occurring in the operational technology network in light of the activities occurring in the information technology network on the common display screen,

and then ii) to confirm the detected cyber threat.

17. The cyber security appliance of claim 10 , further comprising:

a communications messaging detector configured to analyze and understand at least content and fields in two or more of i) a data link, ii) a network protocol, iii) a transport protocol, iv) a session protocol, and v) application layers of networking protocols used in operational technology networks as well as vi) those protocols shared by and used by information technology networks.

18. The cyber security appliance of claim 10 , further comprising:

a graphical user interface is configured to cooperate with communications messaging detector to examine various fields and other header information in the communications to determine whether that communication is headed to a specific operational technology component that exists beyond an endpoint gateway to operational technology components beyond that Internet Protocol address of the endpoint gateway, where the operational technology components do not have an IP address, and then display both components of an information technology network with IP addresses and identifiable operational technology network without IP addresses on a common display screen to allow a viewer to see both the components of the information technology network and components of the operational technology network on the common display screen.

19. The cyber security appliance of claim 10 , further comprising:

a graphical user interface configured to show i) components of the operational technology network and components of an information technology network and ii) detailed data flows and commands that those network components are receiving in real time and when an abnormal behavior is detected.

20. The cyber security appliance of claim 10 , further comprising:

a cyber threat module configured to compare a chain of one or more of the detected anomalies by referencing one or more machine-learning models trained on, at least, the cyber threat.

Assignments (2)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
Continuity (3)
Continuation 16278953 · Feb 19, 2019
Provisional Application 62632623 · Feb 20, 2018
Related Publication 20240073242A1 · Feb 29, 2024
References Cited (109)
US 6154844A · Touboul et al. · 2000 [cited by applicant]
US 6965968B1 · Touboul · 2005 [cited by applicant]
US 7307999B1 · Donaghey · 2007 [cited by applicant]
US 7418731B2 · Touboul · 2008 [cited by applicant]
US 7448084B1 · Apap et al. · 2008 [cited by applicant]
US 8312540B1 · Kahn et al. · 2012 [cited by applicant]
US 8819803B1 · Richards et al. · 2014 [cited by applicant]
US 8879803B2 · Ukil et al. · 2014 [cited by applicant]
US 8966036B1 · Asgekar et al. · 2015 [cited by applicant]
US 9043905B1 · Allen et al. · 2015 [cited by applicant]
US 9106687B1 · Sawhney et al. · 2015 [cited by applicant]
US 9185095B1 · Moritz et al. · 2015 [cited by applicant]
US 9213990B2 · Adjaoute · 2015 [cited by applicant]
US 9401925B1 · Guo et al. · 2016 [cited by applicant]
US 9516039B1 · Yen et al. · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9641544B1 · Treat et al. · 2017 [cited by applicant]
US 9712548B2 · Shmueli et al. · 2017 [cited by applicant]
US 9727723B1 · Kondaveeti et al. · 2017 [cited by applicant]
US 10050987B1 · Mohta · 2018 [cited by examiner]
US 10530749B1 · Park · 2020 [cited by examiner]
US 11689544B2 · Ciocarlie · 2023 [cited by examiner]
US 20020186698A1 · Ceniza · 2002 [cited by applicant]
US 20030070003A1 · Chong et al. · 2003 [cited by applicant]
US 20040083129A1 · Herz · 2004 [cited by applicant]
US 20040167893A1 · Matsunaga et al. · 2004 [cited by applicant]
US 20050065754A1 · Schaf et al. · 2005 [cited by applicant]
US 20070118909A1 · Hertzog et al. · 2007 [cited by applicant]
US 20070294187A1 · Scherrer · 2007 [cited by applicant]
US 20080005137A1 · Surendran et al. · 2008 [cited by applicant]
US 20080109730A1 · Coffman et al. · 2008 [cited by applicant]
US 20090106174A1 · Battisha et al. · 2009 [cited by applicant]
US 20090254971A1 · Herz et al. · 2009 [cited by applicant]
US 20100009357A1 · Nevins et al. · 2010 [cited by applicant]
US 20100095374A1 · Gillum et al. · 2010 [cited by applicant]
US 20100125908A1 · Kudo · 2010 [cited by applicant]
US 20100235908A1 · Eynon et al. · 2010 [cited by applicant]
US 20100299292A1 · Collazo · 2010 [cited by applicant]
US 20110093428A1 · Wisse · 2011 [cited by applicant]
US 20110213742A1 · Lemmond et al. · 2011 [cited by applicant]
US 20110261710A1 · Chen et al. · 2011 [cited by applicant]
US 20120096549A1 · Amini et al. · 2012 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120209575A1 · Barbat et al. · 2012 [cited by applicant]
US 20120210388A1 · Kolishchak · 2012 [cited by applicant]
US 20120284791A1 · Miller et al. · 2012 [cited by applicant]
US 20120304288A1 · Wright et al. · 2012 [cited by applicant]
US 20130054783A1 · Ge · 2013 [cited by examiner]
US 20130091539A1 · Khurana et al. · 2013 [cited by applicant]
US 20130198119A1 · Eberhardt, III et al. · 2013 [cited by applicant]
US 20130198840A1 · Drissi et al. · 2013 [cited by applicant]
US 20130254885A1 · Devost · 2013 [cited by applicant]
US 20130305357A1 · Ayyagari · 2013 [cited by applicant]
US 20140007237A1 · Wright et al. · 2014 [cited by applicant]
US 20140074762A1 · Campbell · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140215618A1 · Amit · 2014 [cited by applicant]
US 20140325643A1 · Bart et al. · 2014 [cited by applicant]
US 20150067835A1 · Chari et al. · 2015 [cited by applicant]
US 20150081431A1 · Akahoshi et al. · 2015 [cited by applicant]
US 20150161394A1 · Ferragut et al. · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150180893A1 · Im et al. · 2015 [cited by applicant]
US 20150213358A1 · Shelton et al. · 2015 [cited by applicant]
US 20150286819A1 · Coden et al. · 2015 [cited by applicant]
US 20150310195A1 · Bailor et al. · 2015 [cited by applicant]
US 20150319185A1 · Kirti et al. · 2015 [cited by applicant]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150363699A1 · Nikovski · 2015 [cited by applicant]
US 20150379110A1 · Marvasti et al. · 2015 [cited by applicant]
US 20160062950A1 · Brodersen et al. · 2016 [cited by applicant]
US 20160078365A1 · Baumard · 2016 [cited by applicant]
US 20160149941A1 · Thakur et al. · 2016 [cited by applicant]
US 20160164902A1 · Moore · 2016 [cited by applicant]
US 20160173509A1 · Ray et al. · 2016 [cited by applicant]
US 20160241576A1 · Rathod et al. · 2016 [cited by applicant]
US 20160352768A1 · Lefebvre et al. · 2016 [cited by applicant]
US 20160373476A1 · Dell'Anno et al. · 2016 [cited by applicant]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170169360A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170220801A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170230391A1 · Ferguson et al. · 2017 [cited by applicant]
US 20170230392A1 · Stockdale · 2017 [cited by applicant]
US 20170230410A1 · Hassanzadeh · 2017 [cited by examiner]
US 20170251012A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170270422A1 · Sorakado · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180167402A1 · Scheidler et al. · 2018 [cited by applicant]
US 20180234302A1 · James · 2018 [cited by examiner]
US 20190089722A1 · Ciocarlie · 2019 [cited by examiner]
US 20190132358A1 · DiValentin · 2019 [cited by examiner]
US 20190141058A1 · Hassanzadeh · 2019 [cited by examiner]
US 20190236177A1 · Jain · 2019 [cited by examiner]
EP 2922268A1 · 2015 [cited by applicant]
WO 2001031420A2 · 2001 [cited by applicant]
WO 2008121945A2 · 2008 [cited by applicant]
WO 2013053407A1 · 2013 [cited by applicant]
WO 2014088912A1 · 2014 [cited by applicant]
WO 2015027828A1 · 2015 [cited by applicant]
WO 2016020660A1 · 2016 [cited by applicant]
Settani et al., “Protecting cyber physical production systems using anomaly detection to enable self-adaptation,” 2018 IEEE Industrial Cyber-Physical Systems (ICPS) Year: 2018 | Conference Paper | Publisher: IEEE. [cited by examiner]
Sarkar et al., “Votnet: Hybrid Simulation of Virtual Operational Technology Network for Cybersecurity Assessment,” 2018 Winter Simulation Conference (WSC) Year: 2018 | Conference Paper | Publisher: IEEE. [cited by examiner]
Marek Zachara et al., “Detecting Unusual User Behavior to Identify Hijacked Internet Auctions Accounts,” Lecture Notes in Computer Science, 2012, vol. 7465, Springer, Berlin, Heidelberg, Germany. [cited by applicant]
The United States Patent Office, Non-Final Office Action, Dec. 1, 2021, 61 pages. [cited by applicant]
The United States Patent Office, Final Office Action, Jun. 28, 2022, 40 pages. [cited by applicant]
European Patent Office, European Search report, Jul. 15, 2019, 8 pages. [cited by applicant]