IP Library Granted Patent US 12,489,835
Granted Patent B2
US 12,489,835 · App. 18/432,575 · Granted Dec 2, 2025

System and methods for automated computer security policy generation and anomaly detection

Inventor: Andres De Jesus Andreu (Cary, NC)
Assignee: OPSWAT Inc.
H04L69/40G06F18/214H04L63/0236H04L63/1416H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,489,835
App. No.
18/432,575
Granted
Dec 2, 2025
Kind
B2
Abstract

A method includes receiving first network traffic data having a plurality of data packets. A representation of each data packet from the plurality of data packets is stored in a first data store, to produce a set of training data. A plurality of communication protocols associated with the set of training data is detected. A set of rules based on the plurality of communication protocols is determined. The set of rules includes domain-specific information associated with each communication protocol detected. Training data from the set of training data is restructured according to the set of rules to produce processed data. The processed data is stored as non-malicious data in a second data store. A security policy is generated based on the processed data.

Claims (54)

1 . A method, comprising:

receiving first network traffic data including a plurality of data packets;

storing a representation of each data packet from the plurality of data packets in a first data store, to produce a set of training data;

detecting a plurality of communication protocols associated with the set of training data;

determining a set of rules based on the plurality of communication protocols, wherein the set of rules includes domain-specific information associated with each communication protocol detected;

restructuring training data from the set of training data according to the set of rules, to produce processed data;

storing the processed data, as non-malicious data, in a second data store; and

generating a security policy based on the processed data.

2 . The method of claim 1 , further comprising:

receiving, via a user interface, a user input; and

generating the security policy in response to the user input.

3 . The method of claim 1 , further comprising:

storing the security policy in the second data store.

4 . The method of claim 1 , further comprising:

applying the security policy to second network traffic data.

5 . The method of claim 1 , wherein the plurality of communication protocols includes at least one of: Modbus, Financial Information exchange (FIX), Distributed Network Protocol (DNP3), Ethernet Global Data (EGD), Ethernet/IP, Message Queuing Telemetry Transport (MQTT), Constrained Application protocol (COAP), IEC104, OPC Unified Architecture (UA) controls, Niagara Fox, Factory Interface Network Service (FINS), or Seamless Message Protocol (SLMP).

6 . The method of claim 1 , wherein the first network traffic data includes known non-malicious data.

7 . The method of claim 1 , wherein the producing the set of training data is performed during a time period associated with known non-malicious data transmission.

8 . A method comprising:

receiving first network traffic data including a first plurality of data packets;

storing a representation of each data packet from the first plurality of data packets in a first data store, to produce a set of training data;

detecting a plurality of communication protocols associated with the set of training data;

determining a set of rules based on the plurality of communication protocols, wherein the set of rules includes domain-specific information associated with each communication protocol detected;

restructuring training data from the set of training data according to the set of rules, to produce processed data;

storing the processed data, as non-malicious data, in a second data store; and

performing anomaly detection based on the processed data.

9 . The method of claim 8 , wherein the performing of the anomaly detection comprises:

receiving second network traffic data including a second plurality of data packets;

comparing the second network traffic data to the processed data; and

determining a deviation in the second network traffic data from the processed data.

10 . The method of claim 9 , further comprising:

when the deviation is determined, blocking the second plurality of data packets of the second network traffic data.

11 . The method of claim 8 , wherein the plurality of communication protocols includes at least one of: Modbus, Financial Information exchange (FIX), Distributed Network Protocol (DNP3), Ethernet Global Data (EGD), Ethernet/IP, Message Queuing Telemetry Transport (MQTT), Constrained Application protocol (COAP), IEC104, OPC Unified Architecture (UA) controls, Niagara Fox, Factory Interface Network Service (FINS), or Seamless Message Protocol (SLMP).

12 . The method of claim 8 , wherein the restructuring the training data from the set of training data according to the set of rules includes compressing the training data from the set of training data according to the set of rules.

13 . The method of claim 8 , wherein the restructuring of the training data includes normalizing the training data according to the set of rules.

14 . A method, comprising:

receiving first network traffic data including a plurality of data packets;

storing a representation of each data packet from the plurality of data packets in a first data store, to produce a set of training data;

detecting a plurality of communication protocols associated with the set of training data;

determining a set of rules based on the plurality of communication protocols, wherein the set of rules includes domain-specific information associated with each communication protocol detected;

restructuring training data from the set of training data according to the set of rules based on the detected plurality of communication protocols, to produce processed data;

storing the processed data, as non-malicious data, in a second data store; and

modifying the restructured data.

15 . The method of claim 14 , wherein the modifying of the restructured data comprises:

removing unwanted data from the processed data.

16 . The method of claim 14 , wherein the modifying of the restructured data comprises:

adding known good data to the processed data.

17 . The method of claim 14 , wherein the modifying of the restructured data comprises:

receiving the first network traffic data;

detecting known good data in the first network traffic data; and

adding the known good data to the processed data.

18 . The method of claim 14 , wherein the plurality of communication protocols includes at least one of: Modbus, Financial Information exchange (FIX), Distributed Network Protocol (DNP3), Ethernet Global Data (EGD), Ethernet/IP, Message Queuing Telemetry Transport (MQTT), Constrained Application protocol (COAP), IEC104, OPC Unified Architecture (UA) controls, Niagara Fox, Factory Interface Network Service (FINS), or Seamless Message Protocol (SLMP).

19 . The method of claim 14 , wherein the first network traffic data includes known non-malicious data.

20 . The method of claim 14 , wherein the restructuring of the training data includes compressing the training data.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2024
From: ANDREU, ANDRES DE JESUS
To: BAYSHORE NETWORKS, INC.
Reel/Frame 066498/0320 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 20, 2024
From: BAYSHORE NETWORKS, INC.
To: OPSWAT INC.
Reel/Frame 066498/0423 →
Continuity (4)
Continuation 17190687 · Mar 3, 2021
Continuation PCTUS2019053533 · Sep 27, 2019
Provisional Application 62737337 · Sep 27, 2018
Related Publication 20240179228A1 · May 30, 2024
References Cited (34)
US 6292098B1 · Ebata · 2001 [cited by examiner]
US 7376080B1 · Riddle · 2008 [cited by examiner]
US 8789183B1 · Xie · 2014 [cited by examiner]
US 8839345B2 · Griffin · 2014 [cited by examiner]
US 9230102B2 · Yu · 2016 [cited by examiner]
US 9690933B1 · Singh et al. · 2017 [cited by applicant]
US 11924316B2 · Andreu · 2024 [cited by examiner]
US 20030061263A1 · Riddle · 2003 [cited by examiner]
US 20060242701A1 · Black · 2006 [cited by examiner]
US 20090235324A1 · Griffin · 2009 [cited by examiner]
US 20100011433A1 · Harrison · 2010 [cited by examiner]
US 20100268763A1 · Rasanen · 2010 [cited by examiner]
US 20110231510A1 · Korsunsky et al. · 2011 [cited by applicant]
US 20140095711A1 · Kim · 2014 [cited by examiner]
US 20140096251A1 · Doctor et al. · 2014 [cited by applicant]
US 20160028763A1 · Mota et al. · 2016 [cited by applicant]
US 20160212171A1 · Senanayake et al. · 2016 [cited by applicant]
US 20170063886A1 · Muddu et al. · 2017 [cited by applicant]
US 20170126718A1 · Baradaran et al. · 2017 [cited by applicant]
US 20180253550A1 · Kuperman et al. · 2018 [cited by applicant]
US 20190036779A1 · Bajaj · 2019 [cited by examiner]
US 20190124118A1 · Swafford · 2019 [cited by applicant]
US 20190332752A1 · Gordon · 2019 [cited by examiner]
US 20210400083A1 · Stokes · 2021 [cited by examiner]
US 20220086190A1 · Nguyen · 2022 [cited by examiner]
US 20220109701A1 · Zeng · 2022 [cited by examiner]
US 20220232025A1 · Kapoor · 2022 [cited by examiner]
US 20220277074A1 · Biller · 2022 [cited by examiner]
US 20230188500A1 · Pikarski · 2023 [cited by examiner]
European Search Report dated May 23, 2022 for European Patent Office Patent Application No. 19866447.6. [cited by applicant]
International Search Report dated Jan. 3, 2020 for PCT Patent Application No. PCT/US2019/053533. [cited by applicant]
Notice of Allowance and Fees dated Oct. 31, 2023 for U.S. Appl. No. 17/190,687. [cited by applicant]
Office Action dated Jan. 4, 2023 for India Patent Application No. 202117010269. [cited by applicant]
Office Action dated Sep. 13, 2023 for U.S. Appl. No. 17/190,687. [cited by applicant]