IP Library Granted Patent US 11,985,040
Granted Patent B2
US 11,985,040 · App. 18/446,402 · Granted May 14, 2024

Multi-baseline unsupervised security-incident and network behavioral anomaly detection in cloud-based compute environments

Inventors: Nitzan Niv (Nesher, IL); Gad Naor (Tel-Aviv, IL)
Assignee: Rapid7 Israel Technologies Ltd.
H04L41/142G06F9/546G06N5/01G06N20/00G06Q30/0271H04L41/069H04L41/145H04L43/062H04L63/102H04L63/104H04L63/1416H04L63/1425H04L63/1441H04L67/30H04L67/535H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,985,040
App. No.
18/446,402
Granted
May 14, 2024
Kind
B2
Abstract

A method and system for detecting anomalous network activity in a cloud-based compute environment. The method comprises receiving configuration data and network activity observations for a set of virtual entities in the cloud-based compute environment; creating a profile for each virtual entity in the set of virtual entities, when the virtual entity does not already have an associated profile; dynamically updating the virtual entity of a profile with the respective network activity observations of the virtual entity; and determining whether anomalies have been detected.

Claims (51)

1. A method for detecting anomalous network behavior in a cloud-based computing environment by using virtual entity groups, the virtual entity groups being associated with corresponding profiles indicating expected network behavior associated with the virtual entity groups, the method comprising:

using at least one hardware processor to perform:

receiving network activity observations for a monitored virtual entity hosted in the cloud-based computing environment, the monitored virtual entity being part of a first virtual entity group of the virtual entity groups, the first virtual entity group being associated with a corresponding first virtual entity group profile indicating expected network behavior associated with the first virtual entity group;

detecting anomalous network behavior by the monitored virtual entity by identifying deviations between the received network activity observations for the monitored virtual entity and the first virtual entity group profile;

determining that the anomalous network behavior indicates a security incident; and

generating a report indicating the security incident and the anomalous network behavior.

2. The method of claim 1 , wherein the monitored virtual entity is a virtual machine hosted on a physical host of the cloud-based computing environment.

3. The method of claim 1 , wherein the monitored virtual entity is associated with an entity profile, the method further comprising:

updating the entity profile for the monitored virtual entity using the network activity observations to obtain an updated entity profile for the monitored virtual entity.

4. The method of claim 3 , wherein detecting the anomalous network behavior by the monitored virtual entity comprises comparing the updated entity profile for the monitored virtual entity with the first virtual entity group profile.

5. The method of claim 3 ,

wherein the entity profile includes one or more probabilistic distributions over a corresponding one or more factors, each of the one or more factors representing an aspect of behavior of the monitored virtual entity,

wherein updating the entity profile for the monitored virtual entity comprises updating the one or more probabilistic distributions based on the network activity observations.

6. The method of claim 1 , further comprising:

initiating one or more mitigation actions to mitigate the anomalous network behavior.

7. A system for detecting anomalous network behavior in a cloud-based computing environment by using virtual entity groups, the virtual entity groups being associated with corresponding profiles indicating expected network behavior associated with the virtual entity groups, the system comprising:

at least one hardware processor configured to perform:

receiving network activity observations for a monitored virtual entity hosted in the cloud-based computing environment, the monitored virtual entity being part of a first virtual entity group of the virtual entity groups, the first virtual entity group being associated with a corresponding first virtual entity group profile indicating expected network behavior associated with the first virtual entity group;

detecting anomalous network behavior by the monitored virtual entity by identifying deviations between the received network activity observations for the monitored virtual entity and the first virtual entity group profile;

determining that the anomalous network behavior indicates a security incident; and

generating a report indicating the security incident and the anomalous network behavior.

8. The system of claim 7 ,

wherein the monitored virtual entity is associated with a respective entity profile,

wherein the hardware processor is further configured to perform updating the entity profile for the monitored virtual entity using the network activity observations to obtain an updated entity profile for the monitored virtual entity, and

wherein detecting the anomalous network behavior by the monitored virtual entity comprises comparing the updated entity profile for the monitored virtual entity with the first virtual entity group profile.

9. The system of claim 7 , wherein the monitored virtual entity is a virtual machine hosted on a physical host of the cloud-based computing environment.

10. At least one non-transitory computer readable storage medium storing instructions that when executed by at least one hardware processor cause the at least one hardware processor to perform a method for detecting anomalous network behavior in a cloud-based computing environment by using virtual entity groups, the virtual entity groups being associated with corresponding profiles indicating expected network behavior associated with the virtual entity groups, the method comprising:

receiving network activity observations for a monitored virtual entity hosted in the cloud-based computing environment, the monitored virtual entity being part of a first virtual entity group of the virtual entity groups, the first virtual entity group being associated with a corresponding first virtual entity group profile indicating expected network behavior associated with the first virtual entity group;

detecting anomalous network behavior by the monitored virtual entity by identifying deviations between the received network activity observations for the monitored virtual entity and the first virtual entity group profile;

determining that the anomalous network behavior indicates a security incident; and

generating a report indicating the security incident and the anomalous network behavior.

11. The at least one non-transitory computer readable storage medium of claim 10 , wherein the monitored virtual entity is associated with a respective entity profile,

wherein the hardware processor is further configured to perform updating the entity profile for the monitored virtual entity using the network activity observations to obtain an updated entity profile for the monitored virtual entity, and

wherein detecting the anomalous network behavior by the monitored virtual entity comprises comparing the updated entity profile for the monitored virtual entity with the first virtual entity group profile.

12. The at least one non-transitory computer readable storage medium of claim 10 , wherein the monitored virtual entity is a virtual machine hosted on a physical host of the cloud-based computing environment.

13. A method for detecting anomalous network behavior in a cloud-based computing environment by using profiles indicating expected network behavior associated with virtual entities, the method comprising:

using at least one computer hardware processor to perform:

receiving network activity observations for a monitored virtual entity hosted in the cloud-based computing environment, the monitored virtual entity being associated with a corresponding entity profile indicating expected network behavior associated with the virtual entity;

detecting anomalous network behavior by the monitored virtual entity by identifying deviations between the received network activity observations for the monitored virtual entity and the entity profile;

determining that the anomalous network behavior indicates a security incident; and

generating a report indicating the security incident and the anomalous network behavior.

14. The method of claim 13 , wherein the monitored virtual entity is a virtual machine hosted on a physical host of the cloud-based computing environment.

15. The method of claim 13 , further comprising:

updating the entity profile for the monitored virtual entity using the network activity observations to obtain an updated entity profile for the monitored virtual entity.

16. The method of claim 15 , wherein detecting the anomalous network behavior by the monitored virtual entity comprises comparing the updated entity profile for the monitored virtual entity with the entity profile.

17. The method of claim 15 ,

wherein the entity profile includes one or more probabilistic distributions over a corresponding one or more factors, each of the one or more factors representing an aspect of behavior of the monitored virtual entity,

wherein updating the entity profile for the monitored virtual entity comprises updating the one or more probabilistic distributions based on the network activity observations.

18. The method of claim 17 , wherein the one or more factors includes multiple factors and the entity profile describes conditional relationships among the multiple factors.

19. The method of claim 18 , wherein the entity profile represents the conditional relationships among the multiple factors using a directed acyclic graph.

20. The method of claim 13 , further comprising initiating one or more mitigation actions to mitigate the anomalous network behavior.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2025
From: RAPID7 ISRAEL TECHNOLOGIES LTD.
To: INTSIGHTS CYBER INTELLIGENCE LTD.
Reel/Frame 072728/0596 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2024
From: NIV, NITZAN; NAOR, GAD
To: RAPID7 ISRAEL TECHNOLOGIES LTD
Reel/Frame 066672/0963 →
Continuity (3)
Continuation 17590221 · Feb 1, 2022
Continuation 16263322 · Jan 31, 2019
Related Publication 20230388195A1 · Nov 30, 2023