IP Library Granted Patent US 12,003,256
Granted Patent B2
US 12,003,256 · App. 18/460,553 · Granted Jun 4, 2024

System and method for data compression with intrusion detection

Inventors: Joshua Cooper (Columbia, SC); Aliasghar Riahi (Orinda, CA); Charles Yeomans (Orinda, CA)
Assignee: ATOMBEAM TECHNOLOGIES INC.
H03M7/3059G06F21/554G06N20/00H03M7/6005
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,003,256
App. No.
18/460,553
Filed
Sep 3, 2023
Granted
Jun 4, 2024
Kind
B2
Art Unit
2498
USPC
726/23
Abstract

A system and method for data compression with intrusion detection, that measures in real-time the probability distribution of an encoded data stream, compares the probability distribution to a reference probability distribution, and uses one or more statistical algorithms to determine the divergence between the two sets of probability distributions to determine if an unusual distribution is the result of a data intrusion. The system comprises both encoding and decoding machines, an intrusion detection module, a codebook training module, and various databases which perform various analyses on encoded data streams.

Claims (55)

1. A system for data compaction with intrusion detection, comprising:

a computing device comprising a processor and a memory;

an intrusion detection module comprising a first plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing device to:

receive a codeword data stream;

use one or more algorithms to compute a probability distribution of a plurality of codewords within the codeword data stream;

compare the computed probability distribution with a reference probability distribution to compute an amount of divergence between the computed probability distribution and the reference probability distribution; and

when the computed amount of divergence exceeds a configured risk sensitivity threshold:

store the computed divergence, the computed probability distribution, and the codeword as anomalous event data in a database;

generate an intrusion alert, the intrusion alert comprising the anomalous event data; and

send the intrusion alert to a user interface to be viewed by a user; and

a codebook training module comprising a second plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing device to:

receive a training dataset;

use the training dataset to create the reference probability distribution;

send the reference probability distribution to the intrusion detection module;

receive data;

format the received data into a test dataset;

retrieve a first measured probability distribution associated with the previous training dataset from a monitor database;

use one or more algorithms to measure a second probability distribution of the test dataset;

compare the first and second measured probability distributions to compute the difference in distribution statistics between the test dataset and the previous training dataset;

in response to the difference in distribution statistics' exceeding a pre-determined difference threshold:

use the test dataset to retrain encoding and decoding algorithms;

utilize the retrained algorithms to create new data sourceblocks;

create new codeword for each new data sourceblock;

store each new data sourceblock and its associated new codeword in an updated codebook; and

send the updated codebook to a plurality of encoding and decoding machines.

2. The system of claim 1 , wherein the monitor database is stored in the memory of the computing device, wherein the monitor database comprises a previous training dataset, the first-measured probability distribution associated with the previous training dataset, performance metrics, and model predictions.

3. The system of claim 1 , further comprising a data deconstruction engine comprising a third plurality of programming instructions stored in the memory which, when operating on the processor, causes the computing device to:

receive a plurality of codewords from a codeword storage; and

send the plurality of codewords as a codeword data stream to the intrusion detection module.

4. A method for data compaction with intrusion detection, comprising the steps of:

receiving a codeword data stream;

using one or more algorithms to compute a probability distribution of a plurality of codewords within the codeword data stream;

comparing the computed probability distribution with a reference probability distribution to compute an amount of divergence between the computed probability distribution and the reference probability distribution; and

when the computed amount of divergence exceeds a configured risk sensitivity threshold:

storing the computed divergence, the computed probability distribution, and the codeword as anomalous event data in a database;

generating an intrusion alert, the intrusion alert comprising the anomalous event data; and

sending the intrusion alert to a user interface to be viewed by a user;

receiving a training dataset;

using the training dataset to create the reference probability distribution;

sending the reference probability distribution to the intrusion detection module;

receiving data;

formatting the received data into a test dataset;

retrieving a first measured probability distribution associated with the previous training dataset from a monitor database;

using one or more algorithms to measure a second probability distribution of the test dataset;

comparing the first and second measured probability distributions to compute the difference in distribution statistics between the test dataset and the previous training dataset;

in response to the difference in distribution statistics' exceeding a pre-determined difference threshold:

using the test dataset to retrain encoding and decoding algorithms;

utilizing the retrained algorithms to create new data sourceblocks;

creating new codeword for each new data sourceblock;

storing each new data sourceblock and its associated new codeword in an updated codebook; and

sending the updated codebook to a plurality of encoding and decoding machines.

5. The method of claim 4 , wherein the monitor database is stored in the memory of the computing device, wherein the monitor database comprises a previous training dataset, the first-measured probability distribution associated with the previous training dataset, performance metrics, and model predictions.

6. The method of claim 4 , further the steps of:

receiving a plurality of codewords from a codeword storage; and

sending the plurality of codewords as a codeword data stream to the intrusion detection module.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2023
From: COOPER, JOSHUA; RIAHI, ALIASGHAR; YEOMANS, CHARLES
To: ATOMBEAM TECHNOLOGIES INC.
Reel/Frame 065987/0332 →
Continuity (20)
Continuation In Part 18161080 · Jan 29, 2023
Continuation 17875201 · Jul 27, 2022
Continuation 17514913 · Oct 29, 2021
Continuation 17458747 · Aug 27, 2021
Continuation In Part 17404699 · Aug 17, 2021
Continuation In Part 17234007 · Apr 19, 2021
Continuation In Part 17180439 · Feb 19, 2021
Continuation In Part 16923039 · Jul 7, 2020
Continuation In Part 16923039 · Jul 7, 2020
Continuation In Part 16716098 · Dec 16, 2019
Continuation 16455655 · Jun 27, 2019
Continuation In Part 16455655 · Jun 27, 2019
Continuation In Part 16200466 · Nov 26, 2018
Continuation In Part 15975741 · May 9, 2018
Provisional Application 63485514 · Feb 16, 2023
Provisional Application 63140111 · Jan 21, 2021
Provisional Application 63027166 · May 19, 2020
Provisional Application 62926723 · Oct 28, 2019
Provisional Application 62578824 · Oct 30, 2017
Related Publication 20230412192A1 · Dec 21, 2023