IP Library Granted Patent US 12,328,327
Granted Patent B2
US 12,328,327 · App. 18/485,297 · Granted Jun 10, 2025

System and method for anomaly detection interpretation

Inventors: Yuval Friedlander (Petah Tiqwa, IL); Ron Shoham (Tel Aviv, IL); Gil Ben Zvi (Hod Hasharon, IL); Tom Hanetz (Tel Aviv, IL)
Assignee: ARMIS SECURITY LTD.
H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,328,327
App. No.
18/485,297
Granted
Jun 10, 2025
Kind
B2
Abstract

A system and method for anomaly interpretation and mitigation. A method includes extracting at least one input feature vector from observation data related to an observation; applying an isolation forest to the at least one input feature vector, wherein the isolation forest includes a plurality of estimators, wherein each estimator is a decision tree, wherein the output of each estimator is a split-path of a plurality of split-paths, each split-path having a path-length and including name and a corresponding value for a respective output feature of a plurality of output features; generating a mapping object based on the application of the isolation forest to the at least one feature vector, wherein the mapping object includes the plurality of split-paths; clipping the mapping object based on the path-length of each split-path; and determining at least one mitigation action based on the clipped mapping object.

Claims (44)

1. A method for anomaly interpretation and mitigation, comprising:

extracting an input feature vector from observation data indicating anomalous behavior of a connected device;

applying an isolation forest to the input feature vector, wherein the isolation forest includes a plurality of estimators, wherein each estimator is a decision tree, wherein an output of each estimator is a split-path of a plurality of split-paths, each split-path having a path-length and including name and a corresponding value for a respective output feature of a plurality of output features, wherein each output feature represents at least a portion of a description of why the observation was determined to indicate anomalous behavior;

generating a mapping object based on an application of the isolation forest to the feature vector, wherein the mapping object includes the plurality of split-paths;

removing a number of split-paths from the mapping object based at least in part on a predetermined ratio of a total number of the plurality of estimators;

determining additional context data determined from remaining split-paths; and

determining at least one mitigation action.

2. The method of claim 1 , further comprising:

sorting the plurality of split-paths based on their respective path-lengths; and removing at least one split-path from the plurality of split-paths.

3. The method of claim 2 , further comprising:

determining the at least one split-path to be removed from the plurality of split-paths based on the sorted plurality of split-paths and a ratio of a total number of estimators.

4. The method of claim 1 , further comprising:

generating additional contextual data, wherein the at least one mitigation action is determined based further on the additional contextual data.

5. The method of claim 4 , wherein the additional contextual data includes statistical data for each output feature determined based on the remaining split-paths.

6. The method of claim 5 , wherein the statistical data indicates, for each output feature, at least one of: a number of occurrences of the output feature among the output features of the remaining split-paths, a percentile of the value of the output feature with respect to other observations in a sub-population of observations, and a position of the output feature within a distribution of the output features of the remaining split-paths.

7. The method of claim 1 , wherein the observation was determined to indicate an anomaly.

8. The method of claim 7 , wherein the observation has an anomaly score representing a likelihood that the observation indicates an anomaly, wherein the anomaly score is above a threshold.

9. The method of claim 1 , wherein each estimator is a binary decision tree.

10. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

extracting at least one input feature vector from observation data related to an observation, wherein the observation indicates anomalous behavior of a connected device;

applying an isolation forest to the at least one input feature vector, wherein the isolation forest includes a plurality of estimators, wherein each estimator is a decision tree, wherein an output of each estimator is a split-path of a plurality of split-paths, each split-path having a path-length and including name and a corresponding value for a respective output feature of a plurality of output features, wherein each output feature represents at least a portion of a description of why the observation was determined to indicate anomalous behavior;

generating a mapping object based on an application of the isolation forest to the at least one feature vector, wherein the mapping object includes the plurality of split-paths;

removing a number of split-paths from the mapping objects based at least in part on a predetermined ratio of a total number of the plurality of estimators;

determining additional context data determined from remaining split-paths; and

determining at least one mitigation action.

11. A system for anomaly interpretation, comprising: a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

extract at least one input feature vector from observation data related to an observation, wherein the observation indicates anomalous behavior of a connected device;

apply an isolation forest to the at least one input feature vector, wherein the isolation forest includes a plurality of estimators, wherein each estimator is a decision tree, wherein an output of each estimator is a split-path of a plurality of split-paths, each split-path having a path-length and including name and a corresponding value for a respective output feature of a plurality of output features, wherein each output feature represents at least a portion of a description of why the observation was determined to indicate anomalous behavior;

generate a mapping object based on an application of the isolation forest to the at least one feature vector, wherein the mapping object includes the plurality of split-paths;

remove a number of split-paths from the mapping object based at least in part on a predetermined ratio of a total number of the plurality of estimators;

determining additional context data determined from remaining split-paths; and

determine at least one mitigation action.

12. The system of claim 11 , wherein the system is further configured to:

sort the plurality of split-paths based on their respective path-lengths; and remove at least one split-path from the plurality of split-paths.

13. The system of claim 12 , wherein the system is further configured to:

determine the at least one split-path to be removed from the plurality of split-paths based on the sorted plurality of split-paths and a ratio of a total number of estimators.

14. The system of claim 11 , wherein the system is further configured to:

generate additional contextual data, wherein the at least one mitigation action is determined based further on the additional contextual data.

15. The system of claim 14 , wherein the additional contextual data includes statistical data for each output feature determined based on the remaining split-paths.

16. The system of claim 15 , wherein the statistical data indicates, for each output feature, at least one of: a number of occurrences of the output feature among the output features of the remaining split-paths, a percentile of the value of the output feature with respect to other observations in a sub-population of observations, and a position of the output feature within a distribution of the output features of the remaining split-paths.

17. The system of claim 11 , wherein the observation was determined to indicate an anomaly.

18. The system of claim 17 , wherein the observation has an anomaly score representing a likelihood that the observation indicates an anomaly, wherein the anomaly score is above a threshold.

19. The system of claim 11 , wherein each estimator is a binary decision tree.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Apr 21, 2026
From: HERCULES CAPITAL, INC.
To: ARMIS SECURITY LTD; ARMIS INC.
Reel/Frame 075477/0965 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2024
From: FRIEDLANDER, YUVAL; SHOHAM, RON; BEN ZVI, GIL; HANETZ, TOM
To: ARMIS SECURITY LTD.
Reel/Frame 069524/0733 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 5, 2024
From: ARMIS SECURITY LTD.
To: HERCULES CAPITAL, INC., AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 066740/0499 →
Continuity (2)
Continuation 17093915 · Nov 10, 2020
Related Publication 20240154984A1 · May 9, 2024
References Cited (27)
US 9412024B2 · Chaudhury et al. · 2016 [cited by applicant]
US 10045218B1 · Stapleton et al. · 2018 [cited by applicant]
US 10924503B1 · Pereira · 2021 [cited by examiner]
US 11190641B1 · Shukla · 2021 [cited by examiner]
US 20190020670A1 · Brabec et al. · 2019 [cited by applicant]
US 20200285737A1 · Kraus et al. · 2020 [cited by applicant]
US 20200334228A1 · Matyska et al. · 2020 [cited by applicant]
US 20210067548A1 · Brandt · 2021 [cited by examiner]
US 20210097177A1 · Chistyakov · 2021 [cited by examiner]
US 20210160266A1 · Sternby · 2021 [cited by examiner]
US 20210378577A1 · Sun · 2021 [cited by examiner]
US 20220086179A1 · Levin · 2022 [cited by examiner]
US 20220138321A1 · Shrestha · 2022 [cited by examiner]
US 20220327219A1 · Choi · 2022 [cited by examiner]
US 20230011129A1 · Wuhib · 2023 [cited by examiner]
CN 106846806A · 2017 [cited by applicant]
CN 108900476A · 2018 [cited by applicant]
EP 3451219A1 · 2019 [cited by applicant]
EP 3896543A1 · 2020 [cited by applicant]
JP 2019179395A · 2019 [cited by applicant]
WO 2020124037A1 · 2020 [cited by applicant]
Deng et al., Sparse Support Vector Machine for Network Behavior Anomaly Detection,2020 IEEE 8th International Conference on Information, Communication and Networks (ICICN) Year: 2020 | Conference Paper | Publisher: IEEE. [cited by examiner]
Zhang et al., “Network Anomaly Detection Based on Cooperative Semi-Supervised Support Vector Machine,” 2019 International Conference on Networking and Network Applications (NaNA) Year: 2019 | Conference Paper | Publishe… [cited by examiner]
Chandola, et al., “Anomaly Detection: A Survey”. ACM Computing Surveys, vol. 41, No. 3, Article 15, 2009, pp. 1-72. [cited by applicant]
Liu, et al., “Isolation Forest” 2008 Eight IEEE International Conference on Data Mining, 2009, pp. 413-422. [cited by applicant]
International Search Report and Written Opinion of International Searching Authority for PCT/IB2021/059726, ISA/IL, Jerusalem, Israel: dated Dec. 19, 2021. [cited by applicant]
Sheng, Xu, “Politecnico Di Milano Machine Learning Techniques for Fault Detection in Chemical Processes. The Tennessee Eastman Process case study,” Dec. 31, 2019. [cited by applicant]
Cited By (3)
US 12,572,846 US 12,574,399 US 12,695,752