IP Library Granted Patent US 12,289,293
Granted Patent B2
US 12,289,293 · App. 18/512,509 · Granted Apr 29, 2025

Network security analysis system with reinforcement learning for selecting domains to scan

Inventors: Eugene (“John”) Neystadt (Kfar Sava, IL); Eyal Heiman (Ramot Hashavim, IL); Elisha Ben-Zvi (Hod Hasharon, IL); Asaf Nadler (Hod Hasharon, IL)
Assignee: Akamai Technologies, Inc.
H04L63/0245G06N20/00H04L47/263H04L61/4511H04L63/0236H04L63/101H04L63/1425H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,289,293
App. No.
18/512,509
Granted
Apr 29, 2025
Kind
B2
Abstract

This document describes among other things, network security systems that incorporate a feedback loop so as to automatically and dynamically adjust the scope of network traffic that is subject to inspection. Risky traffic can be sent for inspection; risky traffic that is demonstrated to have high rate of threats can be outright blocked without further inspection; traffic that is causing errors due to protocol incompatibility or should not be inspected for regulatory or other reasons can be flagged so it bypasses the security inspection system. The system can operate on a domain by domain basis, IP address basis, or otherwise.

Claims (29)

1. A method performed by one or more computers, each of which comprises circuitry forming one or more processors and memory storing instructions for execution on the one or more processors, the method comprising:

receiving traffic directed to a plurality of domains, the one or more computers lacking resources necessary to scan traffic directed to all of the plurality of domains;

maintaining a state comprising a subset of domains to be scanned within the plurality of domains;

scanning traffic directed to the subset of domains to detect one or more security exploits, in accord with the state; and,

applying a reinforcement machine learning model to update the state in a feedback control loop to control domains that are subject to said scanning, said applying comprising: (i) providing a reward for domains in the subset found to be associated with one or more security exploits, upon said scanning, and (ii) providing no reward for domains in the subset found not to be associated with one or more security exploits, upon said scanning; and (iii) updating the state through one or more of: keeping a domain within the subset, adding a domain to the subset, removing a domain from the subset.

2. The method of claim 1 , wherein the one or more security exploits comprise any of: hosting malware and triggering a firewall rule.

3. The method of claim 1 , wherein providing no reward comprises applying a negative scalar.

4. The method of claim 1 , wherein providing the reward comprises applying a positive scalar.

5. The method of claim 1 , wherein said applying of the reinforcement machine learning model executes on logs produced by said scanning.

6. The method of claim 1 , wherein said receiving and scanning are performed by a secure web gateway, and said maintaining and applying are performed by an agent in the feedback control loop.

7. The method of claim 1 , wherein the feedback control loop executes periodically to update the state and thereby control said scanning.

8. A system, comprising one or more computers in a content delivery network, each of the one or more computers comprising circuitry forming at least one processor and memory storing instructions for execution on the at least one processor to operate the system as set forth below:

receive traffic directed to a plurality of domains, the one or more computers lacking resources necessary to scan traffic directed to all of the plurality of domains;

maintain a state comprising a subset of domains to be scanned within the plurality of domains;

scan traffic directed to the subset of domains to detect one or more security exploits, in accord with the state; and,

apply a reinforcement machine learning model to update the state in a feedback control loop to control domains that are subject to said scanning, said applying comprising: (i) providing a reward for domains in the subset found to be associated with one or more security exploits, upon said scanning, and (ii) providing no reward for domains in the subset found not to be associated with one or more security exploits, upon said scanning; and (iii) updating the state through one or more of: keeping a domain within the subset, adding a domain to the subset, removing a domain from the subset.

9. The system of claim 8 , wherein the one or more security exploits comprise any of: hosting malware and triggering a firewall rule.

10. The system of claim 8 , wherein providing no reward comprises applying a negative scalar.

11. The system of claim 8 , wherein providing the reward comprises applying a positive scalar.

12. The system of claim 8 , wherein said applying of the reinforcement machine learning model executes on logs produced by said scanning.

13. The system of claim 8 , wherein said receiving and scanning are performed by a secure web gateway, and said maintaining and applying are performed by an agent in the feedback control loop.

14. The system of claim 8 , wherein the feedback control loop executes periodically to update the state and thereby control said scanning.

15. A non-transitory computer readable medium holding computer program instructions for execution on at least one hardware processor, the computer program instructions comprising instructions to:

receive traffic directed to a plurality of domains, the one or more computers lacking resources necessary to scan traffic directed to all of the plurality of domains;

maintain a state comprising a subset of domains to be scanned within the plurality of domains;

scan traffic directed to the subset of domains to detect one or more security exploits, in accord with the state; and,

apply a reinforcement machine learning model to update the state in a feedback control loop to control domains that are subject to said scanning, said applying comprising: (i) providing a reward for domains in the subset found to be associated with one or more security exploits, upon said scanning, and (ii) providing no reward for domains in the subset found not to be associated with one or more security exploits, upon said scanning; and (iii) updating the state through one or more of: keeping a domain within the subset, adding a domain to the subset, removing a domain from the subset.

16. The non-transitory computer readable medium of claim 15 , wherein the one or more security exploits comprise any of: hosting malware and triggering a firewall rule.

17. The non-transitory computer readable medium of claim 15 , wherein said receiving and scanning are performed by a secure web gateway, and said maintaining and applying are performed by an agent in the feedback control loop.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2023
From: NEYSTADT, EUGENE (JOHN); HEIMAN, EYAL; BEN-ZVI, ELISHA; NADLER, ASAF
To: AKAMAI TECHNOLOGIES, INC.
Reel/Frame 065823/0302 →
Continuity (3)
Continuation 17659561 · Apr 18, 2022
Continuation 16168451 · Oct 23, 2018
Related Publication 20240163253A1 · May 16, 2024
References Cited (15)
US 11245667B2 · Neystadt · 2022 [cited by applicant]
US 11310201B2 · Neystadt · 2022 [cited by applicant]
US 11831609B2 · Neystadt · 2023 [cited by applicant]
US 20090077666A1 · Chen · 2009 [cited by examiner]
US 20130014253A1 · Neou · 2013 [cited by examiner]
US 20140173712A1 · Ferdinand · 2014 [cited by examiner]
US 20150143504A1 · Desai · 2015 [cited by examiner]
US 20150180892A1 · Balderas · 2015 [cited by examiner]
US 20170091460A1 · Kuhr · 2017 [cited by examiner]
US 20190109872A1 · Dhakshinamoorthy · 2019 [cited by examiner]
Zhang et al., “Boosting Markov Reward Models for Probabilistic Security Evaluation by Characterizing Behaviors of Attacker and Defender”, Mar. 2008, Third International Conference on Availability, Reliability and Securi… [cited by examiner]
U.S. Appl. No. 16/168,451, filed Oct. 23, 2018. [cited by applicant]
U.S. Appl. No. 16/168,487, filed Oct. 23, 2018. [cited by applicant]
U.S. Appl. No. 17/659,561, filed Apr. 18, 2022. [cited by applicant]
Transmittal Letter titled Communication Under MPEP § 609.02, submitted with this SB/08 of Nov. 17, 2023, 2 pages. [cited by applicant]