IP Library Granted Patent US 12,206,703
Granted Patent B2
US 12,206,703 · App. 18/519,175 · Granted Jan 21, 2025

Asset anomaly detection based on cross organizational asset data modeling

Inventors: Richard Tsang (Toronto, CA); Fatemeh Kazemeyni (Toronto, CA); Evgeniya Barkova (Toronto, CA)
Assignee: Rapid7, Inc.
H04L63/1441G06N7/01G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,206,703
App. No.
18/519,175
Granted
Jan 21, 2025
Kind
B2
Abstract

Methods and systems for identifying assets for review. The methods described herein involve generating an organizational statistical model describing assets associated with a first organization and generating a report identifying a discrepancy between the organizational statistical model and an identified asset of the first type associated with the first organization.

Claims (68)

1. A method comprising:

performing, by one or more computer systems:

receiving organizational asset data of a first organization, wherein the organizational asset data includes data regarding a plurality of assets of different types;

generating an organizational statistical model for the first organization by applying a clustering machine learning algorithm to the organizational asset data to cluster the plurality of assets into clusters according to respective types of the assets;

receiving cross-organizational asset data of a second organization, wherein the cross-organizational asset data includes data regarding a plurality of assets of different types associated with at least the second organization;

generating a cross-organizational statistical model associated with the second organization by applying the clustering machine learning algorithm to the cross-organizational asset data to cluster the plurality of assets of the second organization according to respective types of the assets of the second organization;

comparing the organizational statistical model with the cross-organizational statistical model to detect a discrepancy between a first asset of the first organization and a second asset of the second organization, wherein the second asset is in a second cluster associated with an asset type, and the first asset is in a first cluster associated with the same asset type; and

outputting a report summarizing the detected discrepancy.

2. The method of claim 1 , wherein

the discrepancy indicates that the second asset behaved in an unexpected or anomalous manner for assets of the asset type.

3. The method of claim 1 , wherein

the discrepancy is indicated as a security alert was observed for the second asset that is statistically unexpected or anomalous for assets of the asset type.

4. The method of claim 1 , wherein

the cross-organizational statistical model is generated based on statistical data of at least some of the organizational asset data of the first organization.

5. The method of claim 1 , further comprising the one or more computer systems:

receiving additional organizational asset data of the first organization, and in response:

updating the organizational statistical model based on the additional organizational asset data; and

updating the cross-organizational statistical model based on the additional organizational asset data.

6. The method of claim 1 , wherein

the cross-organizational statistical model is continuously updated based on additional organizational asset data of a plurality of organizations that are associated with a same industry.

7. The method of claim 1 , wherein

the asset type is a classification of assets based on one or more of:

whether a particular asset is a laptop,

whether a particular asset is a mobile device,

one or more types of software installed on the particular asset,

one or more configuration settings of the particular asset,

a connection history of the particular asset, and

one or more ports used by the particular asset, and

a packet count or bytes transmitted to or from the particular asset.

8. The method of claim 1 , wherein

the asset type is defined based on one or more golden standard assets of the asset type.

9. The method of claim 8 , wherein

the report is a security report outputted via a graphical user interface (GUI) of the security monitoring system, wherein the GUI is generated on a computer system remote from a first network of the first asset and a second network of the second asset.

10. The method of claim 1 , wherein

one or more computer systems are part of a security monitoring system configured to monitor respective security postures of a plurality of networks of a plurality of organizations.

11. The method of claim 10 , wherein

the discrepancy is indicated as a visual alert, and the method further includes performing one or more threat mitigation procedures on the second asset or the second network according to user input received via the GUI.

12. The method of claim 11 , further comprising display, via the GUI, a graphical representation of a set of clusters generated by the clustering machine learning algorithm including the first cluster and the second cluster, wherein the graphical representation indicates respective distances among the clusters determined using a distinct function.

13. The method of claim 10 , further comprising receiving, via the GUI, user feedback indicating to confirm the discrepancy or dismiss the discrepancy.

14. A system comprising:

one or more computer systems comprising one or more hardware processors, wherein the one or more hardware processors are configured to:

receive organizational asset data of a first organization, wherein the organizational asset data includes data regarding a plurality of assets of different types;

generate an organizational statistical model for the first organization by applying a clustering machine learning algorithm to the organizational asset data to cluster the plurality of assets into clusters according to respective types of the assets;

receive cross-organizational asset data of a second organization, wherein the cross-organizational asset data includes data regarding a plurality of assets of different types associated with at least the second organization;

generate a cross-organizational statistical model associated with the second organization by applying the clustering machine learning algorithm to the cross-organizational asset data to cluster the plurality of assets of the second organization according to respective types of the assets of the second organization;

compare the organizational statistical model with the cross-organizational statistical model to detect a discrepancy between a first asset of the first organization and a second asset of the second organization, wherein the second asset is in a second cluster associated with an asset type, and the first asset is in a first cluster associated with the same asset type; and

output a report summarizing the detected discrepancy.

15. The system of claim 14 , wherein

the discrepancy indicates that the second asset behaved in an unexpected or anomalous manner for assets of the asset type.

16. The system of claim 14 , wherein

the discrepancy is indicated as a security alert was observed for the second asset that is statistically unexpected or anomalous for assets of the asset type.

17. The system of claim 14 , wherein

the cross-organizational statistical model is generated based on statistical data of at least some of the organizational asset data of the first organization.

18. The system of claim 14 , wherein the one or more computer systems are configured to:

receive additional organizational asset data of the first organization, and in response:

updating the cross-organizational statistical model based on the additional organizational asset data.

19. The system of claim 14 , wherein the asset type is a classification of assets based on one or more of:

whether a particular asset is a laptop,

whether a particular asset is a mobile device,

one or more types of software installed on the particular asset,

one or more configuration settings of the particular asset,

a connection history of the particular asset, and

one or more ports used by the particular asset, and

a packet count or bytes transmitted to or from the particular asset.

20. The system of claim 14 , wherein

one or more computer systems are part of a security monitoring system configured to monitor respective security postures of a plurality of networks of a plurality of organizations.

21. The system of claim 20 , wherein

the report is a security report outputted via a graphical user interface (GUI) of the security monitoring system, wherein the GUI is generated on a computer system remote from a first network of the first asset and a second network of the second asset.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2024
From: BARKOVA, EVGENIYA; TSANG, RICHARD; KAZEMEYNI, FATEMEH
To: RAPID7, INC.
Reel/Frame 068702/0773 →
Continuity (2)
Continuation 16548068 · Aug 22, 2019
Related Publication 20240129335A1 · Apr 18, 2024
References Cited (8)
US 10771489B1 · Bisht · 2020 [cited by examiner]
US 20120041575A1 · Maeda · 2012 [cited by examiner]
US 20120166317A1 · Karnik · 2012 [cited by examiner]
US 20150082432A1 · Eaton · 2015 [cited by examiner]
US 20190197411A1 · Di · 2019 [cited by examiner]
US 20200134083A1 · Elliman · 2020 [cited by examiner]
US 20200177633A1 · Shivamoggi · 2020 [cited by examiner]
US 20200267057A1 · Garvey · 2020 [cited by examiner]