IP Library Granted Patent US 12,206,699
Granted Patent B1
US 12,206,699 · App. 18/536,482 · Granted Jan 21, 2025

Identifying high-influence features for model-detected anomalies

Inventors: Jocelyn Beauchesne (Saint-Lormal, FR); John Lim Oh (Mukilteo, WA); Vasudha Shivamoggi (Cambridge, MA); Roy Donald Hodgman (Cambridge, MA)
Assignee: Rapid7, Inc.
H04L63/1425G06N5/04G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,206,699
App. No.
18/536,482
Granted
Jan 21, 2025
Kind
B1
Abstract

An anomaly detection system is disclosed capable of reporting anomalous processes or hosts in a computer network using machine learning models trained using unsupervised training techniques. In embodiments, the system assigns observed processes to a set of process categories based on the file system path of the program executed by the process. The system extracts a feature vector for each process or host from the observation records and applies the machine learning models to the feature vectors to determine an outlier metric each process or host. The processes or hosts with the highest outlier metrics are reported as detected anomalies to be further examined by security analysts. In embodiments, the machine learnings models may be periodically retrained based on new observation records using unsupervised machine learning techniques. Accordingly, the system allows the models to learn from newly observed data without requiring the new data to be manually labeled by humans.

Claims (45)

1. A system comprising:

one or more computing devices that implement an anomaly detection system, configured to:

execute an anomaly detection model on a dataset of observation records about processes executed on individual machines to determine (a) an outlier record in the dataset, and (b) an outlier score of the outlier record, wherein the anomaly detection model is trained using one or more machine learning techniques;

randomly generate a plurality of synthetic observation record as comparison records to use to determine an influence of a set of features on the outlier score, wherein the generation retains one or more features from the outlier record in an individual comparison record and modifies one or more features in the individual comparison record;

execute the anomaly detection model on the comparison records randomly generated to obtain a set of comparison outlier score; and

output a model interpretation result of the outlier record that indicates respective influences of the set of features on the outlier score.

2. The system of claim 1 , wherein the set of features include one or more features that are randomly selected.

3. The system of claim 1 , wherein the set of features include one or more features that are selected according to user-specified configuration.

4. The system of claim 1 , wherein the anomaly detection system is configured to:

output a determination that the outlier record is an anomaly, wherein the output includes the outlier score of the outlier record and the model interpretation result of the outlier record.

5. The system of claim 1 , wherein the anomaly detection system is configured to:

train another version of the anomaly detection model, wherein the other version is trained using a training dataset that reduces a dimensionality of the dataset of observation records used by the anomaly detection model, where the dimensionality reduction is performed based on the model interpretation result.

6. The system of claim 1 , wherein individual ones of the observation records represent respective observations of machines.

7. The system of claim 1 , wherein individual ones of the observation records represent respective types of processes observed on an individual machine.

8. The system of claim 1 , wherein:

the outlier record is encoded as a bit vector;

to generate the individual comparison record, the anomaly detection system is configured to randomly change one or more bits of the bit vector.

9. The system of claim 1 , wherein the model interpretation result includes respective influence metrics of individual ones of the features in the set of features.

10. The system of claim 9 , wherein to determine an influence metric of a feature, the anomaly detection system is configured to:

fit a linear model to approximate the outlier score based on a linear combination of respective outlier scores computed for the comparison records.

11. The system of claim 1 , wherein the anomaly detection system is configured to:

select which features of the outlier record to modify to generate the comparison records based on a feature variability metric of the features in the dataset.

12. The system of claim 1 , wherein the anomaly detection system is implemented as part of a cyberattack monitoring system, configured to:

collect datasets of observation records from the machines in a remote network; and

use the anomaly detection system to detect evidence of cyberattacks in the collected datasets.

13. A method comprising:

performing, by one or more computing devices that implement an anomaly detection system:

executing an anomaly detection model on a dataset of observation records about processes executed on individual machines to determine (a) an outlier record in the dataset, and (b) an outlier score of the outlier record, wherein the anomaly detection model is trained using one or more machine learning techniques;

randomly generating a plurality of synthetic observation record as comparison records to use to determine an influence of a set of features on the outlier score, wherein the generation retains one or more features from the outlier record in an individual comparison record and modifies one or more features in the individual comparison record;

executing the anomaly detection model on the comparison records randomly generated to obtain a set of comparison outlier score; and

outputting a model interpretation result of the outlier record that indicates respective influences of the set of features on the outlier score.

14. The method of claim 13 , wherein the set of features include one or more features that are randomly selected.

15. The method of claim 13 , wherein the set of features include one or more features that are selected according to user-specified configuration.

16. The method of claim 13 , further comprising performing, by the anomaly detection system:

training another version of the anomaly detection model, wherein the other version is trained using a training dataset that reduces a dimensionality of the dataset of observation records used by the anomaly detection model, where the dimensionality reduction is performed based on the model interpretation result.

17. The method of claim 13 , wherein:

the outlier record is encoded as a bit vector;

generating the individual comparison record comprises randomly changing one or more bits of the bit vector.

18. The method of claim 13 , further comprising performing, by the anomaly detection system:

including in the model interpretation result respective influence metrics of individual ones of the features in the set of features.

19. The method of claim 18 , further comprising performing, by the anomaly detection system:

fitting a linear model to approximate the outlier score based on a linear combination of respective outlier scores computed for the comparison records; and

determining an influence metric of a feature based on the linear model.

20. The system of claim 13 , further comprising performing, by the anomaly detection system:

selecting which features of the outlier record to modify to generate the comparison records based on a feature variability metric of the features in the dataset.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2024
From: BEAUCHESNE, JOCELYN; OH, JOHN LIM; SHIVAMOGGI, VASUDHA; HODGMAN, ROY DONALD
To: RAPID7, INC.
Reel/Frame 068702/0680 →
Continuity (1)
Continuation 17967243 · Oct 17, 2022
References Cited (38)
US 7689455B2 · Fligler et al. · 2010 [cited by applicant]
US 7698071B2 · Harris · 2010 [cited by applicant]
US 8838511B2 · Kristal et al. · 2014 [cited by applicant]
US 8948540B2 · Robinson et al. · 2015 [cited by applicant]
US 9210181B1 · Nandy et al. · 2015 [cited by applicant]
US 9843596B1 · Averbuch et al. · 2017 [cited by applicant]
US 9906405B2 · Mankovskii · 2018 [cited by applicant]
US 9910941B2 · Dusanapudi et al. · 2018 [cited by applicant]
US 10235601B1 · Wrenninge et al. · 2019 [cited by applicant]
US 10270788B2 · Faigon et al. · 2019 [cited by applicant]
US 10311368B2 · Lokare et al. · 2019 [cited by applicant]
US 10372910B2 · Martin et al. · 2019 [cited by applicant]
US 10599957B2 · Walters et al. · 2020 [cited by applicant]
US 10645601B2 · Kleinbeck et al. · 2020 [cited by applicant]
US 10743778B2 · Zuckerman-Stark et al. · 2020 [cited by applicant]
US 10846188B2 · Tien et al. · 2020 [cited by applicant]
US 11348034B1 · Jain · 2022 [cited by examiner]
US 11399039B2 · Rubin · 2022 [cited by examiner]
US 20150341376A1 · Nandy et al. · 2015 [cited by applicant]
US 20160036837A1 · Jain et al. · 2016 [cited by applicant]
US 20180096261A1 · Chu et al. · 2018 [cited by applicant]
US 20180153495A1 · Itu et al. · 2018 [cited by applicant]
US 20190124045A1 · Zong et al. · 2019 [cited by applicant]
US 20220038332A1 · Umakanth · 2022 [cited by examiner]
US 20220207434A1 · Xue · 2022 [cited by examiner]
Jonathon Shlens, A Tutorial on Principal Component Analysis, Apr. 7, 2014, Version 3.02, Google Research, Mountain View, CA. [cited by applicant]
Zhang, Li, Ding, & Zhang, Binary Matrix Factorization with Applications, Chinese Academy of Sciences, Florida International University, UT Arlington. [cited by applicant]
Lee, Huang, & Hu, Sparse Logistic Principal Components Analysis for Binary Data, 2010, vol. 4, No. 3, 1579-1601, Institute of Mathematical Statistics. [cited by applicant]
Xie, Li, & Xue, A Survey of Dimensionality Reduction Techniques Based on Random Projection, May 30, 2018. [cited by applicant]
Porwal & Mukund, Credit Card Fraud Detection in e-Commerce: An Outlier Detection Approach, May 7, 2019, ebay Inc., San Jose, CA. [cited by applicant]
Manevitz & Yousef, One-Class SVMs for Document Classification, Journal of Machine Learning Research 2, 139-154, Dec. 1, 2001. [cited by applicant]
Chen & Guestrin, XGBoost: A Scalable Tree Boosting System, Jun. 10, 2016. [cited by applicant]
Snoek, Larochelle, & Adams, Practical Bayesian Optimization of Machine Learning Algorithms. [cited by applicant]
Liu, Lafferty, & Wasserman, Sparse Nonparametric Density Estimation in High Dimensions Using the Rodeo, Carnegie Mellon University, Pittsburgh, PA. [cited by applicant]
Gillis, The Why and How of Nonnegative Matrix Factorization, Mar. 7, 2014, Universite de Mons, Belgium. [cited by applicant]
Candes, Li, Ma, & Wright, Robust Principal Component Analysis, Dec. 17, 2009. [cited by applicant]
Brochu, Cora, & Freitas, A Tutorial on Bayesian Optimization of Expensive Cost Functions, with Application to Active User Modeling and Hierarchical Reinforcement Learning, Dec. 14, 2010. [cited by applicant]
Wu & Charikar, Local Density Estimation in High Dimensions, Sep. 20, 2018. [cited by applicant]