IP Library Granted Patent US 12,237,979
Granted Patent B2
US 12,237,979 · App. 18/629,589 · Granted Feb 25, 2025

Multi-baseline unsupervised security-incident and network behavioral anomaly detection in cloud-based compute environments

Inventors: Nitzan Niv (Nesher, IL); Gad Naor (Tel-Aviv, IL)
Assignee: Rapid7 Israel Technologies Ltd.
H04L41/142G06F9/546G06N5/01G06N20/00G06Q30/0271H04L41/069H04L41/145H04L43/062H04L63/102H04L63/104H04L63/1416H04L63/1425H04L63/1441H04L67/30H04L67/535H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,237,979
App. No.
18/629,589
Granted
Feb 25, 2025
Kind
B2
Abstract

A method and system for detecting anomalous network activity in a cloud-based compute environment. The method comprises receiving configuration data and network activity observations for a set of virtual entities in the cloud-based compute environment; creating a profile for each virtual entity in the set of virtual entities, when the virtual entity does not already have an associated profile; dynamically updating the virtual entity of a profile with the respective network activity observations of the virtual entity; and determining whether anomalies have been detected.

Claims (36)

1. A system for detecting anomalous network behavior in a cloud-based computing environment by using profiles indicating expected network behavior associated with virtual entities, the system comprising:

at least one computer hardware processor configured to perform:

receiving network activity observations for a monitored virtual entity hosted in the cloud-based computing environment, the monitored virtual entity being associated with a corresponding entity profile indicating expected network behavior associated with the virtual entity;

detecting anomalous network behavior by the monitored virtual entity by identifying deviations between the received network activity observations for the monitored virtual entity and the entity profile;

determining that the anomalous network behavior indicates a security incident; and

generating a report indicating the security incident and the anomalous network behavior.

2. The system of claim 1 , wherein the monitored virtual entity is a virtual machine hosted on a physical host of the cloud-based computing environment.

3. The system of claim 1 , further comprising:

updating the entity profile for the monitored virtual entity using the network activity observations to obtain an updated entity profile for the monitored virtual entity.

4. The system of claim 3 , wherein detecting the anomalous network behavior by the monitored virtual entity comprises comparing the updated entity profile for the monitored virtual entity with the entity profile.

5. The system of claim 3 ,

wherein the entity profile includes one or more probabilistic distributions over a corresponding one or more factors, each of the one or more factors representing an aspect of behavior of the monitored virtual entity,

wherein updating the entity profile for the monitored virtual entity comprises updating the one or more probabilistic distributions based on the network activity observations.

6. The system of claim 5 , wherein the one or more factors includes multiple factors and the entity profile describes conditional relationships among the multiple factors.

7. The system of claim 6 , wherein the entity profile represents the conditional relationships among the multiple factors using a directed acyclic graph.

8. The system of claim 1 , further comprising initiating one or more mitigation actions to mitigate the anomalous network behavior.

9. At least one non-transitory computer readable storage medium storing processor executable instructions that, when executed by at least one computer hardware processor, cause the at least one computer hardware processor to perform a method for detecting anomalous network behavior in a cloud-based computing environment by using profiles indicating expected network behavior associated with virtual entities, the method comprising:

receiving network activity observations for a monitored virtual entity hosted in the cloud-based computing environment, the monitored virtual entity being associated with a corresponding entity profile indicating expected network behavior associated with the virtual entity;

detecting anomalous network behavior by the monitored virtual entity by identifying deviations between the received network activity observations for the monitored virtual entity and the entity profile;

determining that the anomalous network behavior indicates a security incident; and

generating a report indicating the security incident and the anomalous network behavior.

10. The at least one non-transitory computer readable storage medium of claim 9 , wherein the monitored virtual entity is a virtual machine hosted on a physical host of the cloud- based computing environment.

11. The at least one non-transitory computer readable storage medium of claim 9 , further comprising:

updating the entity profile for the monitored virtual entity using the network activity observations to obtain an updated entity profile for the monitored virtual entity.

12. The at least one non-transitory computer readable storage medium of claim 11 , wherein detecting the anomalous network behavior by the monitored virtual entity comprises comparing the updated entity profile for the monitored virtual entity with the entity profile.

13. The at least one non-transitory computer readable storage medium of claim 12 , wherein the one or more factors includes multiple factors and the entity profile describes conditional relationships among the multiple factors.

14. The at least one non-transitory computer readable storage medium of claim 13 , wherein the entity profile represents the conditional relationships among the multiple factors using a directed acyclic graph.

15. The at least one non-transitory computer readable storage medium of claim 11 ,

wherein the entity profile includes one or more probabilistic distributions over a corresponding one or more factors, each of the one or more factors representing an aspect of behavior of the monitored virtual entity,

wherein updating the entity profile for the monitored virtual entity comprises updating the one or more probabilistic distributions based on the network activity observations.

16. The at least one non-transitory computer readable storage medium of claim 9 , further comprising initiating one or more mitigation actions to mitigate the anomalous network behavior.

17. A system for detecting anomalous network behavior in a cloud-based computing environment by using profiles indicating expected network behavior associated with virtual entities, the system comprising:

at least one computer hardware processor configured to perform:

receiving network activity observations for a monitored virtual entity hosted in the cloud-based computing environment, the monitored virtual entity being associated with a corresponding entity profile indicating expected network behavior associated with the virtual entity;

detecting anomalous network behavior by the monitored virtual entity by identifying deviations between the received network activity observations for the monitored virtual entity and the entity profile; and

generating a report indicating the anomalous network behavior.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 29, 2025
From: RAPID7 ISRAEL TECHNOLOGIES LTD.
To: INTSIGHTS CYBER INTELLIGENCE LTD.
Reel/Frame 072728/0596 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2024
From: NIV, NITZAN; NAOR, GAD
To: RAPID7 ISRAEL TECHNOLOGIES LTD
Reel/Frame 069591/0518 →
Continuity (4)
Continuation 18446402 · Aug 8, 2023
Continuation 17590221 · Feb 1, 2022
Continuation 16263322 · Jan 31, 2019
Related Publication 20240259271A1 · Aug 1, 2024
References Cited (16)
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 11425149B2 · Niv et al. · 2022 [cited by applicant]
US 11818014B2 · Niv et al. · 2023 [cited by applicant]
US 20130305357A1 · Ayyagari · 2013 [cited by examiner]
US 20160078365A1 · Baumard · 2016 [cited by examiner]
US 20170262325A1 · Liisberg · 2017 [cited by applicant]
US 20180047065A1 · Wildberger · 2018 [cited by examiner]
US 20190132344A1 · Lem et al. · 2019 [cited by applicant]
US 20200057956A1 · Phan · 2020 [cited by examiner]
US 20200195670A1 · Deardorff · 2020 [cited by examiner]
US 20200252416A1 · Niv et al. · 2020 [cited by applicant]
US 20220159025A1 · Niv et al. · 2022 [cited by applicant]
US 20230388195A1 · Niv et al. · 2023 [cited by applicant]
Rienstra, Ranked Programming. Ranking Theory. Aug. 2018. 7 pages. [cited by applicant]
Scarfone et al., Guide to intrusion detection and prevention systems (idps). NIST special publication. Feb. 20, 2007;800(2007):94:1-127. [cited by applicant]
Spohn et.al., A Survey of Ranking Theory. KOPS—Konstanzer Online Publications, 2009:185-228. [cited by applicant]
Cited By (1)
US 12,711,391