IP Library Patent Application 19212252
Patent Application
App. No. 19/212,252

STATISTICAL ANALYSIS OF NETWORK BEHAVIOR USING EVENT VECTORS TO IDENTIFY BEHAVIORAL ANOMALIES USING A COMPOSITE SCORE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/212,252
Abstract

Examples of the present disclosure describe systems and methods for identifying anomalous network behavior. In aspects, a network event may be observed network sensors. One or more characteristics may be extracted from the network event and used to construct an evidence vector. The evidence vector may be compared to a mapping of previously-identified events and/or event characteristics. The mapping may be represented as one or more clusters of expected behaviors and anomalous behaviors. The mapping may be modeled using analytic models for direction detection and magnitude detection. One or more centroids may be identified for each of the clusters. A “best fit” may be determined and scored for each of the analytic models. The scores may be fused into single binocular score and used to determine whether the evidence vector is likely to represent an anomaly.

Claims (8)

1 . A computer-implemented method for training a model to identify expected network behaviors for anomaly detection, the method comprising:

obtaining training data representative of historical network activity;

generating, by at least one processor, a plurality of evidence vectors based on network characteristics of the training data, wherein each evidence vector represents directional characteristics and magnitude characteristics of a historical network event;

selecting, by the at least one processor, a plurality of prototype vectors to model expected network behaviors;

refining the plurality of prototype vectors by repeatedly performing, for a plurality of the evidence vectors generated based on the training data, the following steps:

identifying, for a respective evidence vector, a corresponding best-fit prototype vector from the plurality of prototype vectors, wherein the identifying is based on a similarity measure that uses the directional characteristics and the magnitude characteristics of the respective evidence vector;

updating the identified best-fit prototype vector to thereby increase its similarity to the respective evidence vector; and

wherein as a result of the refining, the refined prototype vectors represent learned directional and magnitude patterns of expected network behaviors.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2025
From: WRIGHT, WILLIAM; KELLERMAN, GEORGE D.
To: WEBROOT INC.
Reel/Frame 071348/0424 →
CERTIFICATE OF CONVERSION Recorded Jun 6, 2025
From: WEBROOT INC.
To: WEBROOT LLC
Reel/Frame 071510/0166 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jun 6, 2025
From: CARBONITE, LLC
To: OPEN TEXT INC.
Reel/Frame 071510/0178 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Jun 6, 2025
From: WEBROOT LLC
To: CARBONITE, LLC
Reel/Frame 071530/0314 →