IP Library › Granted Patent US 9,503,469
Granted Patent B2
US 9,503,469 · App. 14/794,708 · Granted Nov 22, 2016

Anomaly detection system for enterprise network security

Inventor: Derek Lin (San Mateo, CA)
Assignee: EMC Corporation
H04L63/1425H04L63/1416G06F21/577H04L63/1408H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,503,469
App. No.
14/794,708
Filed
Jul 8, 2015
Granted
Nov 22, 2016
Kind
B2
Art Unit
2492
USPC
726/22
Abstract

Anomaly detection is disclosed, including: determining a set of anomalous events associated with an enterprise network; and determining a path of interest based at least in part on at least a subset of the set of anomalous events.

Claims (40)

1. An anomaly detection system, comprising:

a processor configured to:

determine a set of anomalous events associated with an enterprise network, wherein each of the set of anomalous events is stored with a corresponding plurality of attributes;

determine a path of interest based at least in part on at least a subset of the set of anomalous events, wherein the path of interest includes a series of two or more anomalous events from the set of anomalous events, wherein each anomalous event of the path of interest is determined to be linked to an adjacent anomalous event of the path of interest based at least in part on a shared attribute that the anomalous event shares with the adjacent anomalous event;

assign to each link associated with adjacent anomalous events comprising the path of interest a link score for that link; and

determine an overall score corresponding to the path of interest based at least in part on respective link scores of one or more links comprising the path of interest; and

a memory coupled to the processor and configured to store data associated with the set of anomalous events.

2. The system of claim 1 , wherein one of the set of anomalous events includes an incident suspected as being associated with a security threat.

3. The system of claim 1 , wherein the processor is further configured to collect a plurality of security patterns and determine one or more features for one of the plurality of security patterns.

4. The system of claim 1 , wherein the processor is further configured to:

build a plurality of sensors, wherein one of the plurality of sensors comprises a model trained on historical event data; and

use the plurality of sensors to determine at least the set of anomalous events based at least in part on current event data.

5. The system of claim 4 , wherein the sensor is configured to determine that an event is anomalous based on a threshold score predefined for the sensor.

6. The system of claim 1 , wherein to determine the path of interest includes to use link analysis to determine a link between pairs of anomalous events included in the set of anomalous events.

7. The system of claim 1 , wherein a link score associated with a link between a first anomalous event and a second anomalous event comprising the path of interest is determined based at least in part on at least some of the stored plurality of attributes corresponding to the first anomalous event and at least some of the stored plurality of attributes corresponding to the second anomalous event.

8. A method for anomaly detection, comprising:

determining, by a processor, a set of anomalous events associated with an enterprise network, wherein each of the set of anomalous events is stored with a corresponding plurality of attributes;

determining a path of interest based at least in part on at least a subset of the set of anomalous events, wherein the path of interest includes a series of two or more anomalous events from the set of anomalous events, wherein each anomalous event of the path of interest is determined to be linked to an adjacent anomalous event of the path of interest based at least in part on a shared attribute that the anomalous event shares with the adjacent anomalous event;

assigning to each link associated with adjacent anomalous events comprising the path of interest a link score for that link; and

determining an overall score corresponding to the path of interest based at least in part on respective link scores of one or more links comprising the path of interest.

9. The method of claim 8 , wherein one of the set of anomalous events includes an incident suspected as being associated with a security threat.

10. The method of claim 8 , further comprising collecting a plurality of security patterns and determining one or more features for one of the plurality of security patterns.

11. The method of claim 8 , further comprising:

building a plurality of sensors, wherein one of the plurality of sensors comprises a model trained on historical event data; and

using the plurality of sensors to determine at least the set of anomalous events based at least in part on current event data.

12. The method of claim 11 , wherein the sensor is configured to determine that an event is anomalous based on a threshold score predefined for the sensor.

13. The method of claim 8 , wherein determining the path of interest includes using link analysis to determine a link between pairs of anomalous events included in the set of anomalous events.

14. The method of claim 8 , wherein a link score associated with a link between a first anomalous event and a second anomalous event comprising the path of interest is determined based at least in part on at least some of the stored plurality of attributes corresponding to the first anomalous event and at least some of the stored plurality of attributes corresponding to the second anomalous event.

15. A computer program product for anomaly detection, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

determining a set of anomalous events associated with an enterprise network, wherein each of the set of anomalous events is stored with a corresponding plurality of attributes;

determining a path of interest based at least in part on at least a subset of the set of anomalous events, wherein the path of interest includes a series of two or more anomalous events from the set of anomalous events, wherein each anomalous event of the path of interest is determined to be linked to an adjacent anomalous event of the path of interest based at least in part on a shared attribute that the anomalous event shares with the adjacent anomalous event;

assigning to each link associated with adjacent anomalous events comprising the path of interest a link score for that link; and

determining an overall score corresponding to the path of interest based at least in part on respective link scores of one or more links comprising the path of interest.

16. The computer program product of claim 15 , wherein one of the set of anomalous events includes an incident suspected as being associated with a security threat.

17. The computer program product of claim 15 , further comprising computer instructions for:

building a plurality of sensors, wherein one of the plurality of sensors comprises a model trained on historical event data; and

using the plurality of sensors to determine at least the set of anomalous events based at least in part on current event data.

18. The computer program product of claim 17 , wherein the sensor is configured to determine that an event is anomalous based on a threshold score predefined for the sensor.

19. The computer program product of claim 15 , wherein determining the path of interest includes using link analysis to determine a link between pairs of anomalous events included in the set of anomalous events.

20. The computer program product of claim 15 , wherein link score associated with a link between a first anomalous event and a second anomalous event comprising the path of interest is determined based at least in part on at least some of the stored plurality of attributes corresponding to the first anomalous event and at least some of the stored plurality of attributes corresponding to the second anomalous event.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2015
From: LIN, DEREK
To: EMC CORPORATION
Reel/Frame 036558/0315 →
Continuity (2)
Continuation 13532355 · Jun 25, 2012
Related Publication 20150381646A1 · Dec 31, 2015