IP Library Granted Patent US 10,419,468
Granted Patent B2
US 10,419,468 · App. 15/647,173 · Granted Sep 17, 2019

Cyber security system with adaptive machine learning features

Inventors: John W. Glatfelter (West Chester, PA); William D. Kelsey (Issaquah, WA); Brian D. Laughlin (Wichita, KS)
Assignee: The Boeing Company
H04L63/1425G06F21/316G06F21/552G06F21/554G06N20/00H04L63/1416H04L63/1433H04W12/12H04L63/1491H04W12/00508
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,419,468
App. No.
15/647,173
Filed
Jul 11, 2017
Granted
Sep 17, 2019
Kind
B2
Art Unit
2492
USPC
726/23
Abstract

Systems and methods for a cyber security system with adaptive machine learning features. One embodiment is a system that includes a server configured to manage a plurality of user devices over a network, and a user device that includes an interface and a processor. The interface is configured to communicate with the server over the network, and the processor implements a machine learning function configured to monitor user interactions with the user device over time to establish a use profile, to detect anomalous use of the user device based on a variance from the use profile, to determine whether the anomalous use is representative of a security threat, and to instruct the user device to perform one or more automatic actions to respond to the security threat.

Claims (86)

1. A system comprising:

a server configured to manage cyber security for a plurality of user devices belonging to an enterprise; and

a user device comprising:

an interface component configured to communicate with the server over a network;

a hardware processor that implements a machine learning function configured to monitor user interactions with the user device over time to establish a use profile, to detect anomalous use of the user device based on a variance from the use profile, to input the anomalous use into the machine learning function to determine that the anomalous use is representative of a security threat to the enterprise, to control the user device to automatically initiate recording behavior of the security threat in memory based on an output of the machine learning function, and to report the behavior of the security threat to the server via the interface; and

another user device managed by the server that is associated with the user device,

wherein the machine learning function is configured, in response to detecting the anomalous use of the user device, to send an instruction to the another user device to validate whether an authorized user is in proximity of the another user device, and

wherein the server is configured to analyze the behavior of the security threat to profile attack patterns for the user devices belonging to the enterprise.

2. The system of claim 1 wherein:

the server is configured to detect that the user device is compromised by the security threat, and to postpone invalidating communication of the user device to the server via the network for a period of time; and

the machine learning function operating on the user device is configured to record and report the behavior of the security threat to the server over the network via the interface component during the period of time.

3. The system of claim 1 wherein:

the behavior of the security threat includes one or more of keystroke data, audio data, image data, application use data, or file access request data.

4. The system of claim 1 wherein:

the machine learning function is configured to restrict capability of the user device to enable increased amounts of data collection related to the behavior of the security threat.

5. The system of claim 1 wherein:

the machine learning function is configured to instruct the user device to activate at least one hardware component including one of a microphone, a camera, and a network interface component, and to record the behavior of the security threat by monitoring the at least one hardware component.

6. The system of claim 1 wherein:

the user device includes a wireless interface component; and

the machine learning function is configured to instruct the user device to activate the wireless interface component to spoof a wireless network, to collect information of a wireless device that connects to the wireless network, and to report the information of the wireless device to the server over the network.

7. The system of claim 1 wherein:

the machine learning function is configured to identify sensitive information stored in memory of the user device that is susceptible to the security threat, to identify an incorrect data set in the memory of the user device that is associated with the sensitive information, and to provide the incorrect data set in response to a request to access the sensitive information.

8. The system of claim 7 further comprising:

a remote server that implements a machine learning system configured to receive information regarding the behavior of the security threat, and to provide the incorrect data set for the user device based on a characteristic of the security threat output from the machine learning system.

9. The system of claim 1 wherein:

the hardware processor implements the machine learning function in one of a protected memory on top of an operating system kernel of the user device, or a hardware abstraction layer of the user device.

10. A method comprising:

communicating, via an interface component of a user device, with a server that manages cyber security for a plurality of user devices belonging to an enterprise;

implementing a machine learning function with a processor of the user device;

monitoring user interactions with the user device over time to establish a use profile;

detecting anomalous use of the user device based on a variance from the use profile;

identifying another user device managed by the server that is associated with the user device;

in response to detecting the anomalous use of the user device, sending an instruction to the another user device to validate whether an authorized user is in proximity of the another user device;

determining the anomalous use is representative of a security threat to the enterprise based on input of the anomalous use into the machine learning function;

controlling the user device to automatically initiate recording behavior of the security threat based on an output of the machine learning function;

reporting the behavior of the security threat to the server; and

analyzing, at the server, the behavior of the security threat to profile attack patterns for the user devices belonging to the enterprise.

11. The method of claim 10 further comprising:

responsive to detecting that the user device is compromised by the security threat, postponing, at the server, an invalidation of communication of the user device to the server via a network for a period of time; and

reporting the behavior of the security threat to the server over the network via the interface component during the period of time.

12. The method of claim 10 wherein further comprising:

the behavior of the security threat includes one or more of keystroke data, audio data, image data, application use data, or file access request data.

13. The method of claim 10 further comprising:

identifying sensitive information stored in memory of the user device that is susceptible to the security threat;

identifying an incorrect data set in the memory of the user device that is associated with the sensitive information; and

providing the incorrect data set in response to a request to access the sensitive information.

14. A non-transitory computer readable medium embodying programmed instructions executed by a processor, wherein the instructions direct the processor to:

communicate, via an interface component of a user device, with a server that manages cyber security for a plurality of user devices belonging to an enterprise;

implement a machine learning function with the user device;

monitor user interactions with the user device over time to establish a use profile;

detect anomalous use of the user device based on a variance from the use profile;

identify another user device managed by the server that is associated with the user device;

in response to detecting the anomalous use of the user device, send an instruction to the another user device to validate whether an authorized user is in proximity of the another user device;

determine the anomalous use is representative of a security threat to the enterprise based on input of the anomalous use into the machine learning function;

control the user device to automatically initiate recording behavior of the security threat in memory based on an output of the machine learning function;

report the behavior of the security threat to the server; and

analyze, at the server, the behavior of the security threat to profile attack patterns for the user devices belonging to the enterprise.

15. The computer readable medium of claim 14 wherein the instructions further direct the processor to:

in response to detecting that the user device is compromised by the security threat, postpone, at the server, an invalidation of communication of the user device to the server via a network for a period of time; and

report the behavior of the security threat to the server over the network via the interface component during the period of time.

16. The computer readable medium of claim 14 wherein:

the behavior of the security threat includes one or more of keystroke data, audio data, image data, application use data, or file access request data.

17. The computer readable medium of claim 14 wherein the instructions further direct the processor to:

identify sensitive information stored in memory of the user device that is susceptible to the security threat;

identify an incorrect data set in the memory of the user device that is associated with the sensitive information; and

provide the incorrect data set in response to a request to access the sensitive information.

18. An apparatus comprising:

a hardware processor configured to detect anomalous use of a user device based on historical use of the user device, to identify another user device that is associated with the user device, to send an instruction to the another user device to validate whether an authorized user is in proximity of the another user device in response to detecting the anomalous use of the user device, to input information of the anomalous use into a machine learning function, to determine a characteristic of a cyber threat from an output of the machine learning function, to initiate recording behavior of the cyber threat in memory based on the characteristic, and to report the behavior of the cyber threat to a server that manages cyber security for the user device and other user devices belonging to an enterprise.

19. The apparatus of claim 18 wherein:

the hardware processor is configured, in response to determining that the characteristic of the cyber threat includes a threat to access a type of data via the user device, to instruct the user device to provide disinformation to respond to a request to access the type of data.

20. The apparatus of claim 18 wherein:

the hardware processor is configured, in response to determining that the characteristic of the cyber threat includes a threat to information leakage of data stored in memory of the user device, to instruct the user device to erase the data.

21. The apparatus of claim 18 wherein:

the hardware processor implements the machine learning function in a server that is remote from the user device.

22. A method comprising:

detecting anomalous use of a user device based on historical use of the user device;

identifying another user device that is associated with the user device;

in response to detecting the anomalous use of the user device, sending an instruction to the another user device to validate whether an authorized user is in proximity of the another user device;

inputting information of the anomalous use into a machine learning function;

determining a characteristic of a cyber threat from an output of the machine learning function;

initiate recording behavior of the cyber threat based on the characteristic; and

reporting the behavior of the cyber threat to a server that manages cyber security for the user device and other user devices belonging to an enterprise.

23. The method of claim 22 further comprising:

establishing, with the machine learning function, a communication pattern received by the device over a network interface;

detecting an intrusion event sequence in the communication pattern with the machine learning function; and

generating a graphical simulation of the intrusion event sequence.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 11, 2017
From: GLATFELTER, JOHN W; KELSEY, WILLIAM D; LAUGHLIN, BRIAN D
To: THE BOEING COMPANY
Reel/Frame 042979/0694 →
Continuity (1)
Related Publication 20190020669A1 · Jan 17, 2019
Cited By (115)
US 12,206,696 US 12,231,453 US 12,244,621 US 12,255,915 US 12,261,866 US 12,267,345 US 12,284,197 US 12,309,181 US 12,309,182 US 12,309,185 US 12,309,236 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,381,901 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,272 US 12,452,279 US 12,457,231 US 12,463,994 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,470,599 US 12,483,576 US 12,489,770 US 12,489,771 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,500,927 US 12,505,126 US 12,506,762 US 12,511,110 US 12,513,221 US 12,524,532 US 12,526,297 US 12,531,888 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,554,853 US 12,556,548 US 12,556,550 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,932 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,931 US 12,706,932 US 12,706,933 US 12,706,980 US 12,712,897 US 12,719,896 US 12,726,495 US 12,730,899 US 12,739,266 US 12,739,267 US 12,744,799 US 12,744,800 US 12,744,802