IP Library Granted Patent US 11,501,013
Granted Patent B1
US 11,501,013 · App. 17/860,196 · Granted Nov 15, 2022

Autonomous machine learning methods for detecting and thwarting malicious database access

Inventors: Purandar Gururaj Das (Lexington, MA); Shanthi Boppana (Boxborough, MA)
Assignee: Sotero, Inc.
G06F21/6218G06F21/566G06N20/00G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,501,013
App. No.
17/860,196
Granted
Nov 15, 2022
Kind
B1
Abstract

An anomaly detection method includes receiving, at a processor, a request including a query that references a database. A plurality of attributes is identified based on the request. The processor concurrently processes the query to identify a result, and analyzes the plurality of attributes to identify an anomaly score. When the anomaly score exceeds a first predefined threshold, a signal representing a quarantine request is sent, and a signal representing the result is not sent. When the anomaly score is between the first predefined threshold and a second predefined threshold, a signal representing a notification and a signal representing the result are sent. When the anomaly score is below the second predefined threshold, a signal representing a quarantine request is sent, and a signal representing the result is not sent.

Claims (41)

1. A method for detecting malicious database access, the method comprising:

receiving, at a processor, a request including a database query that references a database;

identifying, via the processor, a plurality of attributes associated with the database query;

concurrently (1) processing the database query, during a first time period, to identify a result, and (2) analyzing the identified plurality of attributes during the first time period, using a self-learning machine learning algorithm, to identify an aggregate anomaly score for anomaly detection based on a plurality of different predefined thresholds;

in response to the aggregate anomaly score exceeding a first predefined threshold from the plurality of different predefined thresholds and during a second time period subsequent to the first time period:

sending a signal, via the processor, representing a quarantine request, and

not sending a signal representing the result,

in response to the aggregate anomaly score being between the first predefined threshold and a second predefined threshold from the plurality of different predefined thresholds during the second time period:

sending a signal, via the processor, representing a notification, and

sending a signal representing the result, and

in response to the aggregate anomaly score being below the second predefined threshold during the second time period:

sending a signal, via the processor, representing a quarantine request, and

not sending a signal representing the result.

2. The method of claim 1 , wherein the aggregate anomaly score is determined based on a plurality of locality-sensitive hash functions.

3. The method of claim 1 , wherein the aggregate anomaly score is identified within between about 25 milliseconds (ms) and about 50 ms of receiving the request.

4. The method of claim 1 , wherein the aggregate anomaly score is identified substantially in real time relative to receiving the request.

5. The method of claim 1 , wherein the analyzing the plurality of attributes is performed without reference to an allow-list or a deny-list.

6. The method of claim 1 , wherein the plurality of attributes includes at least one of: a user identifier, a source application, a timestamp, an internet protocol (IP) address, a geographic location, a target object, a query type, an amount of data being requested, a command type, or a number of queries including the database query and within a predefined time period.

7. The method of claim 1 , wherein the database query is a range query.

8. The method of claim 1 , wherein the database is an encrypted database.

9. The method of claim 8 , wherein an encryption of the encrypted database includes one of a deterministic encryption, an order-preserving encryption, or a numeric encryption.

10. A non-transitory, processor-readable storage medium storing processor device executable instructions for detecting malicious database access, the processor device executable instructions including instructions to:

receive a request including a representation of a database query transaction for an encrypted database;

identify a plurality of attributes associated with the database query;

process the database query, during a first time period, to identify a result;

analyze concurrently the identified plurality of attributes during the first time period, using a self-learning machine learning algorithm, to identify an aggregate anomaly score for anomaly detection based on a plurality of different predefined thresholds;

during a second time period subsequent to the first time period, and in response to the aggregate anomaly score exceeding a first predefined threshold from the plurality of different predefined thresholds:

send a signal representing a quarantine request, without sending a signal representing the result,

during the second time period, and in response to the aggregate anomaly score being between the first predefined threshold and a second predefined threshold from the plurality of different predefined thresholds:

send a signal representing a notification, and

send a signal representing the result, and

during the second time period, and in response to the aggregate anomaly score being below the second predefined threshold:

send a signal representing a quarantine request, without sending a signal representing the result.

11. The non-transitory, processor-readable medium of claim 10 , wherein the instructions to analyze the plurality of attributes include instructions to analyze the plurality of attributes based on a weighted score.

12. The non-transitory, processor-readable medium of claim 10 , wherein the instructions to analyze the plurality of attributes include instructions to analyze the plurality of attributes without applying a filter.

13. The non-transitory, processor-readable medium of claim 10 , wherein the instructions to analyze the plurality of attributes include instructions to analyze the plurality of attributes without referencing any predefined rule.

14. The non-transitory, processor-readable medium of claim 10 , wherein the aggregate anomaly score is determined based on a plurality of locality-sensitive hash functions.

15. The non-transitory, processor-readable medium of claim 10 , wherein the instructions to analyze the plurality of attributes include instructions to analyze the plurality of attributes without referencing an allow-list or a deny-list.

16. The non-transitory, processor-readable medium of claim 10 , wherein an encryption of the encrypted database includes one of a deterministic encryption, an order-preserving encryption, or a numeric encryption.

17. The non-transitory, processor-readable medium of claim 10 , wherein the request includes a range query.

18. The non-transitory, processor-readable medium of claim 10 , further storing processor device executable instructions to log the request without logging the result.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2022
From: DAS, PURANDAR GURURAJ; BOPPANA, SHANTHI
To: SOTERO, INC.
Reel/Frame 060683/0799 →
Continuity (1)
Provisional Application 63219933 · Jul 9, 2021
Cited By (4)
US 12,223,075 US 12,346,440 US 12,556,539 US 12,639,470