IP Library › Granted Patent US 11,593,714
Granted Patent B2
US 11,593,714 · App. 16/906,119 · Granted Feb 28, 2023

Adaptive anomaly detector

Inventors: Aman Agrawal (Bangalore, IN); Josephine Suganthi Joseph Leo (Sunnyvale, CA); Kasirao Velugu (Bangalore, IN); Praveen Dandin (Fremont, CA); Rama Rao Katta (Fremont, CA); Ratnesh Singh Thakur (San Jose, CA); Seth Kenneth Keith (Scotts Valley, CA); Rakesh Thangellapalli (Milpitas, CA)
Assignee: Citrix Systems, Inc.
G06N20/00G06N3/04G06N3/08H04L63/1416H04L63/1425H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,593,714
App. No.
16/906,119
Granted
Feb 28, 2023
Kind
B2
Abstract

A computer system is provided. The computer system includes a memory, a network interface, and a processor coupled to the memory and the network interface. The processor is configured to receive a response to a request to verify whether an ostensible client of a service is actually a client or a bot, the response including an indicator of whether the ostensible client is a client or a bot; receive information descriptive of interoperations between the ostensible client and the service that are indicative of whether the ostensible client is a client or a bot; and train a plurality of machine learning classifiers using the information and the indicator to generate a next generation of the plurality of machine learning classifiers.

Claims (57)

1. A computer system comprising:

a memory;

a network interface; and

at least one processor coupled to the memory and the network interface and configured to

receive a response to a completely automated public Turing test to tell computers and humans apart (CAPTCHA) challenge to verify whether an ostensible client of a service is actually a client or a bot, the response including an indicator of whether the ostensible client is a client or a bot;

receive information descriptive of interoperations between the ostensible client and the service that are indicative of whether the ostensible client is a client or a bot;

train a plurality of machine learning classifiers using the information and the indicator to generate a next generation of the plurality of machine learning classifiers, wherein the plurality of machine learning classifiers includes a master classifier and one or more community classifiers;

calculate an accuracy of each machine learning classifier of the plurality of machine learning classifiers;

determine whether any community classifier of the next generation of machine learning classifiers has an accuracy that exceeds an accuracy of the master classifier by a first threshold amount; and

replace the master classifier with a particular community classifier of the one or more community classifiers to generate a new master classifier where the accuracy of the particular community classifier exceeds the accuracy of the master classifier by the first threshold amount.

2. The computer system of claim 1 , wherein the information descriptive of the interoperations includes one or more of source Internet Protocol (IP) address, destination IP address, source port, destination port, protocol, total packets exchanged, average inter arrival time of packets, and average time between mouse clicks.

3. The computer system of claim 1 , wherein the plurality of machine learning classifiers comprise a plurality of artificial neural networks.

4. The computer system of claim 1 , wherein the one or more community classifiers comprise a peer classifier, an alpha classifier, and an historical classifier.

5. The computer system of claim 1 , wherein the at least one processor is further configured to:

determine whether any particular machine learning classifier of the next generation of the plurality of machine learning classifiers has an accuracy that transgresses a threshold value based on the accuracy of an ancestor classifier of the particular machine learning classifier; and

replace the particular machine learning classifier with the ancestor classifier where the accuracy of the particular machine learning classifier transgresses the threshold value.

6. The computer system of claim 1 , wherein the at least one processor is further configured to:

identify a first community machine learning classifier of the next generation of the plurality of machine learning classifiers that has an accuracy that exceeds the accuracy of the master classifier by the first threshold amount; and

replace the master classifier with the first community machine learning classifier to generate a new master classifier.

7. The computer system of claim 6 , wherein the at least one processor is further configured to store the master classifier in a data store.

8. The computer system of claim 6 , wherein the plurality of machine learning classifiers are a first plurality of machine learning classifiers and the at least one processor is further configured to add, as a peer classifier, the new master classifier to a second plurality of machine learning classifiers comprising a second master classifier.

9. The computer system of claim 6 , wherein the memory includes an archive, and wherein the at least one processor is further configured to store in the archive the master classifier that was replaced by the first community classifier.

10. The computer system of claim 1 , wherein the at least one processor is further configured to:

determine that the accuracy of a particular community classifier of the next generation of machine learning classifiers has decreased by second threshold amount; and

replace the particular community classifier with a new community classifier.

11. The computer system of claim 1 , wherein the at least one processor is further configured to:

determine whether any particular machine learning classifier of the next generation of the plurality of machine learning classifiers has an accuracy that has decreased below a threshold value based on the accuracy of an ancestor classifier of the particular machine learning classifier; and

replace the particular machine learning classifier with a new machine learning classifier where the accuracy of the particular machine learning classifier has decreased below the threshold value.

12. A method of automatically training a plurality of machine learning classifiers to detect bots, the method comprising:

receiving a response to a completely automated public Turing test to tell computers and humans apart (CAPTCHA) challenge to verify whether an ostensible client of a service is actually a client or a bot, the response including an indicator of whether the ostensible client is a client or a bot;

receiving information descriptive of interoperations between the ostensible client and the service that are indicative of whether the ostensible client is a client or a bot;

training a plurality of machine learning classifiers using the information and the indicator to generate a next generation of the plurality of machine learning classifiers, wherein the plurality of machine learning classifiers includes a master classifier and one or more community classifiers;

calculating an accuracy of each machine learning classifier of the next generation of the plurality of machine learning classifiers;

determining whether any community classifier of the next generation of machine learning classifiers has an accuracy that exceeds an accuracy of the master classifier by a first threshold amount; and

replacing the master classifier with a particular community classifier of the one or more community classifiers to generate a new master classifier where the accuracy of the particular community classifier exceeds the accuracy of the master classifier by the first threshold amount.

13. The method of claim 12 , wherein receiving the information comprising receiving information including one or more of source Internet Protocol (IP) address, destination IP address, source port, destination port, protocol, total packets exchanged, average inter arrival time of packets, and average time between mouse clicks.

14. The method of claim 12 , further comprising:

determining whether any particular machine learning classifier of the next generation of the plurality of machine learning classifiers has an accuracy that transgresses a threshold value based on the accuracy of an ancestor classifier of the particular machine learning classifier; and

replacing the particular machine learning classifier with the ancestor classifier where the accuracy of the particular machine learning classifier transgresses the threshold value.

15. The method of claim 12 , further comprising:

identifying a first community classifier of the next generation of the plurality of machine learning classifiers that has an accuracy that exceeds the accuracy of the master classifier by the first threshold amount; and

replacing the master classifier with the first community classifier to generate a new master classifier.

16. The method of claim 15 , wherein the plurality of machine learning classifiers are a first plurality of machine learning classifiers and the method further comprises adding, as a peer classifier, the new master classifier to a second plurality of machine learning classifiers comprising a second master classifier.

17. The method of claim 15 , further comprising:

storing, in an archive, the master classifier that has been replaced by the first community classifier.

18. The method of claim 12 , further comprising:

determining whether the accuracy of any community classifier of the next generation of machine learning classifiers has decreased by a second threshold amount.

19. The method of claim 18 , further comprising:

determining that the accuracy of a first community classifier of the next generation of the plurality of machine learning classifiers has decreased by the second threshold amount; and

replacing the first community classifier with a new community classifier.

20. A non-transitory computer readable medium storing processor executable instructions to automatically train a plurality of machine learning classifiers, the instructions comprising instructions to:

receive a response to a completely automated public Turing test to tell computers and humans apart (CAPTCHA) challenge to verify whether an ostensible client of a service is actually a client or a bot, the response including an indicator of whether the ostensible client is a client or a bot;

receive information descriptive of interoperations between the ostensible client and the service that are indicative of whether the ostensible client is a client or a bot;

train a plurality of machine learning classifiers using the information and the indicator to generate a next generation of the plurality of machine learning classifiers, wherein the plurality of machine learning classifiers includes a master classifier and one or more community classifiers;

calculate an accuracy of each machine learning classifier of the next generation of the plurality of machine learning classifiers;

determine whether a particular community classifier of the next generation of the plurality of machine learning classifiers has an accuracy that transgresses a threshold value based on the accuracy of the master classifier; and

replace the master classifier with the particular community classifier to generate a new master classifier where the accuracy of the particular community classifier transgresses the threshold value.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2020
From: AGRAWAL, AMAN; JOSEPH LEO, JOSEPHINE SUGANTHI; DANDIN, PRAVEEN; KATTA, RAMA RAO; THAKUR, RATNESH SINGH; KEITH, SETH KENNETH; THANGELLAPALLI, RAKESH; VELUGU, KASIRAO
To: CITRIX SYSTEMS, INC.
Reel/Frame 054251/0241 →
Priority Claims (1)
IN 202011019340 · May 6, 2020 · national
Continuity (1)
Related Publication 20210350277A1 · Nov 11, 2021