IP Library › Granted Patent US 11,924,048
Granted Patent B2
US 11,924,048 · App. 16/619,745 · Granted Mar 5, 2024

Anomaly detection in computer networks

Inventors: Maximilien Servajean (London, GB); Yipeng Cheng (London, GB)
Assignee: British Telecommunications Public Limited Company
H04L41/142G06F18/2193G06F18/23G06F18/295G06N3/047H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,924,048
App. No.
16/619,745
Granted
Mar 5, 2024
Kind
B2
Abstract

A method of anomaly detection for network traffic communicated by devices via a computer network, the method including clustering a set of time series, each time series including a plurality of time windows of data corresponding to network communication characteristics for a device; training an autoencoder for each cluster based on time series in the cluster; generating a set of reconstruction errors for each autoencoder based on testing the autoencoder with data from time windows of at least a subset of the time series; generating a probabilistic model of reconstruction errors for each autoencoder; and generating an aggregation of the probabilistic models for, in use, detecting reconstruction errors for a time series of data corresponding to network communication characteristics for a device as anomalous.

Claims (25)

1. A method of anomaly detection for network traffic communicated by devices via a computer network, the method comprising:

clustering a set of time series, each time series including a plurality of time windows of data corresponding to network communication characteristics for a device and each cluster being defined based on an autoencoder for each cluster converting each time series to a vector of features for the time series and a clustering algorithm clustering the vectors;

training the autoencoder for each cluster based on a time series in the cluster;

generating, for the autoencoder of each cluster, a set of reconstruction errors for the autoencoder based on testing the autoencoder with data from time windows of at least a subset of the time series from which the autoencoder was trained;

generating a probabilistic model of reconstruction errors for each autoencoder; and

generating an aggregation of the probabilistic model for, in use, detecting reconstruction errors for a time series of data corresponding to network communication characteristics for a device as anomalous.

2. The method of claim 1 , wherein the set of reconstruction errors for the autoencoder of each cluster is generated based on the autoencoder processing each time series in a corresponding cluster of time series.

3. The method of claim 1 , wherein each cluster is defined based on a random subdivision of the set of time series.

4. The method of claim 3 , wherein the set of reconstruction errors for the autoencoder of each cluster is generated based on the autoencoder processing each of the time series.

5. The method of claim 1 , wherein each probabilistic model is a Gaussian model of reconstruction errors for the autoencoder of each cluster.

6. The method of claim 5 , wherein the aggregation of the probabilistic model is a Gaussian mixture model.

7. The method of claim 1 , wherein the aggregation of the probabilistic model is a hidden Markov model.

8. A computer system comprising:

a processor and memory storing computer program code for anomaly detection for network traffic communicated by devices via a computer network, by:

clustering a set of time series, each time series including a plurality of time windows of data corresponding to network communication characteristics for a device and each cluster being defined based on an autoencoder for each cluster converting each time series to a vector of features for the time series and a clustering algorithm clustering the vectors;

training an autoencoder for each cluster based on a time series in the cluster;

generating, for the autoencoder of each cluster, a set of reconstruction errors for each autoencoder based on testing a respective autoencoder with data from time windows of at least a subset of the time series from which each respective autoencoder was trained;

generating a probabilistic model of reconstruction errors for the autoencoder; and

generating an aggregation of the probabilistic model for, in use, detecting reconstruction errors for a time series of data corresponding to network communication characteristics for a device as anomalous.

9. A non-transitory computer-readable storage medium storing a computer program element comprising computer program code to, when loaded into a computer system and executed thereon, cause the computer system to perform anomaly detection for network traffic communicated by devices via a computer network, by:

clustering a set of time series, each time series including a plurality of time windows of data corresponding to network communication characteristics for a device and each cluster being defined based on an autoencoder for each cluster converting each time series to a vector of features for the time series and a clustering algorithm clustering the vectors;

training an autoencoder for each cluster based on a time series in the cluster;

generating, for the autoencoder of each cluster, a set of reconstruction errors for the autoencoder based on testing the autoencoder with data from time windows of at least a subset of the time series from which the autoencoder was trained;

generating a probabilistic model of reconstruction errors for each autoencoder; and

generating an aggregation of the probabilistic model for, in use, detecting reconstruction errors for a time series of data corresponding to network communication characteristics for a device as anomalous.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2019
From: SERVAJEAN, MAXIMILIEN; CHENG, YIPENG
To: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
Reel/Frame 051209/0682 →
Priority Claims (1)
EP 17175330 · Jun 9, 2017 · regional
Continuity (1)
Related Publication 20200210782A1 · Jul 2, 2020
Cited By (1)
US 12,676,872