IP Library Granted Patent US 12,073,293
Granted Patent B2
US 12,073,293 · App. 16/937,568 · Granted Aug 27, 2024

Machine learning model evaluation in cyber defense

Inventors: Eamon Hirata Jordan (Honolulu, HI); Chad Kumao Takahashi (Honolulu, HI); Ryan Susumu Ito (Wahiawa, HI)
Assignee: Resurgo, LLC
G06N20/00G06F21/552G06N7/01H04L43/08H04L43/16H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,073,293
App. No.
16/937,568
Granted
Aug 27, 2024
Kind
B2
Abstract

Testing machine learning sensors by adding obfuscated training data to test data, and performing real time model fit analysis on live network traffic to determine whether to retrain.

Claims (16)

1. A process for improving sensors that use machine learning models previously trained on previous training data, for defending a computer network against cyber attacks in live network traffic that contains both normal network traffic and said cyber attacks, to determine more accurately whether and when to react to intrusion detection alert logs, comprising:

installing said sensors in said computer network;

determining model fit of said models by applying techniques of anomaly detection, measuring similarity between said live network traffic and said previous training data, and determining model overfit;

assigning thresholds, and aggregating results of whether said models are above or below said thresholds, for each of said techniques of anomaly detection, measuring similarity between said live network traffic and said previous training data, and determining model overfit, to identify model fit in real time of said live network traffic with said previous training data on a scale of model fits;

activating model retraining based on said scale of model fits, wherein said model retraining selects an optimal model for distinguishing between said cyber attacks and said normal network traffic; and

reinstalling said optimal model in said sensors, to perform real time evaluation of said live network traffic, including anomaly detection,

wherein said model retraining step is performed by:

obtaining samples of said normal network traffic from said network;

providing samples of said cyber attacks from said network or from a repository of cyber attacks, wherein said samples of cyber attacks constitute known attacks;

sample classifying each of said samples as either said normal network traffic or said known attacks, to create ground truths for said samples;

splitting said samples into a training set and a test set, with each of said sets containing samples of said normal network traffic and said known attacks;

using a model generating algorithm to generate a variety of models for distinguishing between said normal network traffic and said known attacks in said training set;

obfuscating a portion of said known attacks in said training set to create obfuscated attack samples;

adding said obfuscated attack samples to said test set to form an enhanced test set;

performing statistical analysis on performance of said models with said enhanced test set to determine intrusion detection capability error; and

selecting one of said models that optimizes a desired model parameter as said optimal model.

Continuity (2)
Division 15373425 · Dec 8, 2016
Related Publication 20200364620A1 · Nov 19, 2020