IP Library Granted Patent US 12,191,889
Granted Patent B2
US 12,191,889 · App. 18/436,045 · Granted Jan 7, 2025

Data compression with signature-based intrusion detection

Inventors: Joshua Cooper (Columbia, SC); Charles Yeomans (Orinda, CA)
Assignee: ATOMBEAM TECHNOLOGIES INC
H03M7/3059G06N20/00H03M7/6005
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,191,889
App. No.
18/436,045
Filed
Feb 8, 2024
Granted
Jan 7, 2025
Kind
B2
Art Unit
2498
USPC
707/693
Abstract

A system and method for data compression with intrusion detection, that measures in real-time the probability distribution of an encoded data stream, compares the probability distribution to a reference probability distribution, and uses one or more statistical algorithms to determine the divergence between the two sets of probability distributions to determine if an unusual distribution is the result of a data intrusion. The system further comprises a signature generating component which correlates anomalous event data with known vulnerabilities and exploits to create a signature based on statistical information of the anomalous event. Computed statistics may be compared against a signature database to determine if a data intrusion has occurred.

Claims (49)

1. A system for data compression with intrusion detection, comprising:

a plurality of computing devices each comprising at least a processor, a memory, and a network interface;

wherein a plurality of programming instructions stored in one or more of the memories and operating on one or more of the processors of the plurality of computing devices causes the plurality of computing devices to:

receive anomalous event data, the anomalous event data comprising a computed divergence of a data stream, a computed first probability distribution of the data stream, and one or more codewords;

compare the anomalous event data to a database, the database comprising a plurality of signatures, the plurality of signatures comprising statistical information associated with a plurality of known vulnerabilities;

when the comparison yields a match:

generate an intrusion alert, the intrusion alert comprising the anomalous event data; and

send the intrusion alert to a security monitoring system.

2. The system of claim 1 , wherein the plurality of programming instructions further causes the plurality of computing devices to:

receive a first codeword data stream;

compute the first probability distribution of a plurality of codewords within the first codeword data stream; and

compute the divergence between the first computed probability distribution and a reference probability distribution.

3. The system of claim 1 , wherein the plurality of programming instructions further causes the plurality of computing devices to:

obtain a plurality of historical anomalous event data;

obtain threat intelligence data, the threat intelligence data comprising at least the plurality of known vulnerabilities and known malicious actor information;

generate a signature for a known malicious actor based on the plurality of historical anomalous event data and the plurality of known vulnerabilities; and

store the signature in the database.

4. The system of claim 3 , wherein the signature comprises statistical information associated with a known vulnerability, the statistical information being derived from the historical anomalous event data.

5. The system of claim 4 , wherein the statistical information comprises at least a historical divergence and a historical probability distribution.

6. The system of claim 3 wherein the plurality of programming instructions further causes the plurality of computing devices to:

when the comparison does not yield a match:

generate a signature associated with the received anomalous event data; and

store the signature in the database.

7. A method for data compression with intrusion detection, comprising the steps of:

receiving anomalous event data, the anomalous event data comprising a computed divergence of a data stream, a computed first probability distribution of the data stream, and one or more codewords;

comparing the anomalous event data to a database, the database comprising a plurality of signatures, the plurality of signatures comprising statistical information associated with a plurality of known vulnerabilities;

when the comparison yields a match:

generating an intrusion alert, the intrusion alert comprising the anomalous event data; and

sending the intrusion alert to a security monitoring system.

8. The method of claim 7 , further comprising the steps of:

receiving a first codeword data stream;

computing the first probability distribution of a plurality of codewords within the first codeword data stream; and

computing the divergence between the first computed probability distribution and a reference probability distribution.

9. The method of claim 7 , further comprising the steps of:

obtaining a plurality of historical anomalous event data;

obtaining threat intelligence data, the threat intelligence data comprising at least the plurality of known vulnerabilities and known malicious actor information;

generating a signature for a known malicious actor based on the plurality of historical anomalous event data and the plurality of known vulnerabilities; and

storing the signature in the database.

10. The method of claim 9 , wherein the signature comprises statistical information associated with a known vulnerability, the statistical information being derived from the historical anomalous event data.

11. The method of claim 10 , wherein the statistical information comprises at least a historical divergence and a historical probability distribution.

12. The method of claim 9 further comprising the steps of:

when the comparison does not yield a match:

generating a signature associated with the received anomalous event data; and

storing the signature in the database.

13. A non-transitory computer-readable medium comprising a plurality of programming instructions that, when operating on a plurality of computing devices each comprising at least a processor, a memory, and a network interface, cause the plurality of computing devices to:

receive anomalous event data, the anomalous event data comprising a computed divergence of a data stream, a computed first probability distribution of the data stream, and one or more codewords;

compare the anomalous event data to a database, the database comprising a plurality of signatures, the plurality of signatures comprising statistical information associated with a plurality of known vulnerabilities; and

when the comparison yields a match:

generate an intrusion alert, the intrusion alert comprising the anomalous event data; and send the intrusion alert to a security monitoring system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 28, 2024
From: COOPER, JOSHUA; YEOMANS, CHARLES
To: ATOMBEAM TECHNOLOGIES INC.
Reel/Frame 068433/0106 →
Continuity (21)
Continuation In Part 18460553 · Sep 3, 2023
Continuation In Part 18161080 · Jan 29, 2023
Continuation 17875201 · Jul 27, 2022
Continuation 17514913 · Oct 29, 2021
Continuation 17458747 · Aug 27, 2021
Continuation In Part 17404699 · Aug 17, 2021
Continuation In Part 17234007 · Apr 19, 2021
Continuation In Part 17180439 · Feb 19, 2021
Continuation In Part 16923039 · Jul 7, 2020
Continuation In Part 16923039 · Jul 7, 2020
Continuation In Part 16716098 · Dec 16, 2019
Continuation 16455655 · Jun 27, 2019
Continuation In Part 16455655 · Jun 27, 2019
Continuation In Part 16200466 · Nov 26, 2018
Continuation In Part 15975741 · May 9, 2018
Provisional Application 63485514 · Feb 16, 2023
Provisional Application 63140111 · Jan 21, 2021
Provisional Application 63027166 · May 19, 2020
Provisional Application 62926723 · Oct 28, 2019
Provisional Application 62578824 · Oct 30, 2017
Related Publication 20240214003A1 · Jun 27, 2024
References Cited (29)
US 9117069B2 · Oliphant · 2015 [cited by examiner]
US 9294589B2 · Crosta et al. · 2016 [cited by applicant]
US 9954920B1 · Paris · 2018 [cited by examiner]
US 10897479B1 · Chen · 2021 [cited by examiner]
US 10984423B2 · Adjaoute · 2021 [cited by examiner]
US 11470182B1 · Virtser · 2022 [cited by examiner]
US 20050248457A1 · Himberger · 2005 [cited by examiner]
US 20140041032A1 · Scheper · 2014 [cited by examiner]
US 20140270404A1 · Hanna · 2014 [cited by examiner]
US 20160155069A1 · Hoover · 2016 [cited by examiner]
US 20170272100A1 · Yanovsky · 2017 [cited by examiner]
US 20180053114A1 · Adjaoute · 2018 [cited by examiner]
US 20190129640A1 · Riahi · 2019 [cited by examiner]
US 20200293653A1 · Huang · 2020 [cited by examiner]
US 20200382281A1 · Fletcher · 2020 [cited by examiner]
US 20210004677A1 · Menick · 2021 [cited by examiner]
US 20210352092A1 · Deardorff · 2021 [cited by examiner]
US 20220171857A1 · McHugh · 2022 [cited by examiner]
US 20220210167A1 · Rajagopalan · 2022 [cited by examiner]
US 20220417282A1 · Jain · 2022 [cited by examiner]
US 20230022279A1 · Vasilenko · 2023 [cited by examiner]
US 20230138035A1 · Lott · 2023 [cited by examiner]
US 20230140918A1 · Saxena · 2023 [cited by examiner]
US 20230246814A1 · Fromm · 2023 [cited by examiner]
US 20230336581A1 · Dunn · 2023 [cited by examiner]
CN 112989334A · 2021 [cited by examiner]
EP 3729768A1 · 2018 [cited by examiner]
WO WO2019122241A1 · 2019 [cited by examiner]
WO WO2020176066A1 · 2020 [cited by examiner]