IP Library › Granted Patent US 12,199,996
Granted Patent B1
US 12,199,996 · App. 17/513,304 · Granted Jan 14, 2025

Confidence scoring for detectors used to detect anomalous behavior

Inventors: David Dorsey (Pflugerville, TX); Michael Andrew Hart (Farmington, CT)
Assignee: Cisco Technology, Inc.
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,199,996
App. No.
17/513,304
Filed
Oct 28, 2021
Granted
Jan 14, 2025
Kind
B1
Art Unit
2491
USPC
726/23
Abstract

A computer-implemented method of determining whether to configure a detection comprised within a query is disclosed. The method includes analyzing a query to determine clauses within the query that identify logs relevant to the detection comprised within the query. The method further includes determining a statistical distribution for modeling a likely hit rate of the detection. Additionally, the method includes updating the statistical distribution with information associated with an observed hit rate. Also, the method includes determining a hit rate for the detection using the updated statistical distribution and live telemetry data and computing a confidence score for the detection. Responsive to a determination that the confidence score for the detection is above a predetermined threshold, the method includes maintaining the detection online.

Claims (43)

1. A computer-implemented method of determining whether to configure a detection comprised within a query in a network, the method comprising:

analyzing the query to determine clauses therewithin that identify logs relevant to the detection from a plurality of logs generated by a data intake and query system;

determining a statistical distribution for modeling a hit rate for the detection, wherein the statistical distribution represents a likely hit rate of the detection, wherein the hit rate of the detection comprises a ratio of a number of alerts received from the detection and a number of the plurality of logs;

updating the statistical distribution with information associated with an observed hit rate for the detection to generate an updated statistical distribution representative of the observed hit rate;

determining the hit rate for the detection using the updated statistical distribution and live telemetry data;

computing a confidence score indicative of whether the detection is triggering with an expected frequency; and

responsive to a determination that the confidence score is above a predetermined threshold, configuring the detection to monitor anomalous activity in the network.

2. The computer-implemented method of claim 1 , further comprising:

responsive to a determination that the confidence score is below a predetermined threshold, deactivating the detection for further recalibration.

3. The computer-implemented method of claim 1 , wherein the statistical distribution is selected from a group including a normal distribution, a Poisson distribution, a beta distribution and a Pareto distribution.

4. The computer-implemented method of claim 1 , wherein the live telemetry data comprises security related telemetry data, and wherein the detection is operable to detect potential network security threats.

5. The computer-implemented method of claim 1 , wherein updating the statistical distribution comprises using Bayesian inference methods.

6. The computer-implemented method of claim 1 , wherein the information associated with the observed hit rate comprises samples of the hit rate computed using a count of the logs that are relevant to the detection and using a count of a number of times the detection is triggered.

7. The computer-implemented method of claim 1 , wherein the information associated with the observed hit rate comprises a statistical description of the hit rate.

8. The computer-implemented method of claim 1 , wherein analyzing the query comprises using natural language processing to identify clauses in the query associated with identifying the logs relevant to the detection.

9. The computer-implemented method of claim 1 , wherein determining the hit rate for the detection comprises using a count of the logs relevant to the detection and a count of a number of times the detection is triggered in conjunction with the updated statistical distribution to compute the hit rate.

10. The computer-implemented method of claim 1 , wherein computing a confidence score for the detection comprises:

responsive to a determination the hit rate is below a low threshold and a number of logs above a high threshold have been processed using the live telemetry data, attributing a high confidence score to the detection; and

responsive to a determination the hit rate is above a high threshold and a number of logs below a low threshold have been processed using the live telemetry data, attributing a lower confidence score to the detection.

11. The computer-implemented method of claim 1 , further comprising:

responsive to a determination that the confidence score for the detection is below a predetermined threshold and that the detection is a high-ranked detection, maintaining the detection online.

12. A non-transitory computer-readable medium having computer-readable program code embodied therein for causing a computer system to perform a method of determining whether to configure a detection comprised within a query in a network, the method comprising:

analyzing the query to determine clauses therewithin that identify logs relevant to the detection from a plurality of logs generated by a data intake and query system;

determining a statistical distribution for modeling a hit rate for the detection, wherein the statistical distribution represents a likely hit rate of the detection, wherein the hit rate of the detection comprises a ratio of a number of alerts received from the detection and a number of the plurality of logs;

updating the statistical distribution with information associated with an observed hit rate for the detection to generate an updated statistical distribution representative of the observed hit rate;

determining the hit rate for the detection using the updated statistical distribution and live telemetry data;

computing a confidence score indicative of whether the detection is triggering with an expected frequency; and

responsive to a determination that the confidence score is above a predetermined threshold, configuring the detection to monitor anomalous activity in the network.

13. The non-transitory computer-readable medium of claim 12 , wherein the method further comprises: responsive to a determination that the confidence score is below a predetermined threshold, deactivating the detection for further recalibration.

14. The non-transitory computer-readable medium of claim 12 , wherein the statistical distribution is selected from a group including a normal distribution, a Poisson distribution, a beta distribution, and a Pareto distribution.

15. The non-transitory computer-readable medium of claim 12 , wherein the live telemetry data comprises security related telemetry data, and wherein the detection is operable to detect potential network security threats.

16. The non-transitory computer-readable medium of claim 12 , wherein the information associated with the observed hit rate comprises a statistical description of the hit rate.

17. The non-transitory computer-readable medium of claim 12 , wherein analyzing the query comprises using natural language processing to identify clauses in the query associated with identifying the logs relevant to the detection.

18. A system for performing a method of determining whether to configure a detection comprised within a query in a network, the system comprising:

a processor and a memory configured to:

analyze the query to determine clauses therewithin that identify logs relevant to the detection from a plurality of logs generated by a data intake and query system;

determine a statistical distribution for modeling a hit rate for the detection, wherein the statistical distribution represents a likely hit rate of the detection, wherein the hit rate of the detection comprises a ratio of a number of alerts received from the detection and a number of the plurality of logs;

update the statistical distribution with information associated with an observed hit rate for the detection to generate an updated statistical distribution representative of the observed hit rate;

determine the hit rate for the detection using the updated statistical distribution and live telemetry data;

compute a confidence score indicative of whether the detection is triggering with an expected frequency; and

responsive to a determination that the confidence score is above a predetermined threshold, configuring the detection to monitor anomalous activity in the network.

19. The system of claim 18 , wherein updating the statistical distribution comprises using Bayesian inference methods.

20. The system of claim 18 , wherein the information associated with the observed hit rate comprises samples of the observed hit rate computed using a count of the logs that are relevant to the detection and using a count of a number of times the detection is triggered.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2021
From: DORSEY, DAVID; HART, MICHAEL ANDREW
To: SPLUNK INC.
Reel/Frame 057950/0979 →
References Cited (18)
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 10375095B1 · Turcotte · 2019 [cited by examiner]
US 10645109B1 · Lin · 2020 [cited by examiner]
US 10878428B1 · Comeaux · 2020 [cited by examiner]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20210377288A1 · Chen Kaidi · 2021 [cited by examiner]
US 20220044719A1 · Li · 2022 [cited by examiner]
US 20220329626A1 · Sambamoorthy · 2022 [cited by examiner]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]