IP Library › Granted Patent US 12,244,617
Granted Patent B2
US 12,244,617 · App. 18/347,498 · Granted Mar 4, 2025

Machine learning based anomaly detection initialization

Inventors: Jeevan Tambuluri (Santa Clara, CA); Ravi Ithal (Los Altos, CA); Steve Malmskog (San Jose, CA); Abhay Kulkarni (Cupertino, CA); Ariel Faigon (Santa Clara, CA); Krishna Narayanaswamy (Saratoga, CA)
Assignee: Netskope, Inc.
H04L63/1416G06F21/554G06F21/6209G06N5/02G06N7/01G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,617
App. No.
18/347,498
Filed
Jul 5, 2023
Granted
Mar 4, 2025
Kind
B2
Art Unit
2494
USPC
726/23
Abstract

The technology relates to machine responses to anomalies detected using machine learning based anomaly detection. In particular, to receiving evaluations of production events, prepared using activity models constructed on per-tenant and per-user basis using an online streaming machine learner that transforms an unsupervised learning problem into a supervised learning problem by fixing a target label and learning a regressor without a constant or intercept. Further, to responding to detected anomalies in near real-time streams of security-related events of tenants, the anomalies detected by transforming the events in categorized features and requiring a loss function analyzer to correlate, essentially through an origin, the categorized features with a target feature artificially labeled as a constant. An anomaly score received for a production event is determined based on calculated likelihood coefficients of categorized feature-value pairs and a prevalencist probability value of the production event comprising the coded features-value pairs.

Claims (69)

1. A method of initializing an anomaly detector that handles a stream of security-related events of one or more organizations, the method comprising:

feeding, to an online machine learner, the stream of security-related events, each security-related event comprising a space identifier (ID) of a plurality of space IDs and one or more feature-value pairs;

transforming the security-related events, the transforming comprising:

assigning the one or more feature-value pairs of each security-related event in the stream of security-related events into a plurality of categorical bins, and

coding the assigned feature-value pairs with a Boolean value representing the feature-value pair associated with the respective categorical bins of the plurality of categorical bins;

analyzing the stream of transformed security-related events using a loss function analyzer of the online machine learner, the analyzing comprising:

grouping transformed security-related events in the stream of transformed security-related events into sub-streams by the space ID of the respective transformed security-related event, and

separately analyzing each sub-stream with the loss function analyzer, the analyzing comprising:

correlating the coded feature-value pairs of the sub-stream with a target feature artificially labeled as a constant to generate a probability prediction for each of the coded feature-value pairs; and

storing the probability predictions for each of the coded feature-value pairs associated with the space ID associated with the respective sub-stream; and

initializing the anomaly detector using the probability predictions.

2. The method of claim 1 , wherein during a training period a majority of feature-value pairs are assigned to at least two categorical bins of the plurality of categorical bins.

3. The method of claim 1 , wherein:

the separately analyzing each sub-stream further comprises:

calculating likelihood coefficients for the coded feature-value pairs based on the probability prediction, the likelihood coefficients indicating a probability of a feature of the feature-value pair having the corresponding value, and

using the likelihood coefficients to determine prevalencist probability values for corresponding security-related events that include the coded feature-value pairs, the prevalencist probability values indicating an occurrence frequency of the corresponding security related events;

the storing the probability prediction comprises storing the likelihood coefficients and the prevalencist probability values for each of the coded feature-value pairs by the space ID associated with the respective sub-stream; and

the initializing the anomaly detector further uses the likelihood coefficients and the prevalencist probability values.

4. The method of claim 3 , further comprising:

storing the likelihood coefficients and the prevalencist probability values for multiple space IDs of the plurality of space IDs in a hash-space as a tenant activity model indicative of activity habits of users in an organization, wherein the multiple space IDs are associated with the organization; and

updating the tenant activity model with new security-related events from the stream of security-related events having one of the multiple space IDs to incorporate changes to the activity habits.

5. The method of claim 3 , further comprising:

storing the likelihood coefficients and the prevalencist probability values for a particular space ID of the plurality of space IDs in a hash-space as a user activity model, indicative of activity habits of a user; and

updating the user activity model with new security-related events from the stream of security-related events having the particular space ID to incorporate changes to the activity habits.

6. The method of claim 3 , further comprising:

accumulating non-zero likelihood coefficients for frequently appearing feature-value pairs;

updating likelihood coefficients of individual feature-value pairs during the correlating; and

converging over time the likelihood coefficients of the frequently appearing feature-value pairs to match likelihood coefficients of the target feature.

7. The method of claim 3 , further comprising:

determining a relative-error ratio for a particular security-related event of the stream of security-related events with a particular space ID based on a predicted prevalencist probability value of the particular security-related event and an observed prevalencist probability value of the particular security-related event;

determining a standard candle value for the particular space ID based on a maximum likelihood coefficient feature-value pair in the particular security-related event;

evaluating likelihood coefficients of individual feature-value pairs in the particular security-related event and determining one or more lowest likelihood coefficient feature-value pairs in the particular security-related event;

calculating an overall likelihood coefficient for the particular security-related event based on the lowest likelihood coefficient feature-value pairs; and

determining the particular security-related event to be an anomaly event when the relative-error ratio, the standard candle value and the overall likelihood coefficient exceed a threshold.

8. The method of claim 7 , further comprising:

distinguishing between a seasoned user and an unseasoned user, the distinguishing comprising:

initializing and analyzing a second particular space ID of the plurality of space IDs using the loss function analyzer with the standard candle value for the second particular space ID; and

maturing the standard candle value of the second particular space ID to a target value responsive to a threshold number of security-related events received in the stream of security-related events having the second particular space ID.

9. The method of claim 8 , wherein seasoned space IDs have non-zero standard candle values and unseasoned space IDs have near-zero standard candle values.

10. The method of claim 1 , further comprising annotating the security-related events with prevalencist probability values of between 0 to 1, indicative of an occurrence frequency of the security-related events.

11. The method of claim 1 , wherein the loss function analyzer is a stochastic gradient descent (SGD) analyzer.

12. The method of claim 3 , further comprising:

storing the likelihood coefficients annotated with corresponding coded feature-value pairs in respective slots of a hash space; and

retrieving the likelihood coefficients for anomaly detection by applying a hash function to the coded feature-value pairs.

13. The method of claim 1 , wherein the security-related events include connection events and application events.

14. The method of claim 1 , further comprising:

learning user-specific activity habits based on the separate analysis of the sub-streams by the space ID; and

persisting in a hash-space separate user-states based on the learned user-specific activity habits, representing occurrence frequencies of all past events for individual users.

15. The method of claim 1 , further comprising:

updating tenant and user activity models over time, including maturing and storing frequently occurring anomalous events as normal user activity.

16. The method of claim 1 , wherein the online machine learner is an online streaming processer that learns features for 5,000 to 50,000 security-related events per second per hardware node.

17. The method of claim 1 , wherein the online machine learner is an online streaming processer that processes 50,000 to 5 million features per second per hardware node.

18. The method of claim 1 , wherein features of the feature-value pairs include:

one or more time dimensions;

a source location dimension;

a source Internet Protocol (IP) address dimension;

a destination location dimension;

a destination IP address dimension;

a source device identity dimension;

an application used dimension;

an activity type and detail dimension;

a manipulated object dimension; or

a combination thereof.

19. The method of claim 1 , further comprising:

assigning time-based features of the security-related events into multiple sets of periodic bins with varying granularity.

20. The method of claim 19 , wherein assigning the time-based features comprises assigning the time-based features into at least one:

day-of-week periodic bin with seven distinct values;

time-of-day periodic bin with twenty-four distinct values; and

part-of-day periodic bin with six distinct values.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 21, 2024
From: FAIGON, ARIEL; NARAYANASWAMY, KRISHNA; TAMBULURI, JEEVAN; ITHAL, RAVI; MALMSKOG, STEVE; KULKARNI, ABHAY
To: NETSKOPE, INC.
Reel/Frame 066860/0776 →
Continuity (5)
Continuation 17332879 · May 27, 2021
Continuation 16389861 · Apr 19, 2019
Continuation 15256483 · Sep 2, 2016
Provisional Application 62346382 · Jun 6, 2016
Related Publication 20230344841A1 · Oct 26, 2023
References Cited (115)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7743003B1 · Tong · 2010 [cited by examiner]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9338187B1 · Oprea · 2016 [cited by examiner]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-LeMair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120137367A1 · Dupont · 2012 [cited by examiner]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140040174A1 · Leung · 2014 [cited by examiner]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150059982A1 · Hayashi · 2015 [cited by examiner]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170147930A1 · Bellala · 2017 [cited by examiner]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
EP 1063833A2 · 2000 [cited by applicant]
Das K, Schneider J. Detecting anomalous records in categorical datasets. In Proceedings of the 13th ACM SIGKDD international conference on Knowledge discovery and data mining Aug. 12, 2007 (pp. 220-229). (Year: 2007). [cited by examiner]
A. Kind, M. P. Stoecklin and X. Dimitropoulos, “Histogram-based traffic anomaly detection,” in IEEE Transactions on Network and Service Management, vol. 6, No. 2, pp. 110-121, Jun. 2009, doi: 10.1109/TNSM.2009.090604. (… [cited by examiner]
Davis JJ, Clark AJ. Data preprocessing for anomaly based network intrusion detection: A review. computers & security. Sep. 1, 2011; 30(6-7):353-75. (Year: 2011). [cited by examiner]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
McCullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-, What are the different email protoc… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?Offer=ab… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet,FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]