IP Library › Granted Patent US 12,308,861
Granted Patent B2
US 12,308,861 · App. 18/423,291 · Granted May 20, 2025

Data compression with intrusion detection

Inventors: Joshua Cooper (Columbia, SC); Aliasghar Riahi (Orinda, CA); Charles Yeomans (Orinda, CA)
Assignee: ATOMBEAM TECHNOLOGIES INC
H03M7/3059G06F21/554G06N20/00H03M7/6005
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,308,861
App. No.
18/423,291
Filed
Jan 25, 2024
Granted
May 20, 2025
Kind
B2
Art Unit
2498
USPC
707/693
Abstract

A system and method for data compression with intrusion detection, that measures in real-time the probability distribution of an encoded data stream, compares the probability distribution to a reference probability distribution, and uses one or more statistical algorithms to determine the divergence between the two sets of probability distributions to determine if an unusual distribution is the result of a data intrusion. The system comprises both encoding and decoding machines, an intrusion detection module, a codebook training module, and various databases which perform various analyses on encoded data streams.

Claims (63)

1. A system for data compression with intrusion detection, comprising:

one or more computing devices, each comprising a processor, a memory, and a network interface;

wherein a plurality of programming instructions stored in one or more of the memories and operating on one or more of the processors of the one or more computing devices causes one or more of the computing devices individually or some combination of the computing devices operating together to:

receive a first codeword data stream;

compute a first probability distribution of a plurality of codewords within the first codeword data stream;

receive a second codeword data stream comprising a test dataset;

use one or more algorithms to compute a second probability distribution of the test dataset;

compare the first probability distribution and the second probability distribution to compute a difference in distribution statistics between the test dataset and the first codeword stream;

check whether the difference in distributions exceeds a pre-determined difference threshold, and when the difference in distributions exceeds the difference threshold:

generate an intrusion alert, the intrusion alert comprising an indicia of anomalous behavior based on the difference in distributions;

send the intrusion alert to a security monitoring system;

use the test dataset to retrain codeword encoding and decoding algorithms;

utilize the retrained algorithms to create one or more new data sourceblocks; and

create a new codeword for one or more of the plurality of codewords of the first codeword data stream using the one or more new data sourceblocks.

2. The system of claim 1 , wherein the plurality of programming instructions further causes one or more computing devices to:

train a machine learning algorithm using a training dataset to create reference probability distributions;

generate the second probability distribution for the test dataset of the received second codeword data stream using the trained machine learning algorithm;

store each new data sourceblock and its associated new codeword in an updated codebook; and

send the updated codebook to one or more of the one or more computing devices.

3. The system of claim 1 , wherein the plurality of programming instructions further causes one or more computing devices to:

receive a plurality of codewords from a codeword storage; and

send the plurality of codewords as a codeword data stream to the one or more computing devices for intrusion detection.

4. A method for data compression with intrusion detection, comprising the steps of:

receiving a first codeword data stream at one or more computing devices, each computing device comprising a processor, a memory, and a network interface;

using the one or more computing devices to perform the steps of:

computing a first probability distribution of a plurality of codewords within the first codeword data stream;

receiving a second codeword data stream comprising a test dataset;

using one or more algorithms to compute a second probability distribution of the test dataset;

comparing the first computed probability distribution and the second probability distribution;

checking whether the difference in distributions exceeds a pre-determined difference threshold, and when the difference in distributions exceeds the difference threshold:

generating an intrusion alert, the intrusion alert comprising an indicia of anomalous behavior based on the difference in distributions; and

sending the intrusion alert to a security monitoring system;

using the test dataset to retrain codeword encoding and decoding algorithms;

utilizing the retrained algorithms to create one or more new data sourceblocks; and

creating a new codeword for one or more of the plurality of codewords of the first codeword data stream using the one or more new data sourceblocks.

5. The method of claim 4 , further comprising the steps of using the one or more computing devices to perform the steps of:

training a machine learning algorithm using a training dataset to create reference probability distributions;

generating the second probability distribution for the test dataset of the received second codeword data stream using the trained machine learning algorithm;

storing each new data sourceblock and its associated new codeword in an updated codebook; and

sending the updated codebook to one or more of the one or more computing devices.

6. The method of claim 4 , further comprising the steps of:

receiving a plurality of codewords from a codeword storage; and

sending the plurality of codewords as a codeword data stream to the one or more computing devices for intrusion detection.

7. A non-transitory, computer-readable medium comprising a plurality of programming instructions that, when operating on one or more computing devices each comprising at least a processor, a memory, and a network interface, causes the one or more computing devices to perform the steps of:

receiving a first codeword data stream at one or more computing devices, each computing device comprising a processor, a memory, and a network interface;

using the one or more computing devices to perform the steps of:

computing a first probability distribution of a plurality of codewords within the first codeword data stream;

receiving a second codeword data stream comprising a test dataset; using one or more algorithms to compute a second probability distribution of the test dataset;

comparing the first probability distribution and the second probability distribution;

checking whether the difference in distributions exceeds a pre-determined difference threshold, and when the difference in distributions exceeds the difference threshold:

generating an intrusion alert, the intrusion alert comprising an indicia of anomalous behavior based on the difference in distributions; and

sending the intrusion alert to a security monitoring system;

using the test dataset to retrain codeword encoding and decoding algorithms;

utilizing the retrained algorithms to create one or more new data sourceblocks; and

creating a new codeword for one or more of the plurality of codewords of the first codeword data stream using the one or more new data sourceblocks.

8. The method of claim 7 , further comprising the step of using the one or more computing devices to perform the steps of:

training a machine learning algorithm using a training dataset to create reference probability distributions;

generating the second probability distribution for the test dataset of the received second codeword data stream using the trained machine learning algorithm;

storing each new data sourceblock and its associated new codeword in an updated codebook; and

sending the updated codebook to one or more of the one or more computing devices.

9. The method of claim 7 , further comprising the step of using the one or more computing devices to perform the steps of:

receiving a plurality of codewords from a codeword storage; and

sending the plurality of codewords as a codeword data stream to the one or more computing devices for intrusion detection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2024
From: COOPER, JOSHUA; RIAHI, ALIASGHAR; YEOMANS, CHARLES
To: ATOMBEAM TECHNOLOGIES INC.
Reel/Frame 068574/0010 →
Continuity (21)
Continuation 18460553 · Sep 3, 2023
Continuation In Part 18161080 · Jan 29, 2023
Continuation 17875201 · Jul 27, 2022
Continuation 17514913 · Oct 29, 2021
Continuation In Part 17404699 · Aug 17, 2021
Continuation In Part 16455655 · Jun 27, 2019
Continuation In Part 16200466 · Nov 26, 2018
Continuation In Part 15975741 · May 9, 2018
Continuation 17458747 · Aug 27, 2021
Continuation In Part 16923039 · Jul 7, 2020
Continuation In Part 16716098 · Dec 16, 2019
Continuation 16455655 · Jun 27, 2019
Continuation In Part 17234007 · Apr 19, 2021
Continuation In Part 17180439 · Feb 19, 2021
Continuation In Part 16923039 · Jul 7, 2020
Provisional Application 63485514 · Feb 16, 2023
Provisional Application 62578824 · Oct 30, 2017
Provisional Application 63027166 · May 19, 2020
Provisional Application 62926723 · Oct 28, 2019
Provisional Application 63140111 · Jan 21, 2021
Related Publication 20240283462A1 · Aug 22, 2024
References Cited (22)
US 9294589B2 · Crosta et al. · 2016 [cited by applicant]
US 9954920B1 · Paris · 2018 [cited by examiner]
US 10897479B1 · Chen · 2021 [cited by examiner]
US 10984423B2 · Adjaoute · 2021 [cited by examiner]
US 11470182B1 · Virtser · 2022 [cited by examiner]
US 20140041032A1 · Scheper · 2014 [cited by examiner]
US 20140270404A1 · Hanna · 2014 [cited by examiner]
US 20160155069A1 · Hoover · 2016 [cited by examiner]
US 20170272100A1 · Yanovsky · 2017 [cited by examiner]
US 20180053114A1 · Adjaoute · 2018 [cited by examiner]
US 20190129640A1 · Riahi · 2019 [cited by examiner]
US 20200293653A1 · Huang · 2020 [cited by examiner]
US 20200382281A1 · Fletcher · 2020 [cited by examiner]
US 20210004677A1 · Menick · 2021 [cited by examiner]
US 20220171857A1 · McHugh · 2022 [cited by examiner]
US 20220210167A1 · Rajagopalan · 2022 [cited by examiner]
US 20230138035A1 · Lott · 2023 [cited by examiner]
US 20230140918A1 · Saxena · 2023 [cited by examiner]
US 20230246814A1 · Fromm · 2023 [cited by examiner]
US 20230336581A1 · Dunn · 2023 [cited by examiner]
CN 112989334A · 2021 [cited by examiner]
Kim, Harry C. International Search Report, Jun. 13, 2024, p. 2. [cited by applicant]