IP Library › Granted Patent US 12,401,663
Granted Patent B2
US 12,401,663 · App. 17/844,438 · Granted Aug 26, 2025

Stack-HAC for machine learning based botnet detection

Inventor: Nandi O. Leslie (Silver Spring, MD)
Assignee: Raytheon Company
H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,663
App. No.
17/844,438
Granted
Aug 26, 2025
Kind
B2
Abstract

Discussed herein are devices, systems, and methods for detecting anomalous or malicious processes based on a network session. A method includes receiving a network session, implementing a stacked hierarchical agglomerative clustering (HAC) algorithm that operates multiple HAC algorithms to identify respective clusters to which the network session maps, each HAC algorithm of the StackHAC algorithm operates using a different linkage function and distance pair, appending the respective clusters from the multiple HAC algorithms to a feature vector representing the network session resulting in an augmented feature space, and determining, using a classifier or clustering model that operates using the augmented feature space as input, whether each of the network sessions is associated with a network intrusion.

Claims (35)

1. A device of a computer network, the device comprising:

at least one memory including instructions stored thereon; and

processing circuitry configured to execute the instructions, the instructions, when executed, cause the processing circuitry to perform operations comprising:

receiving a network session;

completing the network session to alter text to numerical values and fill-in any empty fields of the network session;

extracting features of the network session;

implementing a stacked hierarchical agglomerative clustering (HAC) algorithm that operates multiple HAC algorithms to identify respective clusters to which the network session maps, each HAC algorithm of the StackHAC algorithm operates on the extracted features to cluster the network session using a different linkage function and distance pair, and each HAC algorithm outputting a cluster assignment;

appending each of the cluster assignments from each of the HAC algorithms to a feature vector representing the network session resulting in a combined augmented feature vector; and

determining, using a classifier or clustering model that operates using the combined augmented feature vector as input, whether the network session is associated with a network intrusion.

2. The device of claim 1 , wherein the network intrusion includes a botnet.

3. The device of claim 1 , wherein the linkage functions include two or more of Ward, average, simple, or complete linkage.

4. The device of claim 1 , wherein the distances include two or more of L 1 , L 2 , or cosine.

5. The device of claim 1 , wherein data of the network session includes three or more of an input interface index, an output interface index, timestamps for flow start and finish times, number of bytes and packets observed in a corresponding flow, source and destination internet protocol (IP) address, internet control message protocol (ICMP) type and code, IP protocol, type of service value, source and destination port numbers for transmission control protocol (TCP), unigram data protocol (UDP), or stream control transmission protocol (SCTP), union of all TCP flags observed over a life of the flow, IP address of an immediate next-hop along a route to a destination, or source and destination IP masks.

6. A non-transitory machine-readable medium including instructions that, when executed by a machine, cause the machine to perform operations for network intrusion detection, the operations comprising:

receiving a network session;

completing the network session to alter text to numerical values and fill-in any empty fields of the network session;

extracting features of the network session;

implementing a stacked hierarchical agglomerative clustering (HAC) algorithm that operates multiple HAC algorithms to identify respective clusters to which the network session maps, each HAC algorithm of the StackHAC algorithm operates on the extracted features to cluster the network session using a different linkage function and distance pair, and each HAC algorithm outputting a cluster assignment;

appending each of the cluster assignments from each of the HAC algorithms to a feature space representing the reduced and modified feature space of the network sessions resulting in a combined augmented or enhanced feature space; and

determining, using a classifier or clustering model that operates using the combined augmented feature vector as input, whether the network session is associated with a network intrusion.

7. The non-transitory machine-readable medium of claim 6 , wherein the network intrusion includes a botnet.

8. The non-transitory machine-readable medium of claim 6 , wherein the linkage functions include two or more of Ward, average, simple, or complete linkage.

9. The non-transitory machine-readable medium of claim 6 , wherein the distances include two or more of L 1 , L 2 , or cosine.

10. The non-transitory machine-readable medium of claim 6 , wherein data of the network session includes three or more of an input interface index, an output interface index, timestamps for flow start and finish times, number of bytes and packets observed in a corresponding flow, source and destination internet protocol (IP) address, internet control message protocol (ICMP) type and code, IP protocol, type of service value, source and destination port numbers for transmission control protocol (TCP), unigram data protocol (UDP), or stream control transmission protocol (SCTP), union of all TCP flags observed over a life of the flow, IP address of an immediate next-hop along a route to a destination, or source and destination IP masks.

11. A method for network intrusion detection, the method comprising:

receiving a network session;

completing the network session to alter text to numerical values and fill-in any empty fields of the network session;

extracting features of the network session;

implementing a stacked hierarchical agglomerative clustering (HAC) algorithm that operates multiple HAC algorithms to identify respective clusters to which the network session maps, each HAC algorithm of the StackHAC algorithm operates on the extracted features to cluster the network session using a different linkage function and distance pair, and each HAC algorithm outputting a cluster assignment;

appending each of the cluster assignments from each of the HAC algorithms to a feature vector representing the network session resulting in a combined augmented feature vector;

and determining, using a classifier or clustering model that operates using the combined augmented feature vector as input, whether the network session is associated with a network intrusion.

12. The method of claim 11 , wherein the network intrusion includes a botnet.

13. The method of claim 11 , wherein the linkage functions include two or more of Ward, average, simple, or complete linkage.

14. The method of claim 11 , wherein the distances include two or more of L 1 , L 2 , or cosine.

15. The method of claim 11 , wherein data of the network session includes three or more of an input interface index, an output interface index, timestamps for flow start and finish times, number of bytes and packets observed in a corresponding flow, source and destination internet protocol (IP) address, internet control message protocol (ICMP) type and code, IP protocol, type of service value, source and destination port numbers for transmission control protocol (TCP), unigram data protocol (UDP), or stream control transmission protocol (SCTP), union of all TCP flags observed over a life of the flow, IP address of an immediate next-hop along a route to a destination, or source and destination IP masks.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 22, 2023
From: LESLIE, NANDI O.
To: RAYTHEON COMPANY
Reel/Frame 064997/0313 →
Continuity (1)
Related Publication 20230412618A1 · Dec 21, 2023
References Cited (9)
US 20200233862A1 · Shaked · 2020 [cited by examiner]
CN 108881277A · 2018 [cited by examiner]
Masoud, Hierarchical Agglomerative Clustering Using Common Neighbours Similarity, IEEE, 2016, pp. 546-551 (Year: 2016). [cited by examiner]
Vijaya et al , An Efficient Hybrid Hierarchical Agglomerative Clustering (HHAC) Technique for Partitioning Large Data Sets, Lecture notes in computer science vol. 3776, pp. 583-588 (Year: 2005). [cited by examiner]
Bahnsen, Alejandro Correa, et al., “Fraud detection by stacking cost-sensitive decision trees”, Data Science for Cyber-Security, (Jul. 27, 2017), 15 pgs. [cited by applicant]
Garcia, S., et al., “The CTU-13 dataset. a labeled dataset with botnet, normal and background traffic”, Retrieved Online. URL: <https://www.stratosphereips.org/datasets-ctu13/>, (2014), 5 pgs. [cited by applicant]
Leslie, Nandi, “An Unsupervised Learning Approach for In-Vehicle Network Intrusion Detection”, 2021 55th Annual Conference on Information Sciences and Systems (CISS), Baltimore, MD, USA, (2021), 1-4. [cited by applicant]
Leslie, Nandi O., “Using Semi-Supervised Learning for Flow-Based Network Intrusion Detection”, Proceedings of the 23rd International Command and Control Research and Technology Symposium (ICCRTS): Multi-Domain C2. Pensa… [cited by applicant]
Yavanoglu, Ozlem, et al., “A review on cyber security datasets for machine learning algorithms”, 2017 IEEE International Conference on Big Data (Bigdata), (Dec. 2017), 2186-2193. [cited by applicant]