IP Library Granted Patent US 12,438,765
Granted Patent B2
US 12,438,765 · App. 17/997,424 · Granted Oct 7, 2025

Network anomaly detection

Inventors: Giulio Giaconi (London, GB); Samuel Moore (London, GB); Christopher Nugent (London, GB); Shuai Zhang (London, GB); Ian Cleland (London, GB)
Assignee: British Telecommunications Public Limited Company
H04L41/06H04L41/12H04L43/08H04L43/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,438,765
App. No.
17/997,424
Filed
Oct 28, 2022
Granted
Oct 7, 2025
Kind
B2
Art Unit
2451
USPC
709/224
Abstract

A method of identifying anomalous network activity. The method includes identifying, based on network data representative of network activity within a network, at least one instance of a sequence of events that occurred within the network. A probability of the sequence of events occurring during non-anomalous network activity is obtained based on transition probabilities between events in the sequence of events. A frequency characteristic dependent on a frequency at which the sequence of events occurred within the network is determined. A likelihood of the sequence of events occurring within the network at the frequency is determined based on a combination of the probability and the frequency characteristic. It is identified, based on the likelihood, that at least a portion of the network data is anomalous.

Claims (45)

1. A method of identifying anomalous network activity, the method comprising:

identifying, based on network data representative of aggregated network activity within a network over a period of time, at least one instance of a sequence of events that occurred within the network;

storing the at least one instance of the sequence of events that occurred within the network in a database;

obtaining a probability of the at least one instance of the sequence of events occurring during non-anomalous network activity using a trained statistical model representative of a transition matrix based on transition probabilities between a particular event in the at least one instance of the sequence of events occurring immediately prior to a different particular event in the at least one instance of the sequence of events;

determining a frequency characteristic representative of a frequency at which the at least one instance of the sequence of events is identified to have occurred within the network based on a number of times the at least one instance of the sequence of events is stored in the database over the period of time;

determining, based on calculating a function of the probability and the frequency characteristic, a likelihood of the at least one instance of the sequence of events occurring within the network at the frequency;

comparing the likelihood to a first threshold and a second threshold;

identifying, based on the likelihood being less than the first threshold or greater than the second threshold, that at least a portion of the network data is anomalous; and

sending an alert to a client device after identifying that at least the portion of the network data is anomalous.

2. The method according to claim 1 , wherein the aggregated network activity comprises port scanning, and the method further comprises identifying, based on the likelihood, that at least a portion of the network data represents anomalous port scanning.

3. The method according to claim 2 , further comprising:

obtaining port scanning data indicative of port scanning of at least one port within the network; and

discretizing the port scanning data to obtain the network data.

4. The method according to claim 2 , wherein the network data represents values indicative of a rate of port scanning for a respective time period.

5. The method according to claim 1 , wherein the probability is obtained using a Markov model of the at least one instance of the sequence of events.

6. The method according to claim 5 , wherein the Markov model is a first order Markov model, a second order Markov model or a third order Markov model.

7. The method according to claim 1 , wherein determining the likelihood comprises applying a power function to the probability, wherein an exponent of the power function depends on the frequency.

8. The method according to claim 1 , wherein the method further comprises:

identifying, based on the network data, a plurality of sequences of events that occurred within the network, the plurality of sequences of events comprising the at least one instance of the sequence of events, the frequency characteristic depending on the frequency and a further frequency at which the plurality of sequences of events occurred within the network.

9. The method according to claim 8 , wherein the frequency characteristic represents a ratio between the frequency and the further frequency.

10. The method according to claim 1 , wherein each of the identifying the at least one instance, obtaining the probability, determining the frequency characteristic, determining the likelihood, and identifying that the at least a portion of the network data is anomalous are performed for each of a plurality of network activity types to identify whether the aggregated network activity represented by the network data represents anomalous network activity of at least one of the plurality of network activity types.

11. The method according to claim 10 , wherein the plurality of network activity types comprises at least one of:

a first activity type comprising port scanning of a first port of the network and a second activity type comprising port scanning of a second port of the network; or

a third activity type comprising network activity within a first portion of the network and a fourth activity type comprising network activity within a second portion of the network.

12. The method according to claim 10 , wherein each of the plurality of network activity types is associated with a respective threshold likelihood and identifying that at least the portion of the network data is anomalous for a given one of the plurality of network activity types is based on comparing the likelihood and the threshold likelihood for the given one of the plurality of network activity types.

13. The method according to claim 10 , wherein each of the plurality of network activity types is associated with a respective trained statistical model for obtaining the probability of the at least on instance of the sequence of events occurring during non-anomalous network activity of the respective network activity type.

14. The method according to claim 1 , further comprising identifying, based on the at least the portion of the network data, at least one of: a device that performed the anomalous network activity, or a portion of the network in which the anomalous network activity occurred.

15. The method according to claim 14 , further comprising at least one of:

blacklisting the device based on identifying that a number of times the anomalous network activity is performed by the device satisfies a first condition; or

adjusting at least one characteristic of the portion of the network based on identifying that a number of times the anomalous network activity occurred in the portion of the network satisfies a second condition.

16. The method according to claim 1 , wherein the trained statistical model is trained using training data comprising further network data representative of the non-anomalous network activity within the network, the further network data being different from the network data.

17. The method according to claim 1 , wherein the at least one instance of the sequence of events is stored in the database in the form of a vector.

18. The method according to claim 1 , further comprising:

determining the frequency at which the at least one instance of the sequence of events occurred within the network based on a number of sequences of events stored in the database and the period of time which the network data was obtained.

19. A system comprising:

storage for storing network data representative of aggregated network activity within a network over a period of time; and

at least one processor configured to:

identify, based on the network data, at least one instance of a sequence of events that occurred within the network,

store the at least one instance of the sequence of events that occurred within the network in a database;

obtain a probability of the at least one instance of the sequence of events occurring during non-anomalous network activity using a trained statistical model representative of a transition matrix based on transition probabilities between a particular event in the at least one instance of the sequence of events occurring immediately prior to a different particular event in the at least one instance of the sequence of events,

determine a frequency characteristic representative of a frequency at which the at least one instance of the sequence of events is identified to have occurred within the network based on a number of times the at least one instance of the sequence of events is stored in the database over the period of time,

determine, based on calculating a function of the probability and the frequency characteristic, a likelihood of the at least one instance of the sequence of events occurring within the network at the frequency,

compare the likelihood to a first threshold and a second threshold,

identify, based on the likelihood being less than the first threshold or greater than the second threshold, that at least a portion of the network data is anomalous, and

send an alert to a client device after identifying that at least the portion of the network data is anomalous.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2023
From: GIACONI, GIULIO; MOORE, SAMUEL; NUGENT, CHRISTOPHER; ZHANG, SHUAI; CLELAND, IAN
To: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
Reel/Frame 063899/0578 →
Priority Claims (1)
EP 20172518 · Apr 30, 2020 · regional
Continuity (1)
Related Publication 20230171277A1 · Jun 1, 2023
References Cited (75)
US 5465321A · Smyth · 1995 [cited by applicant]
US 6989742B2 · Ueno et al. · 2006 [cited by applicant]
US 7930752B2 · Hertzog et al. · 2011 [cited by applicant]
US 9225738B1 · Chiles · 2015 [cited by examiner]
US 9253201B2 · Song et al. · 2016 [cited by applicant]
US 9471544B1 · Yu · 2016 [cited by examiner]
US 9516053B1 · Muddu · 2016 [cited by examiner]
US 10063576B2 · Song et al. · 2018 [cited by applicant]
US 10425702B2 · Trainor et al. · 2019 [cited by applicant]
US 10475141B2 · Mcintosh et al. · 2019 [cited by applicant]
US 10673880B1 · Pratt · 2020 [cited by examiner]
US 11159415B2 · McLean · 2021 [cited by examiner]
US 20030117279A1 · Ueno · 2003 [cited by examiner]
US 20070300300A1 · Guo et al. · 2007 [cited by applicant]
US 20100131952A1 · Akiyama · 2010 [cited by examiner]
US 20110145185A1 · Wang et al. · 2011 [cited by applicant]
US 20140254772A1 · Williams · 2014 [cited by examiner]
US 20170230410A1 · Hassanzadeh et al. · 2017 [cited by applicant]
US 20170244749A1 · Shulman · 2017 [cited by examiner]
US 20180004941A1 · Reinecke · 2018 [cited by examiner]
US 20180004948A1 · Martin · 2018 [cited by examiner]
US 20190182279A1 · Song et al. · 2019 [cited by applicant]
US 20190323869A1 · Kodeswaran et al. · 2019 [cited by applicant]
US 20190370143A1 · Salunke et al. · 2019 [cited by applicant]
US 20230153428A1 · Mitani · 2023 [cited by examiner]
CN 105722129A · 2016 [cited by applicant]
CN 107438052A · 2017 [cited by applicant]
EP 1324290A2 · 2003 [cited by applicant]
EP 1708414A1 · 2006 [cited by applicant]
EP 3242240A1 · 2017 [cited by applicant]
EP 3242240B1 · 2018 [cited by applicant]
EP 3528457A2 · 2019 [cited by applicant]
EP 3531329A1 · 2019 [cited by applicant]
GB 2547201A · 2017 [cited by applicant]
KR 100950079B1 · 2010 [cited by applicant]
Al-Fuqaha A., et al., “Internet of Things: A Survey on Enabling Technologies, Protocols, and Applications,” IEEE Communication Surveys & Tutorials, vol. 17, No. 4, Fourth Quarter 2015, pp. 2347-2376. [cited by applicant]
Blanco R., et al., “Anomaly Detection Using Gaussian Mixture Probability Model to Implement Intrusion Detection Systems,” HAIS 2019, Hybrid Artificial Intelligent Systems, Retrieved from the Internet: https://link.sprin… [cited by applicant]
Carnevali L., et al., “Learning Marked Markov Modulated Poisson Processes for Online Predictive Analysis of Attack Scenarios,” 2019 IEEE 30th International Symposium on Software Reliability Engineering, IEEE, XP03370866… [cited by applicant]
Chandola V., et al., “Anomaly Detection for Discrete Sequences: A Survey,” IEEE Transactions on Knowledge and Data Engineering, vol. 24, No. 5, May 2012, pp. 823-839. [cited by applicant]
Chatterjee S., “Anomaly Detection Strategies for IoT Sensors,” Feb. 12, Retrieved from the internet: https://medium.com/analytics-vidhya/anomaly-detection-strategies-for-iot-sensors-6281e84263df, undated, 16 pages. [cited by applicant]
Chen L., et al., “Sensor-based Activity Recognition,” IEEE Transactions on Systems, Man, and Cybernetics—Part C: Applications and Reviews, Nov. 2012, vol. 42, No. 6, pp. 790-808. [cited by applicant]
Colakovic A., et al., “Internet of Things (IoT): A Review of Enabling Technologies, Challenges, and Open Research Issues,” Revised on May 18, 2018, 27 pages. [cited by applicant]
Combined Search and Examination Report under Sections 17 and 18(3) for Great Britain Application No. 2006412.7, mailed on Oct. 6, 2020, 9 pages. [cited by applicant]
Desnitsky V.A., et al., “Detection of Anomalies in Data for Monitoring of Security Components in the Internet of Things,” IEEE, 2015, pp. 189-192. [cited by applicant]
Diaz M., et al., “State-of-the-Art, Challenges, and Open Issues in the Integration of Internet of Things and Cloud Computing,” Journal of Network and Computer Applications, 2016, vol. 67, pp. 99-117. [cited by applicant]
Diro A.A., et al., “Deep Learning: The Frontier for Distributed Attack Detection in Fog-to-Things Computing,” IEEE Communications Magazine, Feb. 2018, pp. 169-175. [cited by applicant]
Evans D., “The Internet of Things—How the Next Evolution of the Internet is Changing Everything,” White Paper, Apr. 2011, 11 pages. [cited by applicant]
Extended European Search Report for Application No. 20172509.0, mailed on Oct. 22, 2020, 9 pages. [cited by applicant]
Extended European Search Report for Application No. 20172518.1, mailed on Sep. 8, 2020, 11 pages. [cited by applicant]
Fekade B., et al., “Probabilistic Recovery of Incomplete Sensed Data in IoT,” IEEE Internet of Things Journal, Aug. 2018, vol. 5, No. 4, pp. 2282-2292. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2021/060459, mailed on Jul. 9, 2021, 11 pages. [cited by applicant]
International Search Report and Written Opinion for Application No. PCT/EP2021/060460, mailed on May 7, 2021, 14 pages. [cited by applicant]
Karkouch A., et al., “Data Quality in Internet of Things: A State-of-the Art Survey,” Journal of Network and Computer Applications, 2016, vol. 73, pp. 57-81. [cited by applicant]
Karkouch A., et al., “Data Quality Enhancement in Internet of Things Environment,” IEEE, 2015, 8 pages. [cited by applicant]
Kasteren T.V., et al., “Accurate Activity Recognition in a Home Setting,” Conference Paper, Jan. 2008, 10 pages. [cited by applicant]
Khanna R., et al., “Control Theoretic Approach to Intrusion Detection Using a Distributed Hidden Markov Model,” IEEE Wireless Communications, Aug. 2008, pp. 24-33. [cited by applicant]
Leckie C., et al., “A Probabilistic Approach to Detecting Network Scans,” Network Operations and Managment Symposium, 2002 IEEE/IFIP, Apr. 2002, Retrieved from the Internet: https://ieeexplore.ieee.org/document/1015594,… [cited by applicant]
Lin J., et al., “A Survey on Internet of Things: Architecture, Enabling Technologies, Security and Privacy, and Applications,” IEEE Internet of Things Journal, Oct. 2017, vol. 4, No. 5, pp. 1125-1142. [cited by applicant]
Moore S.J., et al., “Impact Analysis of Erroneous Data on IoT Reliability”, IEEE Smart World, Ubiquitous Intelligence & Computing, Advanced & Trusted Computing, Scalable Computing & Communications, Cloud & Big Data Comp… [cited by applicant]
Ni K., et al., “Sensor Network Data Fault Types,” ACM Transactions on Sensor Networks, ACM, 2 Penn Plaza, Suite 701 New York NY 10121-0701 USA, vol. 5, No. 3, Jun. 4, 2009, XP058301703, ISSN: 1550-4859, DOI: 10.1145/152… [cited by applicant]
Nong Y., “A Markov Chain Model of Temporal Behavior for Anomaly Detection,” Proceedings of the 2000 IEEE Workshop on Information Assurance and Security, Jun. 2000, pp. 171-174. [cited by applicant]
Notification of Grant for Great Britain Application No. 2006411.9, dated May 3, 2022, 2 pages. [cited by applicant]
Paschalidis I.C., et al., “Anomaly Detection in Sensor Networks based on Large Deviations of Markov Chain Models,” Proceedings of the 47th IEEE Conference on Decision and Control, Dec. 9-11, 2008, pp. 2338-2343. [cited by applicant]
Rayes A., et al., “Internet of Things—From Hype to Reality: The Road to Digitization,” Second Edition, 2019, 393 pages. [cited by applicant]
Saini N.K., “Trust Factor and Reliability-Over-a-Period-of-Time as Key Differentiators in IoT enabled Services,” International Conference on Internet of Things and Applications (IOTA), 2016, pp. 411-414. [cited by applicant]
Santis G. DE., et al., “Internet-Wide Scanners Classification using Gaussian Mixture and Hidden Markov Models,” Nov. 26, 2018, 6 pages. [cited by applicant]
Search Report under Section 17 for Great Britain Application No. 2006411.9, mailed on Oct. 8, 2020, 4 pages. [cited by applicant]
Sicari S., et al., “A Secure and Quality-Aware Prototypical Architecture for the Internet of Things,” Information Systems, Feb. 2016, 15 pages. [cited by applicant]
Sicari S., et al., “A Security-and Quality-Aware System Architecture for Internet of Things,” Information Systems Frontiers, 2016, vol. 18, pp. 665-677. [cited by applicant]
Stiawan D., et al., “Anomaly Detection and Monitoring in Internet of Things Communication,” 8th International Conference on Information Technology and Electrical Engineering (ICITEE), 2016, 4 pages. [cited by applicant]
Thanigaivelan N.K., et al., “Distributed Internal Anomaly Detection System for Internet-of-Things,” 2016 13th IEEE Annual Consumer Communications & Networking Conference (CCNC), 2 pages. [cited by applicant]
Treinen, J.J., “Heuristics for improved enterprise intrusion Detection”, PhD thesis, published in Jun. 2009, 119 pages. [cited by applicant]
Casagrande et al., “Predicting Sensor Events, Activities, and Time of Occurrence Using Binary Sensor Data From Homes With Older Adults”, IEEE Access, vol. 7, 2019, pp. 111012-111029. [cited by applicant]
Ordonez et al., “Sensor-based Bayesian Detection of Anomalous Living Patterns in a home setting”, Pers Ubiquit Comput, vol. 19, No. 2, 2015, pp. 259-270. [cited by applicant]
Zhu et al., “Wearable Sensor-Based Behavioral Anomaly Detection in Smart Assisted Living Systems”, IEEE Transactions on Automation Science and Engineering, vol. 12, No. 4, Oct. 2015, pp. 1225-1234. [cited by applicant]