IP Library › Granted Patent US 12,506,757
Granted Patent B2
US 12,506,757 · App. 18/160,441 · Granted Dec 23, 2025

Anomaly detection using collaborative filtering

Inventors: Yair Allouche (Dvira, IL); Bo-Yu Kuo (Kaohsiung, TW); Aviad Cohen (Meitar, IL)
Assignee: International Business Machines Corporation
H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,506,757
App. No.
18/160,441
Granted
Dec 23, 2025
Kind
B2
Abstract

Described are techniques for network anomaly detection. The techniques include generating, from network traffic, a plurality of network interactions, where respective network interactions comprise a communication source and a communication destination. The techniques further include generating, for the respective network interactions, a recommendation score using a trained Collaborative Filtering (CF) model. The techniques further include calculating, for the respective network interactions, an outlier score based on the recommendation score. The techniques further include generating a notification identifying an anomaly in the network traffic based on at least one outlier score satisfying a threshold.

Claims (38)

1 . A method comprising:

generating, from network traffic, a plurality of network interactions, wherein respective network interactions comprise a communication source, a communication destination, and a metric associated with the communication source and the communication destination;

generating, for the respective network interactions, a recommendation score using a trained Collaborative Filtering (CF) model;

calculating, for the respective network interactions, an outlier score, wherein the outlier score comprises a normalized difference that is determined by taking an absolute value of a difference between the recommendation score and the metric and dividing by a maximal rating;

generating a notification identifying an anomaly in the network traffic based on at least one outlier score satisfying a threshold; and

automatically performing a cybersecurity mitigation action on one or more network components based on the anomaly.

2 . The method of claim 1 , wherein the metric comprises an amount of data exchanged between the communication source and the communication destination.

3 . The method of claim 1 , wherein the metric comprises a recency of data exchanged between the communication source and the communication destination.

4 . The method of claim 1 , wherein the metric comprises a frequency of interaction between the communication source and the communication destination.

5 . The method of claim 1 , wherein a relatively stronger recommendation score generates a relatively less anomalous outlier score, and wherein a relatively weaker recommendation score generates a relatively more anomalous outlier score.

6 . The method of claim 1 , wherein the communication source comprises an Internet Protocol (IP) address.

7 . The method of claim 1 , wherein the communication source comprises a Media Access Control (MAC) address.

8 . The method of claim 1 , wherein the communication source comprises a host name.

9 . The method of claim 1 , wherein the communication source comprises a username.

10 . The method of claim 1 , wherein the communication source comprises a dynamic Internet Protocol (IP) range.

11 . The method of claim 1 , wherein the communication source comprises a network name.

12 . The method of claim 1 , wherein the communication source comprises a container identifier.

13 . The method of claim 1 , wherein the communication source comprises, for respective network interactions, at least one Internet Protocol (IP) address, at least one Media Access Control (MAC) address, at least one host name, at least one username, at least one dynamic Internet Protocol (IP) range, at least one network name, and at least one container identifier.

14 . The method of claim 1 , wherein the communication destination is an application identifier.

15 . The method of claim 1 , wherein the method is performed by a server implementing network anomaly detection code, and wherein the method further comprises:

metering usage of the network anomaly detection code; and

generating an invoice based on metering the usage of the network anomaly detection code.

16 . The method of claim 1 , wherein the communication destination is a destination port.

17 . The method of claim 1 , wherein the cybersecurity mitigation action comprises adjusting a bandwidth Quality of Service characteristic of the one or more network components.

18 . A system comprising:

one or more computer readable storage media storing program instructions; and

one or more processors which, in response to executing the program instructions, are configured to perform a method comprising:

generating, from network traffic, a plurality of network interactions, wherein respective network interactions comprise a communication source, a communication destination, and a metric associated with the communication source and the communication destination;

generating, for the respective network interactions, a recommendation score using a trained Collaborative Filtering (CF) model;

calculating, for the respective network interactions, an outlier score, wherein the outlier score comprises a normalized difference that is determined by taking an absolute value of a difference between the recommendation score and the metric and dividing by a maximal rating;

generating a notification identifying an anomaly in the network traffic based on at least one outlier score satisfying a threshold; and

automatically performing a cybersecurity mitigation action on one or more network components based on the anomaly.

19 . A computer program product comprising one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions comprising instructions configured to cause one or more processors to perform a method comprising:

generating, from network traffic, a plurality of network interactions, wherein respective network interactions comprise a communication source, a communication destination, and a metric associated with the communication source and the communication destination;

generating, for the respective network interactions, a recommendation score using a trained Collaborative Filtering (CF) model;

calculating, for the respective network interactions, an outlier score, wherein the outlier score comprises a normalized difference that is determined by taking an absolute value of a difference between the recommendation score and the metric and dividing by a maximal rating;

generating a notification identifying an anomaly in the network traffic based on at least one outlier score satisfying a threshold; and

automatically performing a cybersecurity mitigation action on one or more network components based on the anomaly.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2023
From: ALLOUCHE, YAIR; KUO, BO-YU; COHEN, AVIAD
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 062508/0447 →
Continuity (1)
Related Publication 20240259409A1 · Aug 1, 2024
References Cited (17)
US 11363037B2 · Karin · 2022 [cited by applicant]
US 20140113588A1 · Chekina · 2014 [cited by examiner]
US 20170017760A1 · Freese · 2017 [cited by examiner]
US 20200274894A1 · Argoeti · 2020 [cited by examiner]
US 20200314119A1 · Karin · 2020 [cited by examiner]
US 20210152581A1 · Hen · 2021 [cited by applicant]
US 20230136756A1 · Malboubi · 2023 [cited by examiner]
CN 104394021B · 2017 [cited by applicant]
Alarcon-Aquino et al., “Anomaly Detection in Communication Networks Using Wavelets”, ResearchGate, DOI. 10.1049/ip-com:20010659 Source: IEEE Xplore, Jan. 2002, 9 Pgs, <https://www.researchgate.net/publication/3350208>. [cited by applicant]
Karasek et al., “SuperB: Superior Behavior-based Anomaly Detection Defining Authorized Users' Traffic Patterns”, Carleton University. Downloaded on Nov. 5, 2020 form IEEE Xplore, 9 Pgs. [cited by applicant]
Leichtnam et al., “Sec2graph: Network Attack Detection Based on Novelty Detection on Graph Structured Data”, Lecture Notes in Computer Science, LNSC, vol. 12223, Jul. 7, 2020, 50 Pgs, <https://link.springer.com/chapter/… [cited by applicant]
Panimalar et al., “Collaborative Pattern-Based Filtering Algorithm for Botnet Detection”, World Engineering & Applied Sciences Journal 7 (3): 2016, 8 Pgs, ISSN 2079-2204. [cited by applicant]
Thottan et al., “Anomaly Detection Approaches for Communication Networks”, Jan. 1, 2010, Computer Communications and Networks, 16 Pgs, <https://link.springer.com/chapter/10.1007/978-1-84882-765-3_11>. [cited by applicant]
Wan et al., “Link-Based Anomaly Detection in Communication Networks”, 2008 IEEE/WIC/ACM International Conference on Web Intelligence and Intelligent Agent Technology, Dec. 6, 2022, 4 Pgs. [cited by applicant]
Zhang et al., “Dynamic Link Anomaly Analysis for Network Security Management”, Springer Link, Journal of Network and Systems Management 27, Nov. 13, 2018, 11 Pgs, <https://link.springer.com/article/10.1007/s10922-018-94… [cited by applicant]
Dondo et al., “Malicious activity detection”, DRDC-RDDC-2021-D078, Technologysciencetechnollogie, May 2021, 69 Pgs. [cited by applicant]
Ishibashi et al., “Analyzing Internet Traffic Structure through Big Data Technology”, NTT Technical Review, vol. 11 No. Nov. 11, 2013, 5 Pgs, <https://www.researchgate.net/publication/286356500>. [cited by applicant]
Cited By (1)
US 12,609,944