IP Library › Granted Patent US 12,568,101
Granted Patent B2
US 12,568,101 · App. 18/581,779 · Granted Mar 3, 2026

Network anomaly detection

Inventors: Michael Gibson (London, GB); Alexander Healing (London, GB); Aditya Manocha (London, GB)
Assignee: British Telecommunications Public Limited Company
H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,101
App. No.
18/581,779
Granted
Mar 3, 2026
Kind
B2
Abstract

A computer-implemented method of training a network anomaly detection system is disclosed. The method involves generating synthetic benign network data and synthetic anomalous network data and combining the synthetic benign network data and synthetic anomalous network data to generate combined synthetic network data having a predetermined density of anomalous network data. The combined synthetic network data is provided to a trained anomaly detection model, and an accuracy score is determined that is representative of how accurately the trained anomaly detection model recognizes anomalous activity in the combined synthetic network data. If the accuracy score is less than a threshold value, the anomaly detection model is trained with additional network data and a new accuracy score is determined. Otherwise, the predetermined density of anomalous network data is reduced and a new accuracy score is determined until a predetermined stopping criterion is met.

Claims (32)

1 . A network anomaly detection system comprising:

at least one processor and memory configured to:

generate synthetic benign network data and synthetic anomalous network data;

combine the synthetic benign network data and synthetic anomalous network data to generate combined synthetic network data having a predetermined density of anomalous network data;

provide the combined synthetic network data to a trained anomaly detection model;

determine an accuracy score representative of how accurately the trained anomaly detection model recognizes anomalous activity in the combined synthetic network data; and

performing one of:

responsive to determining that the accuracy score is less than a threshold value, train the anomaly detection model with additional network data and then repeat the providing, the determining, and the performing, or

reducing the predetermined density of anomalous network data and repeating the combining, the providing, and the determining until a predetermined stopping criterion is met.

2 . The network anomaly detection system of claim 1 , wherein the synthetic benign network data is generated using a generative data model with real-world benign network data.

3 . The network anomaly detection system of claim 1 , wherein the predetermined stopping criterion is a predetermined minimum density of anomalous network data.

4 . The network anomaly detection system of claim 1 , wherein training the anomaly detection model with additional network data comprises training the anomaly detection model with training data having the predetermined density of anomalous network data.

5 . The network anomaly detection system of claim 1 , further configured to use the anomaly detection model to detect anomalous activity in real network data subsequent to the training or the reducing.

6 . The network anomaly detection system of claim 5 , further comprising an anomaly response system configured to perform a mitigative action in response to detection of the anomalous activity.

7 . A computer-implemented method of training a network anomaly detection system, the method comprising:

generating synthetic benign network data and synthetic anomalous network data;

combining the synthetic benign network data and synthetic anomalous network data to generate combined synthetic network data having a predetermined density of anomalous network data;

providing the combined synthetic network data to a trained anomaly detection model;

determining an accuracy score representative of how accurately the trained anomaly detection model recognizes anomalous activity in the combined synthetic network data; and

performing one of:

responsive to determining that the accuracy score is less than a threshold value, proceeding by training the anomaly detection model with additional network data and then repeating the providing, the determining, and the performing, or

reducing the predetermined density of anomalous network data and repeating the combining, the providing, and the determining until a predetermined stopping criterion is met.

8 . The method of claim 7 , wherein the synthetic benign network data is generated by a generative data model using real-world benign network data.

9 . The method of claim 7 , wherein the predetermined stopping criterion is a predetermined minimum density of anomalous network data.

10 . The method of claim 7 , wherein training the anomaly detection model with additional network data comprises training the anomaly detection model with training data having the predetermined density of anomalous network data.

11 . A computer-implemented anomaly detection method comprising:

training a network anomaly detection system using the method of claim 7 ; and

subsequent to training the network anomaly detection system, using the network anomaly detection system to detect anomalous activity in real network data.

12 . The method of claim 11 , further comprising performing a mitigative action in response to detecting the anomalous activity.

13 . The network anomaly detection system of claim 1 , wherein the network anomaly detection system is an intrusion detection system.

14 . The method of claim 7 , wherein the network anomaly detection system is an intrusion detection system.

15 . A non-transitory computer-readable storage medium storing a computer program comprising instructions which, when executed by a computer, cause the computer to carry out the method of claim 7 .

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 17, 2025
From: GIBSON, MICHAEL; HEALING, ALEXANDER; MANOCHA, ADITYA
To: BRITISH TELECOMMUNICATIONS PUBLIC LIMITED COMPANY
Reel/Frame 072930/0001 →
Priority Claims (1)
EP 23157824 · Feb 21, 2023 · regional
Continuity (1)
Related Publication 20240283806A1 · Aug 22, 2024
References Cited (21)
US 11374952B1 · Coskun · 2022 [cited by examiner]
US 11509674B1 · Beauchesne · 2022 [cited by examiner]
US 12292971B2 · Harang · 2025 [cited by examiner]
US 20150326600A1 · Karabatis · 2015 [cited by examiner]
US 20160028753A1 · Di Pietro et al. · 2016 [cited by applicant]
US 20180159871A1 · Komashinskiy et al. · 2018 [cited by applicant]
US 20190075123A1 · Smith · 2019 [cited by examiner]
US 20210287071A1 · Ben Fadhel · 2021 [cited by examiner]
US 20220014554A1 · Vasu · 2022 [cited by examiner]
US 20220060491A1 · Achleitner et al. · 2022 [cited by applicant]
US 20220156372A1 · Harang · 2022 [cited by examiner]
US 20230024796A1 · Hazard · 2023 [cited by examiner]
US 20230058516A1 · Khanna · 2023 [cited by examiner]
US 20230164156A1 · Grossman · 2023 [cited by examiner]
US 20230179616A1 · Rahmes · 2023 [cited by examiner]
CN 110430183A · 2019 [cited by applicant]
“Combined Search & Exam Report for GB2302447.4”, May 23, 2023, 5 pgs. [cited by applicant]
“The Extended European Search Report for EP23157824.6”, Sep. 7, 2023, 7 pgs. [cited by applicant]
Sabari, KK , et al., “Anomaly-based Intrusion Detection using GAN for Industrial Control Systems”, 2022 10th International Conference on Reliability, Infocom Technologies and Optimization (Trends and Future Directions) … [cited by applicant]
Tang, Bo , et al., “KernelADASYN: Kernel Based Adaptive Synthetic Data Generation for Imbalanced Learning”, Sendai, Japan: IEEE. Retrieved from https://ieeexplore.ieee.org/abstract/document/7256954, 2015, pp. 664-571. [cited by applicant]
Wan, Zhiqiang , et al., “Variational Autoencoder Base Synthetic Data Generation for Imbalanced Learning”, Honolulu, USA: IEEE, 2017, 7 pgs. [cited by applicant]