IP Library Granted Patent US 12,609,944
Granted Patent B1
US 12,609,944 · App. 18/911,000 · Granted Apr 21, 2026

Data lineage-based anomaly detection

Inventor: Sheng-Che Chang (Ottawa, CA)
Assignee: Trend Micro Incorporated
H04L63/1416G06F21/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,609,944
App. No.
18/911,000
Granted
Apr 21, 2026
Kind
B1
Abstract

Disclosed are a system and methods for detecting anomalies in a computer network. Files that are stored in the computer network of an organization are enumerated. The locality-sensitive hash values of the enumerated files are calculated. Sensitive files among the enumerated files are identified based on the locality-sensitive hash values of the enumerated files. Similarity between identified sensitive files is determined based on their distance from each other. The identified sensitive files are linked on a timeline based on their similarity and creation time. One or more event filters are applied to the timeline to detect anomalous file events. Files on the timeline that are involved in the anomalous file events and users that operated on the files are flagged. Mitigation is performed on the flagged files and users.

Claims (32)

1 . A method of detecting anomalies in a computer network, the method comprising:

enumerating a plurality of files that are on computer systems of the computer network;

calculating a locality-sensitive hash value of each of the plurality of files;

identifying sensitive files from among the plurality of files based on corresponding locality-sensitive hash values of the plurality of files;

determining similarity of the identified sensitive files to each other by comparing corresponding locality-hash values of the identified sensitive files;

linking the identified sensitive files on a timeline based on the similarity of the identified sensitive files to each other and file creation time of the identified sensitive files;

applying one or more event filters to the timeline to detect an anomaly;

flag sensitive files on the timeline that are involved in the anomaly; and

performing mitigation on the flagged sensitive files.

2 . The method of claim 1 , wherein determining the similarity of the identified sensitive files to each other comprises:

determining distance scores between the identified sensitive files; and

comparing the distance scores to similarity thresholds.

3 . The method of claim 1 , wherein the locality-sensitive hash value of each of the plurality of files is calculated using Trend Locality Sensitive Hashing (TLSH) algorithm.

4 . The method of claim 1 , further comprising:

performing mitigation on users that operated on the flagged sensitive files.

5 . The method of claim 1 , wherein the mitigation includes raising an alert.

6 . The method of claim 1 , wherein the anomaly is indicative of intrusion.

7 . A computer system comprising at least one processor and a memory, the memory storing instructions that when executed by the at least one processor cause the computer to:

calculate a locality-sensitive hash value of each of a plurality of files;

identify sensitive files from among the plurality of files based on corresponding locality-sensitive hash values of the plurality of files;

determine similarity of the identified sensitive files to each other by comparing corresponding locality-hash values of the identified sensitive files;

link the identified sensitive files on a timeline based on the similarity of the identified sensitive files to each other and file creation time of the identified sensitive files;

apply one or more event filters to the timeline to detect an anomaly; and

perform mitigation on sensitive files on the timeline that are involved in the anomaly.

8 . The computer system of claim 7 , wherein the similarity of the identified sensitive files to each other is determined by:

determining distance scores between the identified sensitive files; and

comparing the distance scores to similarity thresholds.

9 . The computer system of claim 7 , wherein the locality-sensitive hash value of each of the plurality of files is calculated using Trend Locality Sensitive Hashing (TLSH) algorithm.

10 . The computer system of claim 7 , wherein the instructions in the memory when executed by the at least one processor cause the computer system to:

perform the mitigation on users that operated on the sensitive files that are involved in the anomaly.

11 . The computer system of claim 7 , wherein the mitigation includes raising an alert.

12 . The computer system of claim 7 , wherein the anomaly is indicative of ransomware.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 9, 2024
From: CHANG, SHENG-CHE
To: TREND MICRO INCORPORATED
Reel/Frame 068854/0422 →
References Cited (22)
US 8499152B1 · Chen · 2013 [cited by examiner]
US 9112895B1 · Lin · 2015 [cited by examiner]
US 10162967B1 · Oliver · 2018 [cited by examiner]
US 11349855B1 · Amit · 2022 [cited by examiner]
US 11487876B1 · Pryde · 2022 [cited by examiner]
US 11494618B2 · Xia · 2022 [cited by examiner]
US 11886586B1 · Chang · 2024 [cited by examiner]
US 12170685B2 · Manor · 2024 [cited by examiner]
US 12506757B2 · Allouche · 2025 [cited by examiner]
US 20180063182A1 · Jones · 2018 [cited by examiner]
US 20180211039A1 · Tamir · 2018 [cited by examiner]
US 20180234234A1 · Hurley · 2018 [cited by examiner]
US 20190207969A1 · Brown · 2019 [cited by examiner]
US 20220207141A1 · Chung · 2022 [cited by examiner]
US 20240152622A1 · Xia · 2024 [cited by examiner]
US 20240211599A1 · Koo · 2024 [cited by examiner]
US 20250227116A1 · Paul · 2025 [cited by examiner]
US 20260006067A1 · Hittel · 2026 [cited by examiner]
CN 106599686B · 2019 [cited by applicant]
“Trend Vision One Search and Observed Attack Technique (Apr. 2023)”, Trend Micro, https://success.trendmicro.com/en-US/solutionlka-0014382, Last updated Apr. 26, 2023. [cited by applicant]
“Trend Vision One, Integrated Attack Surface Management (ASM) and Extended Detection and Response (XDR), Solution Brief”, 2024. [cited by applicant]
“TLSH—A Locality Sensitive Hash”, Trend Micro, https://tlsh.org/index.html, Last Updated Nov. 26, 2021. [cited by applicant]