IP Library Granted Patent US 12,632,572
Granted Patent B2
US 12,632,572 · App. 18/586,277 · Granted May 19, 2026

Machine learning-based encrypted file classification for identifying encrypted data movement

Inventors: Yi Zhang (Santa Clara, CA); Siying Yang (Saratoga, CA); Yihua Liao (Palo Alto, CA); Dagmawi Mulugeta (London, GB); Raymond Joseph Canzanese, Jr. (Philadelphia, PA); Ari Azarafrooz (Rancho Santa Margarita, CA)
Assignee: Netskope, Inc.
G06F21/602G06F9/547H04L41/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,632,572
App. No.
18/586,277
Granted
May 19, 2026
Kind
B2
Abstract

The disclosed technology facilitates User and Entity Behavior Analytics (UEBA) by classifying a file being transferred as encrypted or not. The technology involves monitoring movement of a files by a user over a wide area network, detecting file encryption for the files using a trained classifier, wherein the detecting includes processing by the classifier some or all of the following features extracted from each of the files: a chi-square randomness test; an arithmetic mean test; a serial correlation coefficient test; a Monte Carlo-Pi test; and a Shannon entropy test, counting a number of the encrypted files moved by the user in a predetermined period, comparing a predetermined maximum number of encrypted files allowed in the predetermined period to the count of the encrypted files moved by the user and detecting that the user has moved more encrypted files than the predetermined maximum number, and generating an alert.

Claims (66)

1 . A computer-implemented method, comprising:

intercepting, by a network security system server interposed on a network between a cloud-based application and a user endpoint associated with a user, movement of a plurality of files over the network to the cloud-based application;

classifying, with a classifier of the network security system server, each file of the plurality of files as one of encrypted or unencrypted, wherein:

the classifier is trained to classify each file based on analyzing sampled bytes of the respective file and a file type of the respective file; and

the classifying comprises:

determining the file type of the respective file;

calculating metrics for the respective file based on analyzing the sampled bytes; and

providing the metrics and the file type to the classifier trained to classify the respective file as encrypted or unencrypted based on the metrics and the file type;

counting, by the network security system server, a number of the plurality of files classified as encrypted and moved by the user during a predetermined time period;

detecting, by the network security system server, based on the counting, that the user has moved more encrypted files than a predetermined maximum number of encrypted files the user is allowed to move during the predetermined time period; and

generating, by the network security system server in response to the detecting, an alert that the user has moved more encrypted files than the user is allowed.

2 . The computer-implemented method of claim 1 , wherein the calculating the metrics comprises calculating two or metrics selected from a chi-square metric, an arithmetic mean metric, a serial correlation coefficient metric, a Monte Carlo-Pi metric, and an entropy metric.

3 . The computer-implemented method of claim 2 , wherein:

the chi-square metric is based on a chi-square randomness test that measures a degree to which a distribution of the sampled bytes varies from an expected distribution of bytes from the respective file;

the arithmetic mean metric is based on an arithmetic mean test that compares an arithmetic mean of the sampled bytes to an expected mean of the bytes from the respective file;

the serial correlation coefficient metric is based on a serial correlation coefficient test that calculates a serial correlation coefficient between pairs of successive sampled bytes from the respective file;

the Monte Carlo-Pi metric is based on a Monte Carlo-Pi test that maps concatenated bytes as coordinates of a square and calculates a degree to which a proportion of the mapped concatenated bytes that fall within a circle circumscribed by the square varies from an expected proportion that corresponds to mapping from the respective file; and

the entropy metric is based on a Shannon entropy test of randomness of the respective file.

4 . The computer-implemented method of claim 1 , further comprising:

analyzing file movement data for the user over a number of days; and

establishing the predetermined maximum number of encrypted files allowed to be moved based on the analyzing.

5 . The computer-implemented method of claim 4 , wherein the number of days is at least 15 days.

6 . The computer-implemented method of claim 1 , further comprising:

analyzing file movement data for a plurality of users within an organization over a number of user-days; and

establishing the predetermined maximum number of encrypted files allowed to be moved based on the analyzing.

7 . The computer-implemented method of claim 6 , wherein the number of user-days is at least one thousand (1000).

8 . The computer-implemented method of claim 7 , wherein the number of user-days includes both workdays and non-workdays.

9 . The computer-implemented method of claim 1 , further comprising:

intercepting first movement of a first subset of the plurality of files over an application programming interface (API) connection to the cloud-based application; and

intercepting second movement of a second subset of the plurality of files via inline traffic associated with the user endpoint.

10 . The computer-implemented method of claim 1 , further comprising:

sampling the respective file to obtain the sampled bytes, wherein a size of the sampled bytes comprises between 10 KB and 250 KB of the respective file.

11 . A network security system interposed on a network between a cloud-based application and a user endpoint associated with a user, the network security system comprising:

one or more processors; and

a memory having stored thereon instructions that, upon execution by the one or more processors, cause the one or more processors to:

intercept movement of a plurality of files over the network to the cloud-based application;

classify, with a classifier, each file of the plurality of files as one of encrypted or unencrypted, wherein;

the classifier is trained to classify each file based on analyzing sampled bytes of the respective file and a file type of the respective file; and

the instructions to classify comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to:

determine the file type of the respective file;

calculate metrics for the respective file based on analyzing the sampled bytes; and

provide the metrics and the file type to the classifier trained to classify the respective file as encrypted or unencrypted based on the metrics and the file type;

count a number of the plurality of files classified as encrypted and moved by the user during a predetermined time period;

detect, based on the counting, that the user has moved more encrypted files than a predetermined maximum number of encrypted files the user is allowed to move during the predetermined time period; and

generate, in response to the detecting, an alert that the user has moved more encrypted files than the user is allowed.

12 . The network security system of claim 11 , wherein the instructions to calculate comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to calculate two or more metrics selected from a chi-square metric, an arithmetic mean metric, a serial correlation coefficient metric, a Monte Carlo-Pi metric, and an entropy metric.

13 . The network security system of claim 12 , wherein:

the chi-square metric is based on a chi-square randomness test that measures a degree to which a distribution of the sampled bytes varies from an expected distribution of bytes from the respective file;

the arithmetic mean metric is based on an arithmetic mean test that compares an arithmetic mean of the sampled bytes to an expected mean of the bytes from the respective file;

the serial correlation coefficient metric is based on a serial correlation coefficient test that calculates a serial correlation coefficient between pairs of successive sampled bytes from the respective file;

the Monte Carlo-Pi metric is based on a Monte Carlo-Pi test that maps concatenated bytes as coordinates of a square and calculates a degree to which a proportion of the mapped concatenated bytes that fall within a circle circumscribed by the square varies from an expected proportion that corresponds to mapping from the respective file; and

the entropy metric is based on a Shannon entropy test of randomness of the respective file.

14 . The network security system of claim 11 , wherein the instructions comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to:

analyze file movement data for the user over a number of days; and

establish the predetermined maximum number of encrypted files allowed to be moved based on the analyzing.

15 . The network security system of claim 14 , wherein the number of days is at least 15 days.

16 . The network security system of claim 11 , wherein the instructions comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to:

analyze file movement data for a plurality of users within an organization over a number of user-days; and

establish the predetermined maximum number of encrypted files allowed to be moved based on the analyzing.

17 . The network security system of claim 16 , wherein the number of user-days is at least one thousand (1000).

18 . The network security system of claim 17 , wherein the number of user-days includes both workdays and non-workdays.

19 . The network security system of claim 11 , wherein the instructions comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to:

intercept first movement of a first subset of the plurality of files over an application programming interface (API) connection to the cloud-based application; and

intercept second movement of a second subset of the plurality of files via inline traffic associated with the user endpoint.

20 . The network security system of claim 11 , wherein the instructions comprise further instructions that, upon execution by the one or more processors, cause the one or more processors to:

sample the respective file to obtain the sampled bytes, wherein a size of the sampled bytes comprises between 10 KB and 250 KB of the respective file.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2024
From: ZHANG, YI; YANG, SIYING; LIAO, YIHUA; MULUGETA, DAGMAWI; AZARAFROOZ, ARI; CANZANESE, RAYMOND JOSEPH, JR.
To: NETSKOPE, INC.
Reel/Frame 067205/0655 →
Continuity (2)
Continuation 17860037 · Jul 7, 2022
Related Publication 20240249005A1 · Jul 25, 2024
References Cited (123)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 8893278B1 · Chechik · 2014 [cited by examiner]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-Lemair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20190093187A1 · Lee et al. · 2019 [cited by applicant]
US 20200034537A1 · Chen · 2020 [cited by examiner]
US 20200036747A1 · Humphries · 2020 [cited by examiner]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20200097653A1 · Mehta et al. · 2020 [cited by applicant]
US 20210044604A1 · Annen et al. · 2021 [cited by applicant]
US 20210192361A1 · Mumme · 2021 [cited by examiner]
US 20220269807A1 · Gehtman et al. · 2022 [cited by applicant]
US 20220327098A1 · Cooper · 2022 [cited by examiner]
US 20230007023A1 · Andrabi et al. · 2023 [cited by applicant]
EP 1063833A2 · 2000 [cited by applicant]
Cha, S., Kim, H., “Detecting Encrypted Traffic: A Machine Learning Approach”, International Workshop on Information Security Applications 2016, pp. 54-65. [retrieved on May 31, 2023], from the internet: <URL: https://li… [cited by examiner]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff “Ending Clear Text Protocols,” Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Newton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
Mccullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al., “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., “Farsite: Federated, available, and reliable storage for an incompletely trusted environment,” SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al., Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-, What are the different email protoc… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” TechTarget, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?Offer=ab… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1, Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet, FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/10.1007/978-3-319-61… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al., “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P. 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]
U.S. Appl. No. 17/860,035 Non-Final Office Action mailed on Jan. 22, 2024, 24 pages. [cited by applicant]
U.S. Appl. No. 17/860,035 Final Office Action mailed on Apr. 18, 2024, 27 pages. [cited by applicant]
Goldstein, Michael, “Statistical Tests for Random Number Generators,” http://blog.mgold.io/2015/02/17/statistical-tests-for-random-number-generators. 17 February 20215. 16 pages. [cited by applicant]
Lee et al. “Machine Learning Based File Entropy Analysis for Ransomware Detection in Backup Systems.” IEEE Access, vol. 7, Jul. 25, 2019, pp. 110205-110215. [cited by applicant]
Hsu et al. “Enhancing File Entropy Analysis to Improve Machine Learning Detection Rate of Ransomware.” IEEE Access, vol. 9, Sep. 20, 2021, pp. 138345-138351. [cited by applicant]
Natekin,“Gradient boosting machines, a tutorial.” Frontiers in Neurorobotics, vol. 7, Article 21, Dec. 4, 2013, pp. 1-21. [cited by applicant]