IP Library › Granted Patent US 12,737,454
Granted Patent B2
US 12,737,454 · App. 17/831,172 · Granted Sep 15, 2026

Systems and methods for encoding behavioral information into an image domain for processing

Inventor: Sameer Khanna (Cupertino, CA)
Assignee: FORTINET, INC.
G06F21/552G01V1/01G01W1/10G06F18/24G06F21/316G06F21/6218G06F40/242G06F40/279G06F40/284G06N7/01G06Q20/389G06Q40/02G06Q40/08G06V10/56G06V10/764G06V10/776G06V40/20H04L43/045H04L63/1416H04L63/1425G06F40/157G06F40/205G06Q50/26
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,737,454
App. No.
17/831,172
Granted
Sep 15, 2026
Kind
B2
Abstract

Systems, devices, and methods are disclosed for encoding behavioral information into an image format to facilitate image based behavioral identification.

Claims (34)

1 . A method for forming behavioral information in an image form, the method comprising:

accessing, by a processing resource, a plurality of behavioral features each of corresponding feature types;

forming, by the processing resource, the plurality of behavioral features into a feature array, wherein the plurality of behavioral features is located in the feature array according to the respective corresponding feature type; and

facilitating processing of non-spatial data with an image-based anomaly detection model designed to process spatial data by encoding, by the processing resource, the feature array as a grayscale image, including modifying each behavioral feature of the feature array such that anomalies in behavioral features are distributed away from normal data by applying a sparse auto encoder model to the feature array.

2 . The method of claim 1 , wherein a value of each of the plurality of behavioral features is converted to a range of zero to two hundred, fifty-five.

3 . The method of claim 1 , the method further comprising:

accessing, by the processing resource, the plurality of behavioral features from feature sources.

4 . The method of claim 3 , wherein the feature sources include one or more of: a user login information source, a lightweight directory access protocol information source, a website access information source, a file access information source, an external device information source, or an email activity information source.

5 . The method of claim 4 , wherein a subset of the plurality of behavioral information accessed from the user login information source includes one or more of: a difference between initial logon and office start time, a difference between last logon and office start time, an average difference in time between office start time and number of logins before office hours, an average difference in time between office end time and number of logins after office hours, a total number of logins, a total number of logins outside of office hours, a total number of logoffs, a total number of logoffs outside of office hours, a total number of unique systems accessed, a total number of unique systems accessed outside of office hours, or an average session length held outside office hours.

6 . The method of claim 4 , wherein a subset of the plurality of behavioral information accessed from the lightweight directory access protocol information source includes an individual's user identification.

7 . The method of claim 4 , wherein a subset of the plurality of behavioral information accessed from the website access information source includes one or more of: a number of websites identified as job posting sites by a conical classification process, a number of websites identified as being a publisher of leaked documents by a conical classification process, or a number of websites identified as being keylogger download sites by a conical classification process.

8 . The method of claim 4 , wherein a subset of the plurality of behavioral information accessed from the file access information source includes one or more of: a number of executable files downloaded, run, or handled in some form, a file path variance over a defined period, or a file path variance after office hours.

9 . The method of claim 4 , wherein a subset of the plurality of behavioral information accessed from the external device information source includes one or more of: a total number of external devices used, or a total number of external devices used outside of office hours.

10 . The method of claim 4 , wherein a subset of the plurality of behavioral information accessed from the email activity information source includes one or more of: a number of emails sent outside organization domain, a number of recipients that a supervisor has sent emails to within organization domain, a number of attachments sent with emails, an average size of emails, a total number of email recipients, or a number of emails identified as the user being disgruntled by a conical classification process.

11 . A system for forming behavioral information in an image form, the system comprising:

a processing resource;

a non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to:

access a plurality of behavioral features each of corresponding feature types;

form the plurality of behavioral features into a feature array, wherein the plurality of behavioral features is located in the feature array according to the respective corresponding feature type; and

facilitate processing of non-spatial data with an image-based anomaly detection model designed to process spatial data by encoding the feature array as a grayscale image, including modifying each behavioral feature of the feature array such that anomalies in behavioral features are distributed away from normal data by applying a sparse auto encoder model to the feature array.

12 . The system of claim 11 , wherein a value of each of the plurality of behavioral features is converted to a range of zero to two hundred, fifty-five.

13 . The system of claim 11 , wherein the instructions further cause the processing resource to:

access the plurality of behavioral features from feature sources.

14 . The system of claim 13 , wherein the feature sources include one or more of: a user login information source, a lightweight directory access protocol information source, a website access information source, a file access information source, an external device information source, and an email activity information source.

15 . A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by a processing resource, causes the processing resource to:

access a plurality of behavioral features each of corresponding feature types;

form the plurality of behavioral features into a feature array, wherein the plurality of behavioral features is located in the feature array according to the respective corresponding feature type; and

facilitate processing of non-spatial data with an image-based anomaly detection model designed to process spatial data by encoding the feature array as a grayscale image, including modifying each behavioral feature of the feature array such that anomalies in behavioral features are distributed away from normal data by applying a sparse auto encoder model to the feature array.

16 . The non-transitory computer-readable storage medium of claim 15 , wherein the instructions further cause the processing resource to:

access the plurality of behavioral features from feature sources, wherein the feature sources include one or more of: a user login information source, a lightweight directory access protocol information source, a website access information source, a file access information source, an external device information source, or an email activity information source.

17 . The non-transitory computer-readable storage medium of claim 16 , wherein a subset of the plurality of behavioral information accessed from the user login information source includes one or more of: a difference between initial logon and office start time, a difference between last logon and office start time, an average difference in time between office start time and number of logins before office hours, an average difference in time between office end time and number of logins after office hours, a total number of logins, a total number of logins outside of office hours, a total number of logoffs, a total number of logoffs outside of office hours, a total number of unique systems accessed, a total number of unique systems accessed outside of office hours, or an average session length held outside office hours.

18 . The non-transitory computer-readable storage medium of claim 17 , wherein a subset of the plurality of behavioral information accessed from the lightweight directory access protocol information source includes an individual's user identification.

19 . The non-transitory computer-readable storage medium of claim 17 , wherein a subset of the plurality of behavioral information accessed from the website access information source includes one or more of: a number of websites identified as job posting sites by a conical classification process, a number of websites identified as being a publisher of leaked documents by a conical classification process, or a number of websites identified as being keylogger download sites by a conical classification process.

20 . The non-transitory computer-readable storage medium of claim 17 , wherein a subset of the plurality of behavioral information accessed from the file access information source includes one or more of: a number of executable files downloaded, run, or handled in some form, a file path variance over a defined period, or a file path variance after office hours.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2022
From: KHANNA, SAMEER
To: FORTINET, INC.
Reel/Frame 060090/0157 →
Continuity (2)
Provisional Application 63235887 · Aug 23, 2021
Related Publication 20230053642A1 · Feb 23, 2023
References Cited (25)
US 10853738B1 · Dockendorf · 2020 [cited by examiner]
US 10893059B1 · Aziz · 2021 [cited by examiner]
US 11089034B2 · Dichiu · 2021 [cited by examiner]
US 11651313B1 · Fridakis · 2023 [cited by applicant]
US 20060262971A1 · Foes · 2006 [cited by examiner]
US 20150288893A1 · Kane · 2015 [cited by examiner]
US 20160180196A1 · Taylor · 2016 [cited by examiner]
US 20170061123A1 · Parker-Wood · 2017 [cited by applicant]
US 20170070527A1 · Bailey · 2017 [cited by applicant]
US 20180176243A1 · Arnaldo · 2018 [cited by examiner]
US 20180191726A1 · Luukkala · 2018 [cited by applicant]
US 20200186544A1 · Dichiu · 2020 [cited by examiner]
US 20200351285A1 · Rosa · 2020 [cited by examiner]
US 20210381717A1 · Hwang · 2021 [cited by examiner]
US 20220286472A1 · Khalil · 2022 [cited by examiner]
US 20220400251A1 · Fisher · 2022 [cited by examiner]
US 20230007024A1 · Maria Vega · 2023 [cited by examiner]
US 20230024796A1 · Hazard · 2023 [cited by examiner]
US 20230039039A1 · Keraudy · 2023 [cited by applicant]
US 20230057125A1 · Khanna · 2023 [cited by examiner]
Khanna “Conical Classification for Computationally Efficient One-Class Topic Determination” Cornell Universtiy Oct. 31, 2021. [cited by applicant]
Zhao et al., “A Review of Computer Vision Methods in Network Security”, IEEE Communications Surveys & Tutorials, 2021, May 7, 2020, 37 pages. [cited by applicant]
Rezende et al., “Malicious Software Classification using Transfer Learning of ResNet-50 Deep Neural Network”, Dec. 2017, DOI:10.1109/ICMLA.2017.00-19, Conference: 16th IEEE International Conference On Machine Learning A… [cited by applicant]
Kancherla et al., “Image Visualization based Malware Detection”, 2013 IEEE Symposium on Computational Intelligence in Cyber Security (CICS), Apr. 2013, 2013, DOI:10.1109/CICYBS.2013.6597204, 5 pages. [cited by applicant]
Tobiyama et al., “Malware Detection with Deep Neural Network Using Process Behavior”, Jun. 2016 DOI:10.1109/COMPSAC.2016.151, Conference: 2016 IEEE 40th Annual Computer Software and Applications Conference (COMPSAC), 6 … [cited by applicant]