IP Library › Granted Patent US 12,743,456
Granted Patent B2
US 12,743,456 · App. 18/793,579 · Granted Sep 22, 2026

Methods and systems for identifying anomalous computer events to detect security incidents

Inventors: Christopher G. Coulter (Stuart, FL); James C. Briggs (Mansfield, GB)
Assignee: Auguria, Inc.
G06F16/335G06F16/2462G06F16/353G06F16/367G06F21/554G06F16/24528G06F17/18G06F18/15
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,743,456
App. No.
18/793,579
Granted
Sep 22, 2026
Kind
B2
Abstract

A method includes receiving, from a plurality of sources, data associated with a plurality of events at the plurality of sources, standardizing the data based on a set of predefined standardization rules to define standardized data, and defining a vector representation for each event from the plurality of events based on the standardized data. The method includes assigning each event from the plurality of events to at least one cohort from a plurality of cohorts based on a similarity associated with the vector representation for that event and each cohort from the plurality of cohorts, generating, using at least one machine learning model, an ontology based on a set of cohorts from the plurality of cohorts and associated with the plurality of events, and storing the plurality of events as associated with the ontology such that the plurality of events can be filtered based on the ontology.

Claims (49)

1 . A non-transitory processor-readable medium storing code representing instructions to be executed by one or more processors, the instructions comprising code to cause the one or more processors to:

receive, from a plurality of sources, data associated with a plurality of events at the plurality of sources;

standardize the data based on a set of predefined standardization rules to define standardized data;

define a vector representation for each event from the plurality of events based on the standardized data;

calculate a similarity associated with the vector representation for each event from the plurality of events and a plurality of cohorts using a coarse sorting process and a fine sorting process;

assign each event from the plurality of events to at least one cohort from the plurality of cohorts based on the similarity associated with the vector representation for that event and each cohort from the plurality of cohorts;

assign each cohort from the plurality of cohorts to an ontology;

generate a confidence score associated with each event from the plurality of events based on the ontology, the confidence score associated with assigning the plurality of cohorts to the ontology; and

identify an anomalous event from the plurality of events based on the confidence score associated with that event not meeting a criterion.

2 . The non-transitory processor-readable medium of claim 1 , wherein the coarse sorting process includes using a locality sensitive hashing (LSH) function.

3 . The non-transitory processor-readable medium of claim 1 , wherein the code to cause the one or more processors to calculate includes code to cause the one or more processors to calculate the similarity based on at least one of a cosine similarity, a hamming distance, a nearest neighbor search, a dot product similarity, or a Euclidean distance.

4 . The non-transitory processor-readable medium of claim 1 , wherein the ontology includes a plurality of categories.

5 . The non-transitory processor-readable medium of claim 1 , wherein the code to cause the one or more processors to define the vector representation includes code to cause the one or more processors to define the vector representation for each event from the plurality of events using a hybrid vector space based on both a dense vector search and a sparse vector search.

6 . The non-transitory processor-readable medium of claim 1 , wherein the ontology is a first ontology and the confidence score is a first score, the instructions further comprising code to cause the one or more processors to:

generate a second score for an event based on the first ontology;

based on the second score for the event being below a threshold for the first ontology, generate, using a machine learning model and based on the event, a second ontology; and

assign the event to the second ontology.

7 . A method, comprising:

receiving, from a plurality of sources, data associated with a plurality of events at the plurality of sources;

standardizing the data based on a set of predefined standardization rules to define standardized data;

defining a vector representation for each event from the plurality of events based on the standardized data;

calculating a similarity associated with the vector representation for each event from the plurality of events and a plurality of cohorts using a coarse sorting process and a fine sorting process;

assigning each event from the plurality of events to at least one cohort from the plurality of cohorts based on the similarity associated with the vector representation for that event and each cohort from the plurality of cohorts;

assigning each cohort from the plurality of cohorts to an ontology;

generating a confidence score associated with each event from the plurality of events based on the ontology, the confidence score associated with assigning the plurality of cohorts to the ontology; and

identifying an anomalous event from the plurality of events based on the confidence score associated with that event not meeting a criterion.

8 . The method of claim 7 , wherein the coarse sorting process includes using a locality sensitive hashing (LSH) function.

9 . The method of claim 7 , wherein the calculating includes calculating the similarity based on at least one of a cosine similarity, a hamming distance, a nearest neighbor search, a dot product similarity, or a Euclidean distance.

10 . The method of claim 7 , wherein the ontology includes a plurality of categories.

11 . The method of claim 7 , wherein the defining includes defining the vector representation for each event from the plurality of events using a hybrid vector space based on both a dense vector search and a sparse vector search.

12 . The method of claim 7 , wherein the ontology is a first ontology, the method further comprising:

generating a second score for an event based on the first ontology;

based on the second score for the event being below a threshold for the first ontology, generating, using a machine learning model and based on the event, a second ontology; and

assigning the event to the second ontology.

13 . An apparatus, comprising:

a processor, and

a non-transitory, processor-readable medium storing instructions that, when executed by the processor, cause the processor to:

receive, from a plurality of sources, data associated with a plurality of events at the plurality of sources,

standardize the data based on a set of predefined standardization rules to define standardized data,

define a vector representation for each event from the plurality of events based on the standardized data,

calculate a similarity associated with the vector representation for each event from the plurality of events and a plurality of cohorts using a coarse sorting process and a fine sorting process,

assign each event from the plurality of events to at least one cohort from the plurality of cohorts based on the similarity associated with the vector representation for that event and each cohort from the plurality of cohorts,

assign each cohort from the plurality of cohorts to an ontology,

generate a confidence score associated with each event from the plurality of events based on the ontology, the confidence score associated with assigning the plurality of cohorts to the ontology, and

identify an anomalous event from the plurality of events based on the confidence score associated with that event not meeting a criterion.

14 . The apparatus of claim 13 , wherein the coarse sorting process includes using a locality sensitive hashing (LSH) function.

15 . The apparatus of claim 13 , wherein the instructions to cause the processor to calculate include instructions to cause the processor to calculate the similarity based on at least one of a cosine similarity, a hamming distance, a nearest neighbor search, a dot product similarity, or a Euclidean distance.

16 . The apparatus of claim 13 , wherein the ontology includes a plurality of categories.

17 . The apparatus of claim 13 , wherein the instructions to cause the processor to define the vector representation include instructions to cause the processor to define the vector representation for each event from the plurality of events using a hybrid vector space based on both a dense vector search and a sparse vector search.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2024
From: COULTER, CHRISTOPHER G.
To: AUGURIA, INC.
Reel/Frame 068557/0827 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2024
From: BRIGGS, JAMES C.; AURELIO - FZCO A DUBAI FREEZONE COMPANY
To: AUGURIA, INC.
Reel/Frame 068557/0913 →
Continuity (2)
Provisional Application 63518271 · Aug 8, 2023
Related Publication 20250053587A1 · Feb 13, 2025
References Cited (40)
US 9338013B2 · Castellucci et al. · 2016 [cited by applicant]
US 10205627B2 · Kushmerick · 2019 [cited by examiner]
US 10284587B1 · Schlatter et al. · 2019 [cited by applicant]
US 10673880B1 · Pratt et al. · 2020 [cited by applicant]
US 11182481B1 · Oliver et al. · 2021 [cited by applicant]
US 12238119B1 · Chivu et al. · 2025 [cited by applicant]
US 12373557B2 · Coulter · 2025 [cited by applicant]
US 20150026027A1 · Priess et al. · 2015 [cited by applicant]
US 20150199224A1 · Mihnev · 2015 [cited by applicant]
US 20180075070A1 · Chandrasekaran · 2018 [cited by examiner]
US 20180219888A1 · Apostolopoulos · 2018 [cited by applicant]
US 20180255084A1 · Kotinas et al. · 2018 [cited by applicant]
US 20180285768A1 · Karuppasamy · 2018 [cited by examiner]
US 20190319987A1 · Levy et al. · 2019 [cited by applicant]
US 20210141897A1 · Seifert et al. · 2021 [cited by applicant]
US 20220179892A1 · Kermode et al. · 2022 [cited by applicant]
US 20220277176A1 · Bhatia et al. · 2022 [cited by applicant]
US 20220292525A1 · Ash et al. · 2022 [cited by applicant]
US 20220309087A1 · Müller et al. · 2022 [cited by applicant]
US 20220368586A1 · Stewart et al. · 2022 [cited by applicant]
US 20230208869A1 · Bisht et al. · 2023 [cited by applicant]
US 20230252140A1 · Coulter · 2023 [cited by applicant]
US 20240256418A1 · Titon · 2024 [cited by examiner]
US 20250086391A1 · Kempf · 2025 [cited by examiner]
WO WO2023154779A2 · 2023 [cited by applicant]
Extended European Search Report for European Application No. 23753645.3 mailed Sep. 25, 2025, 8 pages. [cited by applicant]
Jarabo-Penas et al., “Bus Headways Analysis for Anomaly Detection,” IEEE Transactions on Intelligent Transportation Systems Year: 2022 I vol. 23, Issue: 10 I Journal Article I Publisher: IEEE, pp. 18975-18988. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/166,654 mailed Nov. 22, 2024, 28 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 18/166,654 mailed Apr. 9, 2025, 10 pages. [cited by applicant]
Park et al., “Autoencoder for Network Anomaly Detection,” 2022 IEEE International Symposium on Measurements & Networking (M&N) Year: 2022 I Conference Paper I Publisher: IEEE., 6 pages. [cited by applicant]
Briggs, “Unlocking the Power of Ontologies for Advanced Security Analytics—Part 3,” retrieved from URL: https://auguria.io/insights/unlocking-the-power-of-ontologies-for-advanced-security-analytics/, Oct. 17, 2024, 13 p… [cited by applicant]
“Science Direct Topics”. ScienceDirect Journals & Books [Internet]. Elsevier B.V. c2023. Available from: https://www.sciencedirect.com/topics/computer-science/log-record-event. 8 pages. [cited by applicant]
International Preliminary Report on Patentability for International Application No. PCT/US2023/062259 mailed Aug. 22, 2024, 7 pages. [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/US2023/062259, mailed on Jul. 11, 2023, 13 pages. [cited by applicant]
International Search Report and Written Opinion for PCT Application No. PCT/US2024/040863 mailed Oct. 18, 2024, 13 pages. [cited by applicant]
Invitation to Pay Fee for International Application No. PCT/US2023/062259 dated Apr. 20, 2023, 2 pages. [cited by applicant]
Joshi et al., “Intelligent clustering scheme for log data streams”. In Computational Linguistics and Intelligent Text Processing: 15th International Conference, CICLing 2014, Kathmandu, Nepal, Apr. 6-12, 2014, Proceedin… [cited by applicant]
Rochford, “Why Your Next SIEM Will Analyze Vectors—Part 1,” retrieved from URL:https://auguria.io/insights/why-your-next-siem-will-analyze-vectors/, Oct. 17, 2024, 12 pages. [cited by applicant]
Rochford, “Why Your Next SIEM Will Analyze Vectors—Part 2,” retrieved from URL:https://auguria.io/insights/why-your-next-siem-will-analyze-vectors-part-2/, Oct. 17, 2024, 15 pages. [cited by applicant]
Warren “How to Detect Pass-the-Hash Attacks”, Internet Archive, WayBack Machine. [Internet]. web.archive.org; Feb. 2019. 12. Available from: https://web.archive.org/web/20211205071738/https:/stealthbits.com/blog/how-to-… [cited by applicant]