IP Library Granted Patent US 12,452,268
Granted Patent B2
US 12,452,268 · App. 17/223,912 · Granted Oct 21, 2025

Methods, systems, and media for detecting anomalous network activity

Inventors: Sherin M. Mathews (Santa Clara, CA); Vaisakh Shaj (Kollam, IN); Sriranga Seetharamaiah (Bangalore, IN); Carl D. Woodward (Santa Clara, CA); Kantheti V V S M B Kumar (Bangalore, IN)
Assignee: McAfee, LLC
H04L63/1425G06N3/02G06N20/00H04L41/142H04L41/145H04L43/045H04L63/1441G06F16/9024H04L2101/668
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,268
App. No.
17/223,912
Granted
Oct 21, 2025
Kind
B2
Abstract

Methods, systems, and media for detecting anomalous network activity are provided. In some embodiments, a method for detecting anomalous network activity is provided, the method comprising: receiving information indicating network activity, wherein the information includes IP addresses corresponding to devices participating in the network activity; generating a graph representing the network activity, wherein each node of the graph indicates an IP address of a device; generating a representation of the graph, wherein the representation of the graph reduces a dimensionality of information indicated in the graph; identifying a plurality of clusters of network activity based on the representation of the graph; determining that at least one cluster corresponds to anomalous network activity; and in response to determining that the at least one cluster corresponds to anomalous network activity, causing a network connection of at least one device included in the at least one cluster to be blocked.

Claims (38)

1. A method for detecting anomalous network activity, comprising:

generating, using a hardware processor, a weighted directed graph representing network activity, wherein the weighted directed graph has a plurality of nodes and has an edge between two of the plurality of nodes, wherein each node of the graph indicates an IP address of a device participating in the network activity, and wherein the edge has at least one weight, wherein the at least one weight includes at least one of: a number of connections between the two of the plurality of nodes, an average number of bytes per packet sent between the two of the plurality of nodes, and a number of ports scanned;

generating a representation of the graph representing the network activity, wherein the representation of the graph representing the network activity reduces a dimensionality of information indicated in the graph representing the network activity, wherein the representation includes a plurality of adjacency matrices, wherein:

a first of the plurality of adjacency matrices represents one of: a number of connections between a source IP address and a destination IP address; an average number of bytes per packet sent between a source IP address and a destination IP address; and a number of ports scanned; and

a second of the plurality of adjacency matrices represents another of: the number of connections between a source IP address and a destination IP address; the average number of bytes per packet sent between a source IP address and a destination IP address; and the number of ports scanned;

identifying a plurality of clusters of network activity from the representation of the graph including the plurality of adjacency matrices;

determining that at least one cluster of the plurality of clusters corresponds to anomalous network activity; and

in response to determining that the at least one cluster of the plurality of clusters corresponds to anomalous network activity, causing a network connection of at least one device included in the at least one cluster to be blocked.

2. The method of claim 1 , wherein the graph representing the network activity is generated using a subset of a plurality of IP addresses, wherein the subset of the plurality of IP addresses corresponds to a group of IP addresses having the most network connections and wherein the subset of the plurality of IP addresses contains fewer than all of the plurality of IP addresses.

3. The method of claim 1 , wherein identifying the plurality of clusters of network activity is based on a machine learning classifier.

4. The method of claim 1 , wherein identifying the plurality of clusters of network activity is based on a neural network.

5. The method of claim 1 , wherein generating the representation of the graph representing the network activity comprises applying a t-Stochastic Neighbor Embedding (t-SNE) technique to the graph representing the network activity.

6. A system for detecting anomalous network activity, the system comprising:

a memory; and

a hardware processor coupled to the memory that is configured to:

generate a weighted directed graph representing network activity, wherein the weighted directed graph has a plurality of nodes and has an edge between two of the plurality of nodes, wherein each node of the graph indicates an IP address of a device participating in the network activity, and wherein the edge has at least one weight, wherein the at least one weight includes at least one of: a number of connections between the two of the plurality of nodes, an average number of bytes per packet sent between the two of the plurality of nodes, and a number of ports scanned;

generate a representation of the graph representing the network activity, wherein the representation of the graph representing the network activity reduces a dimensionality of information indicated in the graph representing the network activity, wherein the representation includes a plurality of adjacency matrices, wherein:

a first of the plurality of adjacency matrices represents one of: a number of connections between a source IP address and a destination IP address; an average number of bytes per packet sent between a source IP address and a destination IP address; and a number of ports scanned; and

a second of the plurality of adjacency matrices represents another of: the number of connections between a source IP address and a destination IP address; the average number of bytes per packet sent between a source IP address and a destination IP address; and the number of ports scanned;

identify a plurality of clusters of network activity from the representation of the graph including the plurality of adjacency matrices;

determine that at least one cluster of the plurality of clusters corresponds to anomalous network activity; and

in response to determining that the at least one cluster of the plurality of clusters corresponds to anomalous network activity, cause a network connection of at least one device included in the at least one cluster to be blocked.

7. The system of claim 6 , wherein the graph representing the network activity is generated using a subset of a plurality of IP addresses, wherein the subset of the plurality of IP addresses corresponds to a group of IP addresses having the most network connections and wherein the subset of the plurality of IP addresses contains fewer than all of the plurality of IP addresses.

8. The system of claim 6 , wherein identifying the plurality of clusters of network activity is based on a machine learning classifier.

9. The system of claim 6 , wherein identifying the plurality of clusters of network activity is based on a neural network.

10. The system of claim 6 , wherein generating the representation of the graph representing the network activity comprises applying a t-Stochastic Neighbor Embedding (t-SNE) technique to the graph representing the network activity.

11. A non-transitory computer-readable medium containing computer-executable instructions that, when executed by a processor, cause the processor to perform a method for detecting anomalous network activity, the method comprising:

generating a weighted directed graph representing network activity, wherein the weighted directed graph has a plurality of nodes and has an edge between two of the plurality of nodes, wherein each node of the graph indicates an IP address of a device participating in the network activity, and wherein the edge has at least one weight, wherein the at least one weight includes at least one of: a number of connections between the two of the plurality of nodes, an average number of bytes per packet sent between the two of the plurality of nodes, and a number of ports scanned;

generating a representation of the graph representing the network activity, wherein the representation of the graph representing the network activity reduces a dimensionality of information indicated in the graph representing the network activity, wherein the representation includes a plurality of adjacency matrices, wherein:

a first of the plurality of adjacency matrices represents one of: a number of connections between a source IP address and a destination IP address; an average number of bytes per packet sent between a source IP address and a destination IP address; and a number of ports scanned; and

a second of the plurality of adjacency matrices represents another of: the number of connections between a source IP address and a destination IP address; the average number of bytes per packet sent between a source IP address and a destination IP address; and the number of ports scanned;

identifying a plurality of clusters of network activity from the representation of the graph including the plurality of adjacency matrices;

determining that at least one cluster of the plurality of clusters corresponds to anomalous network activity; and

in response to determining that the at least one cluster of the plurality of clusters corresponds to anomalous network activity, causing a network connection of at least one device included in the at least one cluster to be blocked.

12. The non-transitory computer-readable medium of claim 11 , wherein the graph representing the network activity is generated using a subset of a plurality of IP addresses, wherein the subset of the plurality of IP addresses corresponds to a group of IP addresses having the most network connections and wherein the subset of the plurality of IP addresses contains fewer than all of the plurality of IP addresses.

13. The non-transitory computer-readable medium of claim 11 , wherein identifying the plurality of clusters of network activity is based on a machine learning classifier.

14. The non-transitory computer-readable medium of claim 11 , wherein identifying the plurality of clusters of network activity is based on a neural network.

15. The non-transitory computer-readable medium of claim 11 , wherein generating the representation of the graph representing the network activity comprises applying a t-Stochastic Neighbor Embedding (t-SNE) technique to the graph representing the network activity.

Assignments (2)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
Continuity (2)
Continuation 16138553 · Sep 21, 2018
Related Publication 20210226975A1 · Jul 22, 2021
References Cited (36)
US 7363656B2 · Weber et al. · 2008 [cited by applicant]
US 7610367B2 · Canright · 2009 [cited by examiner]
US 8625860B2 · Kveton · 2014 [cited by examiner]
US 8656161B2 · Nakae · 2014 [cited by examiner]
US 8762298B1 · Ranjan · 2014 [cited by examiner]
US 8792298B2 · Toennessen · 2014 [cited by applicant]
US 10476896B2 · DiValentin · 2019 [cited by examiner]
US 11146578B2 · Lem · 2021 [cited by examiner]
US 11982871B2 · Chamberlin · 2024 [cited by examiner]
US 20070209074A1 · Coffman · 2007 [cited by examiner]
US 20090070870A1 · Riordan · 2009 [cited by applicant]
US 20100057895A1 · Huang · 2010 [cited by applicant]
US 20150020199A1 · Neil · 2015 [cited by examiner]
US 20160014147A1 · Zoldi · 2016 [cited by examiner]
US 20160219066A1 · Vasseur · 2016 [cited by examiner]
US 20160352768A1 · Lefebvre · 2016 [cited by examiner]
US 20170149812A1 · Alton et al. · 2017 [cited by applicant]
US 20180013777A1 · DiValentin · 2018 [cited by examiner]
US 20180077180A1 · Zhang et al. · 2018 [cited by applicant]
US 20180097828A1 · Coskun · 2018 [cited by examiner]
US 20180255084A1 · Kotinas · 2018 [cited by examiner]
US 20190132224A1 · Verma · 2019 [cited by examiner]
US 20190166144A1 · Mirsky · 2019 [cited by examiner]
US 20190327252A1 · Grothendieck · 2019 [cited by examiner]
US 20210092140A1 · Kazerounian · 2021 [cited by examiner]
US 20220400130A1 · Kapoor · 2022 [cited by examiner]
US 20250106233A1 · Bishop, III · 2025 [cited by examiner]
KR 101888683 · 2018 [cited by applicant]
International Search Report and Written Opinion dated Jan. 10, 2020 in International Patent Application No. PCT/US2019/051666, pp. 1-10. [cited by applicant]
Liffreing, I., “How Brands are Using Apple's New AR Capabilities”, In Digday, Sep. 25, 2017, pp. 1-5. [cited by applicant]
Notice of Allowance dated Feb. 3, 2021 in U.S. Appl. No. 16/138,553, pp. 2-4. [cited by applicant]
Office Action dated Jul. 15, 2020 in U.S. Appl. No. 16/138,553, pp. 2-8. [cited by applicant]
Extended European Search Report dated May 13, 2022 in EP Patent Application No. 19862623.6, pp. 1-8. [cited by applicant]
International Patent Application No. PCT/US2019/051666, filed Sep. 18, 2019, pp. 1-27. [cited by applicant]
International Preliminary Report on Patentability dated Apr. 1, 2021 in International Patent Application No. PCT/US2019/051666, pp. 1-7. [cited by applicant]
U.S. Appl. No. 16/138,553, filed Sep. 21, 2018, pp. 1-13. [cited by applicant]