MLchartDataset catalogue

Patent · US11381583B1 · B1 · US

Systems and methods for detecting anomalous system or network behavior

(11) Publication number
US11381583B1
(21) Application number
16/178,284
(22) Filing date
2018-11-01
(30) Priority date
2017-11-03
(43) Publication date
2022-07-05
(45) Date of grant
2022-07-05
(51) IPC
G06F 11/00; G06F 11/34; G06F 17/16; G06K 9/62; G06N 3/08; H04L 9/40
(52) CPC
  • H04L Transmission of digital information, e.g. telegraphic communication: 63/1425
  • G06F Electric digital data processing: 11/008, 11/0751, 11/3055, 11/3419, 11/3447, 17/16, 17/18, 18/214, 2201/81
  • G06K Graphical data reading; presentation of data; record carriers; handling record carriers: 9/6256
  • G06N Computing arrangements based on specific computational models: 3/045, 3/0464, 3/08, 3/09
  • G06V Image or video recognition or understanding: 10/774, 10/82
(73) Assignee
Dimensionalmechanics Inc
(72) Inventors
Jason K. Ellis; Rajeev Dutt
(54) Title
Systems and methods for detecting anomalous system or network behavior
(57) Abstract

A system and associated methods for the detection of anomalous behavior in a system. In some embodiments, time-series data that is obtained from the system (such as log data) may be used as an input to a process that converts the data into greyscale values. The greyscale values are used to construct an “image” of the system operation that is used as an input to a convolutional neural network (CNN). The image is used to train the neural network so that the neural network is able to recognize when other input “images” constructed from time-series data are anomalous or otherwise indicative of a difference between the prior (and presumed normal or acceptable) and the current operation of the system.

Full text
View on Google Patents

Claims (14)

  1. A method for detecting anomalous behavior in a system, comprising: acquiring a set of time-series data generated by or characterizing past behavior of the system; converting the set of time-series data into a set of grey-scale values of the past behavior of the system; forming a plurality of matrices from the set of grey-scale values of the past behavior of the system, wherein each matrix represents the grey-scale values at a specific time or during a specific time interval as an image; training a neural network using the plurality of matrices of the past behavior of the system to determine a predicted state vector of the system at a future time, the future time determined by system entropy or causal correlation between events that occur in the system; acquiring time-series data representing a current operational state of the system; converting the set of time-series data representing the current operational state into grey-scale values of the current operational state; forming a matrix from the grey-scale values of the current operational state; inputting the formed matrix of the current operational state to the trained neural network, the neural network trained to: determine a predicted state vector of the system based on the formed matrix of the current operational state; compare the predicted state vector of the system at a predicted time to the actual state vector of the system at the predicted time; identify a difference between the predicted state vector and the actual state vector of the system at the predicted time; generate an output from the trained neural network that includes an indication that the predicted state vector and the actual state vector are different at the predicted time; and determining that the output indicates the presence of an anomaly in the system based on the indication that the predicted state vector and the actual state vector are different at the predicted time; and generating an alert in response to the indication of the presence of the anomaly.
  2. The method of claim 1, wherein the time-series data of the past behavior of the system represents a value of a parameter or a characteristic of the system at a specific time or during a specific time interval in the past.
  3. The method of claim 1, wherein the neural network is a convolutional neural network (CNN).
  4. The method of claim 1, wherein the set of time-series data of the past behavior of the system is one of data representing TCP/IP traffic, GPU or CPU utilization, hard disk read/write actions, or memory utilization.
  5. The method of claim 1, wherein the neural network is further trained to determine a probability that the system is operating in a normal state, a probability that a system anomaly has occurred, or an image describing a future state of the system.
  6. The method of claim 5, wherein the output represents the probability that the system is operating in a normal state, and determining if the output indicates the presence of an anomaly further comprises determining if the probability is less than a threshold value.
  7. The method of claim 1, wherein the system is a network of nodes with a connection between the nodes.
  8. An apparatus for detecting anomalous behavior in a system, comprising: an electronic processor programmed with a set of executable instructions; an electronic data storage in which are stored the set of executable instructions, wherein the set of instructions includes instructions, which when executed, cause the apparatus to implement one or more processes to acquire a set of time-series data generated by or characterizing past behavior of the system; convert the set of time-series data into a set of grey-scale values of the past behavior of the system; form a plurality of matrices from the set of grey-scale values of the past behavior of the system, wherein each matrix represents the grey-scale values at a specific time or during a specific time interval as an image; train a neural network using the plurality of matrices of the past behavior of the system to determine a predicted state vector of the system at a future time, the future time determined by system entropy or causal correlation between events that occur in the system; acquire time-series data representing a current operational state of the system; convert the set of time-series data representing the current operational state into grey-scale values of the current operational state; form a matrix from the grey-scale values of the current operational state; input the formed matrix of the current operational state to the trained neural network, the neural network trained to: determine a predicted state vector of the system based on the formed matrix of the current operational state; compare the predicted state vector of the system at a predicted time to the actual state vector of the system at the predicted time; identify a difference between the predicted state vector and the actual state vector of the system at the predicted time; generate an output from the trained neural network that includes an indication that the predicted state vector and the actual state vector are different at the predicted time; determine that the output indicates the presence of an anomaly in the system based on the indication that the predicted state vector and the actual state vector are different at the predicted time; and generate an alert in response to the indication of the presence of the anomaly.
  9. The apparatus of claim 8, wherein the time series data of the past behavior of the system represents a value of a parameter or a characteristic of the system at a specific time or during a specific time interval in the past.
  10. The apparatus of claim 8, wherein the neural network is a convolutional neural network (CNN).
  11. The apparatus of claim 8, wherein the set of time-series data of the past behavior of the system is one of data representing TCP/IP traffic, GPU or CPU utilization, hard disk read/write actions, or memory utilization.
  12. The apparatus of claim 8, wherein the neural network is further trained to determine a probability that the system is operating in a normal state, a probability that a system anomaly has occurred, or an image describing a future state of the system.
  13. The apparatus of claim 12, wherein the output represents the probability that the system is operating in a normal state, and determining if the output indicates the presence of an anomaly further comprises determining if the probability is less than a threshold value.
  14. The apparatus of claim 8, wherein the system is a network of nodes with a connection between the nodes.

Description

Computer and data transmission networks are important parts of the infrastructure used by companies, the Government, and the public to exchange messages, transfer information, access services, and perform important tasks. As a result, the systems, devices, and networks involved in performing such tasks are relied upon to be secure and to be operating properly. The need to ensure this type of secure and reliable behavior has led to the development of methods for managing networks and detecting anomalous behaviors, with the expectation that by detecting such anomalous behaviors, security breaches and other harmful actions (or attempts at such actions) can be identified and prevented (or in some cases, remedied) more efficiently.

Conventionally, network behavior anomaly detection (NBAD) is the term used to describe continuous monitoring of a proprietary network for an unusual event, for an event or set of events suggesting an anomaly, or for detecting suggestive trends in network behavior or operations. NBAD is an integral part of network behavior analysis (NBA), which offers an additional layer of security to that provided by traditional anti-threat applications such as firewalls, antivirus software and spyware-detection software. An NBAD program typically tracks critical network characteristics in real-time and generates an alarm or warning, or takes a specified corrective action if an anomaly or suggestive trend in network characteristics is detected. This is important, as such an anomaly or trend might indicate the presence of a threat or an attempt to cause harm to the network or its users.

Citations (4)

  • US7181768B1
  • US20180115567A1
  • US20170364792A1
  • US20180260697A1
Record as JSON
{
  "publication_number": "US11381583B1",
  "country": "US",
  "kind": "B1",
  "title": "Systems and methods for detecting anomalous system or network behavior",
  "abstract": "A system and associated methods for the detection of anomalous behavior in a system. In some embodiments, time-series data that is obtained from the system (such as log data) may be used as an input to a process that converts the data into greyscale values. The greyscale values are used to construct an “image” of the system operation that is used as an input to a convolutional neural network (CNN). The image is used to train the neural network so that the neural network is able to recognize when other input “images” constructed from time-series data are anomalous or otherwise indicative of a difference between the prior (and presumed normal or acceptable) and the current operation of the system.",
  "claims": [
    "1. A method for detecting anomalous behavior in a system, comprising: acquiring a set of time-series data generated by or characterizing past behavior of the system; converting the set of time-series data into a set of grey-scale values of the past behavior of the system; forming a plurality of matrices from the set of grey-scale values of the past behavior of the system, wherein each matrix represents the grey-scale values at a specific time or during a specific time interval as an image; training a neural network using the plurality of matrices of the past behavior of the system to determine a predicted state vector of the system at a future time, the future time determined by system entropy or causal correlation between events that occur in the system; acquiring time-series data representing a current operational state of the system; converting the set of time-series data representing the current operational state into grey-scale values of the current operational state; forming a matrix from the grey-scale values of the current operational state; inputting the formed matrix of the current operational state to the trained neural network, the neural network trained to: determine a predicted state vector of the system based on the formed matrix of the current operational state; compare the predicted state vector of the system at a predicted time to the actual state vector of the system at the predicted time; identify a difference between the predicted state vector and the actual state vector of the system at the predicted time; generate an output from the trained neural network that includes an indication that the predicted state vector and the actual state vector are different at the predicted time; and determining that the output indicates the presence of an anomaly in the system based on the indication that the predicted state vector and the actual state vector are different at the predicted time; and generating an alert in response to the indication of the presence of the anomaly.",
    "2. The method of claim 1, wherein the time-series data of the past behavior of the system represents a value of a parameter or a characteristic of the system at a specific time or during a specific time interval in the past.",
    "3. The method of claim 1, wherein the neural network is a convolutional neural network (CNN).",
    "4. The method of claim 1, wherein the set of time-series data of the past behavior of the system is one of data representing TCP/IP traffic, GPU or CPU utilization, hard disk read/write actions, or memory utilization.",
    "5. The method of claim 1, wherein the neural network is further trained to determine a probability that the system is operating in a normal state, a probability that a system anomaly has occurred, or an image describing a future state of the system.",
    "6. The method of claim 5, wherein the output represents the probability that the system is operating in a normal state, and determining if the output indicates the presence of an anomaly further comprises determining if the probability is less than a threshold value.",
    "7. The method of claim 1, wherein the system is a network of nodes with a connection between the nodes.",
    "8. An apparatus for detecting anomalous behavior in a system, comprising: an electronic processor programmed with a set of executable instructions; an electronic data storage in which are stored the set of executable instructions, wherein the set of instructions includes instructions, which when executed, cause the apparatus to implement one or more processes to acquire a set of time-series data generated by or characterizing past behavior of the system; convert the set of time-series data into a set of grey-scale values of the past behavior of the system; form a plurality of matrices from the set of grey-scale values of the past behavior of the system, wherein each matrix represents the grey-scale values at a specific time or during a specific time interval as an image; train a neural network using the plurality of matrices of the past behavior of the system to determine a predicted state vector of the system at a future time, the future time determined by system entropy or causal correlation between events that occur in the system; acquire time-series data representing a current operational state of the system; convert the set of time-series data representing the current operational state into grey-scale values of the current operational state; form a matrix from the grey-scale values of the current operational state; input the formed matrix of the current operational state to the trained neural network, the neural network trained to: determine a predicted state vector of the system based on the formed matrix of the current operational state; compare the predicted state vector of the system at a predicted time to the actual state vector of the system at the predicted time; identify a difference between the predicted state vector and the actual state vector of the system at the predicted time; generate an output from the trained neural network that includes an indication that the predicted state vector and the actual state vector are different at the predicted time; determine that the output indicates the presence of an anomaly in the system based on the indication that the predicted state vector and the actual state vector are different at the predicted time; and generate an alert in response to the indication of the presence of the anomaly.",
    "9. The apparatus of claim 8, wherein the time series data of the past behavior of the system represents a value of a parameter or a characteristic of the system at a specific time or during a specific time interval in the past.",
    "10. The apparatus of claim 8, wherein the neural network is a convolutional neural network (CNN).",
    "11. The apparatus of claim 8, wherein the set of time-series data of the past behavior of the system is one of data representing TCP/IP traffic, GPU or CPU utilization, hard disk read/write actions, or memory utilization.",
    "12. The apparatus of claim 8, wherein the neural network is further trained to determine a probability that the system is operating in a normal state, a probability that a system anomaly has occurred, or an image describing a future state of the system.",
    "13. The apparatus of claim 12, wherein the output represents the probability that the system is operating in a normal state, and determining if the output indicates the presence of an anomaly further comprises determining if the probability is less than a threshold value.",
    "14. The apparatus of claim 8, wherein the system is a network of nodes with a connection between the nodes."
  ],
  "description_excerpt": "Computer and data transmission networks are important parts of the infrastructure used by companies, the Government, and the public to exchange messages, transfer information, access services, and perform important tasks. As a result, the systems, devices, and networks involved in performing such tasks are relied upon to be secure and to be operating properly. The need to ensure this type of secure and reliable behavior has led to the development of methods for managing networks and detecting anomalous behaviors, with the expectation that by detecting such anomalous behaviors, security breaches and other harmful actions (or attempts at such actions) can be identified and prevented (or in some cases, remedied) more efficiently.\n\nConventionally, network behavior anomaly detection (NBAD) is the term used to describe continuous monitoring of a proprietary network for an unusual event, for an event or set of events suggesting an anomaly, or for detecting suggestive trends in network behavior or operations. NBAD is an integral part of network behavior analysis (NBA), which offers an additional layer of security to that provided by traditional anti-threat applications such as firewalls, antivirus software and spyware-detection software. An NBAD program typically tracks critical network characteristics in real-time and generates an alarm or warning, or takes a specified corrective action if an anomaly or suggestive trend in network characteristics is detected. This is important, as such an anomaly or trend might indicate the presence of a threat or an attempt to cause harm to the network or its users.",
  "cpc": [
    "H04L 63/1425",
    "G06F 11/008",
    "G06F 11/0751",
    "G06F 11/3055",
    "G06F 11/3419",
    "G06F 11/3447",
    "G06F 17/16",
    "G06F 17/18",
    "G06F 18/214",
    "G06F 2201/81",
    "G06K 9/6256",
    "G06N 3/045",
    "G06N 3/0464",
    "G06N 3/08",
    "G06N 3/09",
    "G06V 10/774",
    "G06V 10/82"
  ],
  "ipc": [
    "G06F 11/00",
    "G06F 11/34",
    "G06F 17/16",
    "G06K 9/62",
    "G06N 3/08",
    "H04L 9/40"
  ],
  "assignees": [
    "Dimensionalmechanics Inc"
  ],
  "inventors": [
    "Jason K. Ellis",
    "Rajeev Dutt"
  ],
  "filing_date": "2018-11-01",
  "publication_date": "2022-07-05",
  "grant_date": "2022-07-05",
  "priority_date": "2017-11-03",
  "application_number": "US-201816178284-A",
  "family_id": "82261302",
  "cited_by_count": 13,
  "citations": [
    "US7181768B1",
    "US20180115567A1",
    "US20170364792A1",
    "US20180260697A1"
  ]
}

Record 1,111 of 8,000 in Patents full text (MLC-0201). Request the full dataset.