US2022337613A1PendingUtilityA1

Computer system providing anomaly detection within a virtual computing sessions and related methods

Assignee: CITRIX SYSTEMS INCPriority: May 16, 2017Filed: Jul 6, 2022Published: Oct 20, 2022
Est. expiryMay 16, 2037(~10.8 yrs left)· nominal 20-yr term from priority
G06F 9/452G06F 9/45558G06F 2221/034G06F 2009/45591G06F 21/577H04L 67/14G06F 2009/45579G06N 20/00H04L 67/10H04L 63/1425G06F 21/53G06N 20/10G06F 21/552G06F 2009/45595
62
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method may include running virtual sessions on a virtualization server corresponding to a published application for client devices associated with respective users. The client devices may have user input devices associated therewith, and the virtual sessions may be responsive to user input device traffic from different virtual drivers at the client devices over respective virtual channels. The method may further include collecting USB traffic relating to file copying based upon the traffic from the virtual drivers during the virtual sessions, determining baseline user input traffic patterns for the collected USB traffic and a normal usage pattern for the published application, monitoring traffic over the virtual channels at the virtualization server during a new virtual session for a given client device and detecting an anomaly therein relative to the baseline user input traffic patterns and the normal usage pattern, and generating an anomaly alert.

Claims

exact text as granted — not AI-modified
1 . A method comprising:
 running virtual sessions on a virtualization server corresponding to a published application for a plurality of client devices associated with respective users, the client devices having user input devices associated therewith, and the virtual sessions being responsive to user input device traffic from a plurality of different virtual drivers at the client devices over a plurality of respective virtual channels;   collecting universal serial bus (USB) traffic relating to file copying based upon the traffic from the virtual drivers of respective client devices during the virtual sessions across the plurality of virtual channels;   determining baseline user input traffic patterns for the collected USB traffic for the users at the virtualization server, and a normal usage pattern for the published application;   monitoring traffic over the virtual channels at the virtualization server during a new virtual session for a given client device and detecting an anomaly therein relative to the baseline user input traffic patterns for different users and the normal usage pattern for the published application; and   generating an anomaly alert based upon detecting the anomaly.   
     
     
         2 . The method of  claim 1  wherein the user input devices comprise keyboards; and wherein determining the baseline user input traffic patterns further comprises determining the baseline user input traffic patterns based upon traffic from the keyboards to the client devices during the virtual sessions. 
     
     
         3 . The method of  claim 2  wherein determining the baseline user input traffic patterns further comprises determining the baseline user input traffic patterns based upon a typing speed associated with the traffic from the keyboards during the virtual sessions. 
     
     
         4 . The method of  claim 1  wherein the client devices further have input/output (I/O) ports associated therewith; and wherein determining the baseline user input traffic patterns comprises determining the baseline user input traffic patterns also based upon traffic associated with the I/O ports. 
     
     
         5 . The method of  claim 1  wherein determining the baseline user input traffic patterns comprises determining the baseline user input traffic patterns based upon machine learning. 
     
     
         6 . The method of  claim 1  wherein detecting comprises detecting the anomaly based upon a multi-variant Gaussian distribution. 
     
     
         7 . The method of  claim 1  wherein the virtual sessions comprise at least one of virtual desktop sessions and virtual application sessions. 
     
     
         8 . A virtualization server comprising:
 a memory and a processor configured to cooperate with the memory to
 run virtual sessions on a virtualization server corresponding to a published application for a plurality of client devices associated with respective users, the client devices having user input devices associated therewith, and the virtual sessions being responsive to user input device traffic from a plurality of different virtual drivers at the client devices over a plurality of respective virtual channels; 
 collect universal serial bus (USB) traffic based upon the traffic relating to file copying from the virtual drivers of respective client devices during the virtual sessions across the plurality of virtual channels; 
 determine baseline user input traffic patterns for the collected USB traffic for the users, and a normal usage pattern for the published application; 
 monitor traffic over the virtual channels during a new virtual session for a given client device and detect an anomaly therein relative to the baseline user input traffic patterns for different users and the normal usage pattern for the published application; and 
 generate an anomaly alert based upon detecting the anomaly. 
   
     
     
         9 . The virtualization server of  claim 8  wherein the user input devices comprise keyboards; and wherein the processor determines the baseline user input traffic patterns further based upon traffic from the keyboards to the client devices during the virtual sessions. 
     
     
         10 . The virtualization server of  claim 9  wherein the processor determines the baseline user input traffic patterns based upon a typing speed associated with the traffic from the keyboards during the virtual sessions. 
     
     
         11 . The virtualization server of  claim 8  wherein the client devices further have input/output (I/O) ports associated therewith; and wherein the processor determines the baseline user input traffic patterns also based upon traffic associated with the I/O ports. 
     
     
         12 . The virtualization server of  claim 8  wherein the processor determines the baseline user input traffic patterns based upon machine learning. 
     
     
         13 . The virtualization server of  claim 8  wherein the processor detects the anomaly based upon a multi-variant Gaussian distribution. 
     
     
         14 . The virtualization server of  claim 8  wherein the virtual sessions comprise at least one of virtual desktop sessions and virtual application sessions. 
     
     
         15 . A non-transitory computer-readable medium having computer-executable instructions for causing a processor of a virtualization server to perform steps comprising:
 running virtual sessions on the virtualization server corresponding to a published application for a plurality of client devices associated with respective users, the client devices having user input devices associated therewith, and the virtual sessions being responsive to user input device traffic from a plurality of different virtual drivers at the client devices over a plurality of respective virtual channels;   collecting universal serial bus (USB) traffic relating to file copying based upon the traffic from the virtual drivers of respective client devices during the virtual sessions across the plurality of virtual channels;   determining baseline user input traffic patterns for the collected USB traffic for the users over a period of time, and a normal usage pattern for the published application;   monitoring traffic over the virtual channels during a new virtual session for a given client device and detecting an anomaly therein relative to the user input baseline traffic patterns for different users and the normal usage pattern for the published application; and   generating an anomaly alert based upon detecting the anomaly.   
     
     
         16 . The non-transitory computer-readable medium of  claim 15  wherein the user input devices comprise keyboards; and wherein determining the baseline user input traffic patterns further comprises determining the baseline user input traffic patterns based upon traffic from the keyboards to the client devices during the virtual sessions. 
     
     
         17 . The non-transitory computer-readable medium of  claim 16  wherein determining the baseline user input traffic patterns further comprises determining the baseline user input traffic patterns based upon a typing speed associated with the traffic from the keyboards during the virtual sessions. 
     
     
         18 . The non-transitory computer-readable medium of  claim 15  wherein the client devices further have input/output (I/O) ports associated therewith; and wherein determining the baseline user input traffic patterns further comprises generating the baseline user input traffic patterns based upon traffic associated with the I/O ports. 
     
     
         19 . The non-transitory computer-readable medium of  claim 15  wherein determining the baseline user input traffic patterns comprises determining the baseline user input traffic patterns based upon machine learning. 
     
     
         20 . The non-transitory computer-readable medium of  claim 15  wherein detecting comprises detecting the anomaly based upon a multi-variant Gaussian distribution.

Join the waitlist — get patent alerts

Track US2022337613A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.