Systems and methods for detecting anomalous behaviors based on temporal profile
Abstract
The present disclosure is directed to a method of detecting anomalous behaviors based on a temporal profile. The method can include collecting, by a control system comprising a processor and memory, a set of network data communicated by a plurality of network nodes over a network during a time duration. The method can include identifying, by the control system, one or more seasonalities from the set of network data. The method can include generating, by the control system, a temporal profile based on the one or more identified seasonalities. The method can include detecting, by the control system and based on the temporal profile, an anomalous behavior performed by one of the plurality of network nodes. The method can include identifying, by the control system and based on the temporal profile, a root cause for the anomalous behavior.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for monitoring a network, comprising:
collecting, in a data-collection mode, a first set of network data communicated by a plurality of network nodes over the network during a first time duration; identifying one or more collection-mode seasonalities from the first set of network data; generating a temporal profile based on the identified one or more collection-mode seasonalities; switching from the data-collection mode to an anomaly-detection mode after the generating of the temporal profile; detecting based on the temporal profile, an anomalous behavior performed by one of the network nodes; and identifying based on the temporal profile, a root cause for the detected anomalous behavior.
2 . The method of claim 1 , wherein the first set of network data includes at least one of: a plurality of raw data packets transmitted over the network, source internet protocol (IP) addresses of the raw data packets, destination IP addresses of the raw data packets, source transmission control protocol (TCP) ports of the raw data packets, destination TCP ports of the raw data packets, source user datagram protocol (UDP) ports of the raw data packets, destination UDP ports of the raw data packets, and data sizes of the raw data packets.
3 . The method of claim 1 , further comprising:
segmenting the first time duration into a plurality of time periods; and dividing the first set of network data into groups based on a plurality of timestamps of the first set of network data, wherein each of the groups corresponds to one of the time periods, and the one or more collection-mode seasonalities are identified based on an occurrence rate of a certain behavior during each of the time periods.
4 . The method of claim 1 , wherein the identifying of the root cause for the detected anomalous behavior comprises:
determining, based on a highest-magnitude-interaction analysis, a network flow associated with the detected anomalous behavior; and identifying which of the network nodes are associated with the determined network flow.
5 . The method of claim 1 , wherein the detecting of the anomalous behavior comprises:
collecting a second set of network data communicated by the network nodes over the network during a second time duration; identifying one or more detection-mode seasonalities from the second set of network data; comparing the detection-mode seasonalities with the temporal profile to calculate a confidence margin; and determining that the calculated confidence margin exceeds a predetermined threshold.
6 . The method of claim 1 , further comprising:
identifying from the first set of network data, a network communication between two of the network nodes, at least one of which is on a list of known malicious network nodes; identifying one or more malicious seasonalities of the identified network communication; generating a malicious temporal profile based on the identified one or more malicious seasonalities; comparing the one or more collection-mode seasonalities to the malicious temporal profile to identify a malicious network communication with an unknown network node; and adding the unknown network node to the list of known malicious network nodes.
7 . The method of claim 1 , further comprising:
identifying from the first set of network data, a network communication between two of the network nodes, at least one of which is on a list of known trusted network nodes; identifying one or more trusted seasonalities of the identified network communication; generating a trusted temporal profile based on the identified one or more trusted seasonalities; comparing the one or more collection-mode seasonalities to the trusted temporal profile to identify a trusted network communication with an unknown network node; and adding the unknown network node to the list of known trusted network nodes.
8 . A computing device comprising:
memory; and one or more processors operatively coupled to the memory, wherein the one or more processors are configured to:
collect, in a data-collection mode, a first set of network data communicated by a plurality of network nodes over a network during a first time duration;
identify one or more collection-mode seasonalities from the first set of network data;
generate a temporal profile based on the identified one or more collection-mode seasonalities;
after switching from the data-collection mode to an anomaly-detection mode, detect based on the temporal profile, an anomalous behavior performed by one of the network nodes; and
identify based on the temporal profile, a root cause for the detected anomalous behavior.
9 . The computing device of claim 8 , wherein the first set of network data includes at least one of: a plurality of raw data packets transmitted over the network, source internet protocol (IP) addresses of the raw data packets, destination IP addresses of the raw data packets, source transmission control protocol (TCP) ports of the raw data packets, destination TCP ports of the raw data packets, source user datagram protocol (UDP) ports of the raw data packets, destination UDP ports of the raw data packets, and data sizes of the raw data packets.
10 . The computing device of claim 8 , wherein the one or more processors are further configured to:
segment the first time duration into a plurality of time periods; and divide the first set of network data into groups based on a plurality of timestamps of the first set of network data, wherein each of the groups corresponds to one of the time periods, and the one or more collection-mode seasonalities are identified based on an occurrence rate of a certain behavior during each of the time periods.
11 . The computing device of claim 8 , wherein the identifying of the root cause for the detected anomalous behavior comprises:
determining, based on a highest-magnitude-interaction analysis, a network flow associated with the detected anomalous behavior; and identifying which of the network nodes are associated with the determined network flow.
12 . The computing device of claim 8 , wherein the detecting of the anomalous behavior comprises:
collecting a second set of network data communicated by the network nodes over the network during a second time duration; identifying one or more detection-mode seasonalities from the second set of network data; comparing the detection-mode seasonalities with the temporal profile to calculate a confidence margin; and determining that the calculated confidence margin exceeds a predetermined threshold.
13 . The computing device of claim 8 , wherein the one or more processors are further configured to:
identify from the first set of network data, a network communication between two of the network nodes, at least one of which is on a list of known malicious network nodes; identify one or more malicious seasonalities of the identified network communication; generate a malicious temporal profile based on the identified one or more malicious seasonalities; compare the one or more collection-mode seasonalities to the malicious temporal profile to identify a malicious network communication with an unknown network node; and add the unknown network node to the list of known malicious network nodes.
14 . The computing device of claim 8 , wherein the one or more processors are further configured to:
identify from the first set of network data, a network communication between two of the network nodes, at least one of which is on a list of known trusted network nodes; identify one or more trusted seasonalities of the identified network communication; generate a trusted temporal profile based on the identified one or more trusted seasonalities; compare the one or more collection-mode seasonalities to the trusted temporal profile to identify a trusted network communication with an unknown network node; and add the unknown network node to the list of known trusted network nodes.
15 . A non-transitory computer-readable medium comprising instructions that are executable by a computing device, wherein the instructions when executed cause the computing device to carry out a method for monitoring a network, the method comprising:
collecting, in a data-collection mode, a first set of network data communicated by a plurality of network nodes over the network during a first time duration; identifying one or more collection-mode seasonalities from the first set of network data; generating a temporal profile based on the identified one or more collection-mode seasonalities; switching from the data-collection mode to an anomaly-detection mode after the generating of the temporal profile; extracting characteristics from the temporal profile; detecting based on a collection-mode seasonality and a corresponding one of the extracted characteristics satisfying a predefined condition, an anomalous behavior performed by one of the network nodes; and identifying based on the temporal profile, a root cause for the detected anomalous behavior.
16 . The non-transitory computer-readable medium of claim 15 , wherein the first set of network data includes at least one of: a plurality of raw data packets transmitted over the network, source internet protocol (IP) addresses of the raw data packets, destination IP addresses of the raw data packets, source transmission control protocol (TCP) ports of the raw data packets, destination TCP ports of the raw data packets, source user datagram protocol (UDP) ports of the raw data packets, destination UDP ports of the raw data packets, and data sizes of the raw data packets.
17 . The non-transitory computer-readable medium of claim 15 , the method further comprising:
segmenting the first time duration into a plurality of time periods; and dividing the first set of network data into groups based on a plurality of timestamps of the first set of network data, wherein each of the groups corresponds to one of the time periods, and the one or more collection-mode seasonalities are identified based on an occurrence rate of a certain behavior during each of the time periods.
18 . The non-transitory computer-readable medium of claim 15 , wherein the identifying of the root cause for the detected anomalous behavior comprises:
determining, based on a highest-magnitude-interaction analysis, a network flow associated with the detected anomalous behavior; and identifying which of the network nodes are associated with the determined network flow.
19 . The non-transitory computer-readable medium of claim 15 , wherein the detecting of the anomalous behavior comprises:
collecting a second set of network data communicated by the network nodes over the network during a second time duration; identifying one or more detection-mode seasonalities from the second set of network data; comparing the detection-mode seasonalities with the temporal profile to calculate a confidence margin; and determining that the calculated confidence margin exceeds a predetermined threshold.
20 . The non-transitory computer-readable medium of claim 15 , the method further comprising:
identifying from the first set of network data, a network communication between two of the network nodes, at least one of which is on a list of known malicious network nodes; identifying one or more malicious seasonalities of the identified network communication; generating a malicious temporal profile based on the identified one or more malicious seasonalities; comparing the one or more collection-mode seasonalities to the malicious temporal profile to identify a malicious network communication with an unknown network node; and adding the unknown network node to the list of known malicious network nodes.Join the waitlist — get patent alerts
Track US2023056101A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.