Method and system for model-based event-driven anomalous behavior detection

Inventors

Gauf, BernardBryman, MichaelMoore, ClaireNicoll, SamuelPonticello, David

Assignees

Innovative Defense Technologies Ltd

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-10929258-B1

Patent

Publication Date

2021-02-23

Expiration Date


Abstract

An embodiment of the present invention is directed to an optimal event-driven anomaly detection scheme. The present invention recognizes that anomaly detection based solely on rules-based (deterministic) or probabilistic analysis alone are insufficient to capture and respond to ever evolving, highly sophisticated threats that tend to persist within a system undetected for long periods of time. According to an embodiment of the present invention, a tiered detection scheme composed of behavioral analysis and machine-learned probabilistic system behaviors provides an optimal level of sensitivity to detect and respond to threats, and further limits the number of false positives identified.

Core Innovation

The invention provides model-based event-driven anomalous behavior detection. It uses a memory component storing data relating to training models and behavior detection and a computer server that generates an expected behavior model. The expected behavior model includes a baseline for anomaly detection responsive to a plurality of statistical classifiers.

During training, the system generates a plurality of behavioral classifiers that create a separation between normal behavior and abnormal behavior. This separation is achieved by subdividing features into sets of data with statistical characterizations, and then generating a collection of trained models of expected system probabilistic behavior for each event type and feature set of data sources. The trained models are used as the expected system behavior model during detection.

During anomalous behavior detection, the system reconstructs a stream of events in real-time based on one or more system messages. It extracts feature data relating to system operation representing at least CPU, network, and memory, identifies a current event with related system contextual state within a set span of time, and generates a system event timeline representing a breakdown of system operation in terms of individual events. Based at least in part on the system event timeline, it determines whether the current event is considered expected behavior or anomalous behavior.

Claims Coverage

The patent includes two independent claims, a system and a method, that share the same inventive structure. The claims cover training expected behavior models using statistical classifiers and behavioral classifiers, then performing model-based real-time anomalous behavior detection using reconstructed event streams, extracted system operation feature data, and an event timeline to determine whether a current event is expected or anomalous.

Training expected behavior models using statistical classifiers and feature subdivision

Generating an expected behavior model by generating a baseline for anomaly detection responsive to a plurality of statistical classifiers, and generating a plurality of behavioral classifiers to create a separation between normal behavior and abnormal behavior by subdividing features into sets of data with statistical characterizations.

Generating trained probabilistic expected behavior models per event type and feature set

Generating a collection of trained models of expected system probabilistic behavior for each event type and feature set of data sources.

Real-time reconstruction of an event stream from system messages

Reconstructing a stream of events in real-time based on one or more system messages.

Extracting system operation feature data and identifying contextual current events

Extracting feature data relating to system operation representing at least CPU, network and memory, and identifying a current event representing an occurrence of a set of actions and related system contextual state in a set span of time, where the related system contextual state is based on the expected system behavior model.

Generating a system event timeline and determining expected versus anomalous behavior

Responsive to the stream of events and extracted feature data, generating a system event timeline that represents a breakdown of system operation in terms of individual events, and based at least in part on the system event timeline determining whether the current event is considered expected behavior or an anomalous behavior.

The independent claims cover training an expected behavior model with a baseline driven by a plurality of statistical classifiers and behavioral classifiers created via subdivision of features into sets with statistical characterizations, then generating trained models of expected system probabilistic behavior per event type and feature set. The detection portion reconstructs real-time event streams from system messages, extracts feature data for system operation, generates a system event timeline from individual events, and determines whether a current event is expected or anomalous based at least in part on the timeline.

Stated Advantages

Improve sensitivity to advanced persistent threats while limiting false positives.

Documented Applications

Advanced persistent threats use case for anomalous behavior detection with improved separability using event context.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.