Continuous learning for intrusion detection
20 claims: 5 independent, 15 dependent
- 1継続的に学習するモデルを介してネットワーク上で提供されるオンラインサービスを保護するための 、プロセッサによって実行される 方法であって、前記オンラインサービスから1つまたは複数のネットワークセッションに関連するセキュリティ信号のセットを収集するステップであって、前記セキュリティ信号のセットは、時間のローリングウィンドウで収集される、ステップと、前記セキュリティ信号のセットのそれぞれのセキュリティ信号が悪意のあるものか無害であるかを識別するステップと、前記時間のローリングウィンドウの均衡させた訓練データセットを、悪意のある信号それぞれについて識別された攻撃タイプに基づいて、前記セキュリティ信号のセットのうち悪意のある信号を均衡させるステップと、無害の信号がそれぞれ受信されるデバイスのタイプに基づいて、前記セキュリティ信号のセットのうち無害の信号を均衡させるステップと、前記悪意のある信号を前記無害の信号と交差結合することにより、前記悪意のある信号を前記無害の信号と均衡させるステップとにより、生成するステップと、前記均衡させた訓練データセットに基づいて予測モデルを生成するステップと、を含み、前記オンラインサービスから新しいネットワークセッションに関連する追加のセキュリティ信号を受信することに応答して、前記追加のセキュリティ信号が悪意のあるものか無害のものかが判定するために前記予測モデルが適用される、方法。
- 2前記セキュリティ信号のセットのそれぞれのセキュリティ信号が悪意のあるものか無害であるかを識別するステップが、それぞれのセキュリティ信号を生成モデルで検査するステップであって、前記生成モデルは、前記均衡させた訓練データセットに従ってモデルトレーナーによって生成され、所与のセキュリティ信号が悪意のあるものか無害であるかの検出結果を生成するよう構成される、ステップと、前記検出結果を分析者ユーザに送信するステップと、前記検出結果に関して前記分析者ユーザからアクションを受け取るのに応答して、前記所与のセキュリティ信号が悪意のあるものか無害であるかを示すように前記検出結果を更新するステップと、をさらに含む、請求項1に記載の方法。
- 3自動化アタッカーが、前記オンラインサービスに対する攻撃を模擬し、前記セキュリティ信号のセットのそれぞれのセキュリティ信号が悪意のあるものか無害であるかを識別するステップが、前記攻撃に応答して生成された前記セキュリティ信号を識別する通知を、前記自動化アタッカーから受け取るステップと、前記攻撃に応答して生成された前記セキュリティ信号を、前記検出結果に関わらず悪意のあるものとして扱うステップと、をさらに含む、請求項2に記載の方法。
- 4前記セキュリティ信号のセットのそれぞれのセキュリティ信号が悪意のあるものか無害であるかを識別するステップが、前記所与のセキュリティ信号から特徴を抽出するステップと、前記所与のセキュリティ信号から抽出された前記特徴が、ある攻撃タイプを定義するものとして管理ユーザによって指定された特徴セットを満たすかどうかを判定するステップと、抽出された前記特徴が前記特徴セットを満たすと判定するのに応答して、前記所与のセキュリティ信号を悪意のあるものと指定するステップと、抽出された前記特徴が前記特徴セットを満たさないと判定するのに応答して、前記所与のセキュリティ信号を無害と指定するステップと、をさらに含む、請求項2に記載の方法。
- 5悪意のある信号それぞれについて識別された攻撃タイプに基づいて、前記セキュリティ信号のセットのうち前記悪意のある信号を均衡させるステップは、前記悪意のある信号に対して観察された攻撃タイプのセットについて、攻撃タイプの総対数を、前記攻撃タイプのセット中で実際よりも少なく示された攻撃タイプの相対量を増加させるステップと、および前記攻撃タイプのセット中で実際よりも多く示された攻撃タイプの相対量を減少させるステップと、のうち少なくとも一方によって均衡させるステップと、をさらに含む、請求項4に記載の方法。
- 6前記特徴セットは、前記管理ユーザから与えられる構造化文書中で識別され、前記構造化文書は、前記セキュリティ信号のセット中で観察すべき特徴タイプおよびデータフィールドを特定し、前記特徴セットの特徴は、コードを修正する必要なしに、前記構造化文書に基づいて前記セキュリティ信号のセットから動的に抽出される、請求項4に記載の方法。
- 7過去のデータ信号が前記セキュリティ信号のセットに含められる、請求項1に記載の方法。
- 8前記無害の信号がそれぞれ受信されるデバイスのタイプに基づいて、前記セキュリティ信号のセットのうち無害の信号を均衡させるステップは、前記ローリングウィンドウ内で少なくとも1つの悪意のある信号が収集された前記オンラインサービス内のデバイスを識別するステップと、前記デバイスに関連する無害の信号を、前記セキュリティ信号のセットから除去するステップと、をさらに含む、請求項1に記載の方法。
- 9前記悪意のある信号を無害の信号と交差結合することにより、前記悪意のある信号を前記無害の信号と均衡させるステップは、前記均衡させた訓練データセットについて複数の攻撃シナリオを生成するために前記悪意のある信号を前記無害の信号と交差結合するステップをさらに含み、前記複数の攻撃シナリオは、前記悪意のある信号と前記無害の信号とを含む、請求項8に記載の方法。
- 10前記ローリングウィンドウ内の前記セキュリティ信号のセットを収集するステップは、現在の時刻からの前記ローリングウィンドウを定義する時間フレームを識別するステップと、前記現在の時刻で前記オンラインサービスから新しいセキュリティ信号を受信するステップと、前記現在の時刻で受信した前記新しいセキュリティ信号を前記セキュリティ信号のセットに追加するステップと、前記現在の時刻からの前記時間フレームの外側で前記セキュリティ信号のセットに追加された既存のセキュリティ信号を識別するステップと、前記セキュリティ信号のセットから、前記現在の時刻からの前記時間フレームの外側で前記セキュリティ信号のセットに追加されたと識別された前記既存のセキュリティ信号を除去するステップとをさらに含む、請求項1に記載の方法。
- 11継続的に学習するモデルを介してネットワーク上で提供されるオンラインサービスをセキュリティ保護するためのシステムであって、プロセッサと、命令を含むメモリ記憶装置と、を備え、前記命令は、前記プロセッサによって実行された時に、前記オンラインサービス内のデバイスからセキュリティ信号を受信することであって、前記セキュリティ信号は1つまたは複数のネットワークセッションと関連付けられる、受信することと、前記セキュリティ信号のそれぞれから特徴ベクトルを抽出することであって、所与の特徴ベクトルは、所与のセキュリティ信号が受信される所与のデバイスの状態を表す数値を提供する、抽出することと、関連付けられた予測モデルを介して前記特徴ベクトルそれぞれの検出結果を生成することであって、所与の検出結果は、所与のネットワークセッションと関連付けられた前記所与のセキュリティ信号が前記所与のデバイス上で悪意のある活動を示唆するか無害の活動を示唆するかを識別する、生成することと、ローリングウィンドウを定義することであって、前記ローリングウィンドウは、現在の時刻からのある時間フレーム内に受信された複数のセキュリティ信号および関連付けられた検出結果を含む、定義することと、前記ローリングウィンドウについて均衡させた訓練データセットを生成することと、を行うように動作可能であり、前記均衡させた訓練データセットを生成するために、前記システムがさらに、悪意のある活動を示唆するものと識別された前記ローリングウィンドウ内の前記セキュリティ信号それぞれの攻撃タイプを識別し、前記ローリングウィンドウ内で実際よりも少なく示された攻撃タイプで識別されたセキュリティ信号の量を、実際よりも多く示された攻撃タイプで識別されたセキュリティ信号の量に対して増加させ、悪意のある活動を示唆するものと識別された前記セキュリティ信号を、無害の活動を示唆するものと識別されたセキュリティ信号と交差結合して、前記ローリングウィンドウについての攻撃シナリオを生成し、機械学習アルゴリズムに従って、前記均衡させた訓練データセットに基づいて前記関連付けられた予測モデルを更新する、ように構成される、システム。
- 12前記関連付けられた予測モデルを更新することは、前記均衡させた訓練データセットに従って、前記セキュリティ信号が前記デバイス上で悪意のある活動を示唆するか無害の活動を示唆するかを、開発モデルの方が正確に識別することを、前記機械学習アルゴリズムが示すのに応答して、前記検出結果を生成するために使用される生成モデルを、前記機械学習アルゴリズムに従って前記均衡させた訓練データセットから開発された前記開発モデルに置き換えることを含む、請求項11に記載のシステム。
- 13過去の信号が前記ローリングウィンドウに含められ、前記過去の信号は、前記時間フレームの外側で収集されたセキュリティ信号を含む、請求項11に記載のシステム。
- 14前記オンラインサービス内の前記デバイスから受信された前記セキュリティ信号は、自動化アタッカーが前記オンラインサービスに対して既知の悪意のある活動を行うのに応答して発生したセキュリティ信号を含み、前記自動化アタッカーが前記既知の悪意のある活動を行うのに応答して発生した前記セキュリティ信号に対して生成された前記検出結果は、前記自動化アタッカーからの通知に基づいて、前記所与のセキュリティ信号が悪意のある活動を示唆することを示すように設定される、請求項11に記載のシステム。
- 15前記均衡させた訓練データセットを生成するために、前記システムがさらに、無害の活動を示唆するものと識別されたセキュリティ信号が受信された特定のデバイスが、前記ローリングウィンドウ内で悪意のある活動を示唆するものと識別された1つまたは複数のセキュリティ信号と関連付けられていることを識別するのに応答して、無害の活動を示唆するものと識別された前記セキュリティ信号を前記ローリングウィンドウから除去するように構成される、請求項11に記載のシステム。
- 16前記均衡させた訓練データセットを生成するために、前記システムがさらに、無害の活動を示唆するものと識別された前記ローリングウィンドウ内の前記セキュリティ信号それぞれが受信されたデバイスのタイプを識別し、前記ローリングウィンドウ内で実際よりも少なく示されたデバイスタイプで識別されたセキュリティ信号の量を、実際よりも多く示されたデバイスタイプで識別されたセキュリティ信号に対して増加させる、ように構成される、請求項11に記載のシステム。
- 17継続的に学習するモデルを介してネットワーク上で提供されるオンラインサービスをセキュリティ保護するためのプロセッサ実行可能命令を含むコンピュータ可読記憶装置であって、前記プロセッサ実行可能命令は、前記オンラインサービスから1つまたは複数のネットワークセッションに関連するセキュリティ信号のセットを収集することであって、前記セキュリティ信号のセットは時間のローリングウィンドウ内で収集される、収集することと、所与のネットワークセッションと関連するそれぞれのセキュリティ信号が悪意のあるものか無害であるかを識別するために、予測モデルを介して前記セキュリティ信号のセットのそれぞれのセキュリティ信号を検査することであって、前記予測モデルは、管理ユーザによって定義された特徴ベクトルに基づいて、所与のセキュリティ信号が悪意のあるものか無害であるかの検出結果を生成するように構成される、検査することと、前記セキュリティ信号のセットを悪意のある信号または無害の信号として識別するために、前記セキュリティ信号のセットを前記検出結果に関連付けることと、均衡させた訓練データセットを生成するために、前記悪意のある信号を前記無害の信号と均衡させることと、前記悪意のある信号それぞれの攻撃タイプを識別することと、前記無害の信号のそれぞれが収集されたデバイスのタイプを識別することと、攻撃事例のセットを生成するために、前記ローリングウィンドウ内の悪意のある信号の各相対数を、識別された攻撃タイプに基づいて等しくすることと、識別された無害事例のセットを生成するために、前記ローリングウィンドウ内の無害の信号の各相対数を、識別されたデバイスタイプに基づいて等しくすることと、および前記攻撃事例のセット中の攻撃事例の数を、前記無害事例のセット中の無害事例の数に対して均衡させるために、前記攻撃事例のセットを前記無害事例のセットの少なくとも一部分と交差結合すること、を含むことと、前記均衡させた訓練データセットおよび機械学習アルゴリズムに基づいて前記予測モデルを精緻化することと、を含む、コンピュータ可読記憶装置。
- 18前記悪意のある信号を前記無害の信号と均衡させることは前記ローリングウィンドウ内で少なくとも1つの悪意のある信号が収集された前記オンラインサービス内でデバイスを識別することと、前記デバイスと関連する無害の信号を、前記セキュリティ信号のセットから除去することと、をさらに含む、請求項17に記載のコンピュータ可読記憶装置。
- 19前記予測モデルを介してそれぞれのセキュリティ信号を検査することは、前記検出結果を分析者ユーザに送信することと、前記検出結果に関連する分析者ユーザからのアクションを受け取るのに応答して、前記分析者ユーザからの前記アクションに照らして、前記所与のセキュリティ信号が悪意のあるものか無害であるかを示すように前記検出結果を更新することと、をさらに含む、請求項17に記載のコンピュータ可読記憶装置。
- 20前記特徴ベクトルは、1つまたは複数の攻撃タイプを識別するよう構成された予測モデルを定義するために前記管理ユーザによって与えられる構造化文書中で識別され る特 徴セットを含み、前記構造化文書は、前記セキュリティ信号のセット中で観察すべき特徴タイプおよびデータフィールドを特定し、前記特徴セットの特徴は、コードを修正する必要なしに、前記構造化文書に基づいて前記セキュリティ信号のセットから動的に抽出される、請求項17に記載のコンピュータ可読記憶装置。
Independent claims20
53 paragraphs, as filed
[0001] Computer networks are under constant threat from malicious parties attempting to gain unauthorized access to the systems hosted by them. The strategies used by malicious individuals to attack networks and the strategies used by network administrators to defend against attacks are constantly evolving in the light of each other and are of the malicious. A new exploit is added to the set and the ineffective exploit is destroyed. However, countermeasure implementations are often ex post facto, and network administrators must wait to identify the newest exploit before deploying the countermeasure, and the corresponding exploit is no longer in use. Occasionally decide when to stop deploying countermeasures. Correctly identifying and blocking the latest exploits is often difficult for network administrators, if they are not yet widespread or if they attack a small group of services offered on the network. Especially so.
<p>[0002] This overview is provided to introduce in simplified form a selection from the concepts further described in the section "Modes for Carrying Out the Invention" below. This overview is not intended to identify all the key or essential features of the subject matter of the patent claim, nor is it intended to assist in determining the scope of the subject matter of the claim.</p><p>[0003] The present invention provides computer storage devices including systems, methods, and instructions that provide continuous learning for intrusion detection. Multiple machine learning models are constantly retrained for network signals based on signals collected from machines and devices in the network that represent attack behavior and harmless behavior. By collecting signals using a rolling window, the model uses up-to-date data to identify attacks, and the model has its own ability to accurately detect attacks, which is the composition of recent data. It is continuously promoted and demoted to protect the network as it increases and decreases accordingly. Models deployed within an active generation network provide security analysts with near real-time detection of their own, and security analysts provide feedback on the accuracy of the model (eg, missed intrusions / false negatives, false positives, false positives). Provides identified intrusions) to further refine how the model is trained.</p><p>[0004] Attack signals are rare compared to harmless signals in order to improve the reliability of the training datasets used to constantly retrain and refine the detection model, thereby improving the model. And balance the attack signal with respect to a particular attack type. Overlaying harmless signals with various types of attack signals from other machines provides a balanced training set for training and refining the model. By balancing the signals of different attack types among the attack signals in the balanced training set, we ensure that the model is trained evenly for all attack types. It dynamically extracts the characteristics of the signal through a text-based configuration, thereby improving the flexibility of the model in responding to various feature sets suggesting attacks on the network.</p><p>[0005] In various embodiments, mimicking an attack with a known internal attacker increases the responsiveness of the network and generates additional attack signals. Similarly, by using historically significant attack signals in some embodiments, they are presented to the model even if certain types of attack signals are not observed in the rolling window. To do so.</p><p>[0006] By providing the network with a continuously learning intrusion detection model, the functionality of the devices and software in the network is improved. New forms of attacks are identified more quickly and reliably, thereby addressing computer-centric issues of how to improve network security. In addition, computing resources are not wasted in attempts to detect outdated forms of attack, thereby reducing the processing resources used to protect the network from malicious parties.</p><p>[0007] For example, it is carried out as a computer process, a computing system, or a manufactured product such as a device, a computer program product, or a computer-readable medium. According to one aspect, a computer program product is a computer storage medium that is readable by a computer system and encodes a computer program containing instructions for executing a computer processor.</p><p>[0008] Details of one or more embodiments will be revealed in the accompanying drawings and described below. Other features and benefits will become apparent from reading the detailed description below and reviewing the relevant drawings. It should be understood that the detailed description below is for illustration purposes only and does not limit the scope of the claims.</p><p>[0009] The accompanying drawings incorporated in and in part thereof of the present disclosure exemplify various embodiments.</p>
<figref num="1A">It is a figure of the exemplary security system which can carry out this disclosure together.</figref><figref num="1B">FIG. 5 is a diagram of an exemplary model training and selection system for use with the exemplary security system of Figure 1A where the disclosure can be implemented together.</figref><figref num="2">It is a flow chart showing a general step with an exemplary method of developing a training dataset for training a predictive model used to secure an online service.</figref><figref num="3">It is a flow chart showing a general step with an exemplary method of training and selecting a predictive model to be used to secure an online service.</figref><figref num="4">FIG. 3 is a block diagram illustrating an exemplary physical component of a computing device.</figref>
[0010] The following detailed description will refer to the accompanying drawings. Where possible, the same reference numerals used in the drawings and in the following description refer to the same or similar elements. Examples may be given, but modifications, adaptations, and other implementations are possible. For example, the elements exemplified in the drawings may be replaced, added, or modified, and the methods described herein replace, reorder, or change the steps of the disclosed method. It may be modified by adding. Therefore, the detailed description below is not restrictive and the appropriate scope is defined by the appended claims. The example may take the form of a hardware implementation, a completely software implementation, or a combination of software and hardware aspects. Therefore, the following detailed description should not be construed in a restrictive sense.
[0011] A computer-readable storage device including systems, methods, and instructions for providing improved network security through a continuously learned intrusion detection model is described herein. By providing the network with a continuously learning intrusion detection model, the functionality of the devices and software in the network is improved. New forms of attacks are identified more quickly and reliably, thereby addressing computer-centric issues of how to improve network security. In addition, computing resources are not wasted in attempting to detect outdated forms of attack, thereby reducing the processing resources used to protect the network from malicious parties.
[0012] FIG. 1A is an exemplary security system 100 to which this disclosure can be implemented. As shown in FIG. 1A, the online service 110 is connected by the security system 100 to various potentially harmless and potentially malicious users. The online service 110 presents a set of networked computing devices such as cloud data centers that provide "cloud" services to various users, including, but not limited to, the following: Is done. Infrastructure as a Service (IaaS) that provides an operating system and software for users to run on the device of online service 110. Platform as a Service (PaaS) where the user provides the software and the online service 110 provides the operating system and device. Alternatively, Software as a provides the user with both the operating system and software that the online service 110 runs on the device. Service (SaaS). A user seeking access to the online service 110 may be a legitimate user or exploit a security vulnerability to break into the online service 110 and perform malicious processes without legitimate permission, and / Alternatively, it may be a malicious person who obtains data from the online service 110.
[0013] The user is harmless, malicious, or the device is secure (not sending a malicious signal) or is at risk (malicious signal). Various security signals 115 from the online service 110 are collected and supplied to the generative model 120 to indicate whether a given session is malicious or harmless. Generates detection result 125. The security signal 115 includes event logs, network traces, system commands, etc., which are analyzed by the generative model 120 through training the generative model 120 to suggest malicious or harmless behavior. Obtain the characteristics to be judged and their characteristic values. For the purposes of this disclosure, the particular security signal 115 is referred to as "malicious" or "harmless" based on the actions within the online service 110 associated with generating the particular security signal 115. Also, as used herein, the term "feature" is a numerical attribute that is accepted by the "model" and is derived from one or more input signals related to the characteristics or behavior observed in the network. be. The model is a feature set (also called a model feature) defined by the analyst to convert the value of the feature into a predictive score or confidence in whether the feature indicates malicious or harmless activity. ) Is an algorithm that accepts.
[0014] A security signal 115 is provided to the generative model 120 to extract various features from the security signal 115. The generative model 120 is trained to identify malicious activity on the online service 110 against this security signal 115. The security signal 115 is a collection of one or more interrelated events that occur on the device inside the online service 110 and has several characteristics (eg, the port used, the IP address where the connection was made, the signal there). Device identification / type received from, user, action taken) may be included, and a subset of those features are extracted for inspection with a given generative model 120, and the security signal 115 is harmless. Determine if it is malicious or malicious. Combine features from one or more security signals 115 into a feature vector for analysis. Then, in various embodiments, the features may be scored to provide a numerical analysis of the features for input to the generative model 120.
[0015] For example, a given IP (Internet Protocol) address may be scored based on frequency of use, where the given IP address between rolling windows 130 is used more frequently. The values presented to the generative model 120 vary compared to less frequent use. On the other hand, if a confidential file is accessed, a prohibited action is taken, a communication with a blacklisted IP address is performed, etc., a binary value indicating that a dangerous state has occurred. The score may be provided to the generative model 120 in the security signal 115. Generative model 120 does not rely on whitelists or blacklists, and generative model training is a feature observed in security signal 115, as described in more detail with respect to FIGS. 1B, 2 and 3. The generative model can, over time, learn features that suggest intrusion into the online service 110, without blacklisting or whitelisting.
[0016] For a given security signal 115, the determination by the generative model 120 identifies whether the security signal 115 is harmless or malicious. These detection results 125 are associated with the security signal 115 to identify the security signal as either malicious or harmless. In some embodiments, at least some of these detection results 125 (eg, malicious detection results 125) are provided to the analyst user, who acts on the basis of the detection results 125 to act maliciously. You may deploy countermeasures against a user or attack, or determine that the detection result 125 supports a different judgment than that of the generative model 120. For example, if the generative model 120 shows a false negative for a malicious signal, the analyst may determine that the signal is actually malicious and indicate the action to be taken. In another example, if a false positive for a harmless signal is shown, the analyst can determine that the signal is actually harmless and indicate that no action should be taken. In a further example, if a true positive for a malicious action is shown, the analyst may indicate that no action should be taken or that an action different from that recommended by security system 100 should be taken. Corrections from the analyst are thereby used for further training and improvement of the model.
[0017] Further, the detection result 125 is observed in various aspects over the past d days (d can be set by the analyst user or another network administrator, for example, 2 days, 10 days, 15 days, etc.). Supplied to a database that stores the rolling window 130 of the security signal 115 and a database that stores the past signal 135 of the security signal 115 that should be used for training, whether or not it was seen in the last d days. .. The historical signal 135 is curete by the analyst user to include a security signal 115 associated with a known external attack. In an additional aspect, the predictive model is such that the analyst user curates the past signal 135 to include harmless signals that may appear suspicious or otherwise return false positives with respect to network intrusion. Ensure that you are trained to respond properly to signals that have been recorded to be difficult to identify properly.
[0018] The automated attacker 140 tests the security of the online service 110 using known patterns of attacks and exploits and provides known results for use in conjunction with the detection result 125 generated by the generative model 120. do. If the detection result 125 of the security signal 115 that is the result of an attack from the automated attacker 140 does not identify that the attack was malicious, the security signal 115 is that the automated attacker 140 is malicious in that signal. Since it indicates that it was a thing, it will be treated as malicious. In various embodiments, the automated attacker 140 is an optional component of the security system 100 or the online service 110.
[0019] A signal in the rolling window 130 (with a detection result 125 (and corrections from the analyst user) from the generative model 120 that indicates whether the security signal 115 was determined to be harmless or malicious. , And the past signal 135, if available) The security signal 115 is fed to the signal splitter 145. Also, in an aspect in which the automated attacker 140 is deployed, the signal splitter 145 is provided with an identification of whether the security signal 115 generated from the attacker's action on the online service 110 is harmless / malicious. The signal splitter 145 is configured to split the security signal 115 into a harmless signal provided to the harmless signal balancer 150 and a malicious signal provided to the attack signal balancer 155.
[0020] Harmless signal balancer 150 and attack signal balancer 155 have developed and balanced a set of security signals 115 used to populate the dataset used by the training data bootstrapper 160 with harmless signals. It provides a malicious signal, thereby training the model to detect the latest exploits of the online service 110. The training data bootstrapper 160 removes the harmless signal received from the endangered device in the online service 110, leaving only the malicious signal from the endangered device. Harmless signals from clean devices are cross-joined with malicious signals from endangered devices, resulting in BxM attack cases, where B is a harmless case. Represents the number of, and M represents the number of malicious cases. This produces enhanced data with attack cases superimposed on harmless cases that appear as if the attack occurred on a clean device.
[0021] Clean devices have different variations of harmless signals, and endangered devices have different variations of attack signals, so cross-coupling two datasets can result in large variations. Create a large number of prepared scenarios. However, if the scenario is randomly selected by an automated attacker 140 etc., there may be unequal numbers of each attack type in the training set, which distorts the training of the model (as a result). Some attacks are more predictable than others). Therefore, by balancing the attack cases against the attack scenario, we ensure that there are approximately the same number (eg ± 5%) of each case attack in the training set. In various embodiments, less than actual attack types (ie, less than balanced numbers of attack types) copy existing malicious signals to increase their relative numbers, and / or , More than actual attack types (ie, more than a balanced number of attack types) either remove existing malicious signals or replace with lesser than actual attack type cases / Superimpose to achieve a balanced set of attack cases.
[0022] Like malicious signals, harmless signals are balanced against each other with respect to the type or role of the device from which they are received, and a given device type or role is in the training dataset. Make sure that is not shown more than it really is (as a result, some attacks are better predicted than others for a given device type / role). Therefore, balancing the harmless cases against the available device types ensures that there are approximately the same number (eg ± 5%) of each device type that provides the harmless cases. In various embodiments, less than actual device types (ie, device types in less than balanced quantities) copy existing harmless signals to increase their relative numbers, and / or. Device types shown more than they really are (ie, more than a balanced number of device types) either remove existing harmless signals or replace them with harmless cases from device types shown less than they really are. / Superimpose to achieve a balanced harmless case set.
[0023] FIG. 1B is an exemplary model training and selection system 105 for use with the exemplary security system 100 of FIG. 1A for which the present disclosure can be implemented together. A balanced dataset of harmless and malicious signals from the training data bootstrapper 160 is trained to both train and evaluate various models to secure the online service 110. Provided to test splitter 165. The dataset is divided into k subsets, where k-1 of the available subsets (eg two-thirds) are used to train the model and one of the datasets (eg two-thirds). For example, one-third) is reserved for evaluating the model. In various embodiments, different proportions are envisioned to divide the dataset into training and evaluation subsets provided to the model trainer 170 and model evaluator 175, respectively.
[0024] The model trainer 170 is configured to train a plurality of development models 180 by one or more machine learning techniques via a training subset of balanced data. Machine learning techniques train the model to make accurate predictions for the data supplied to the model (eg, whether the security signal 115 is harmless, malicious, or the noun is a person. Whether it's a place or a thing, what's the weather like tomorrow). During the training phase, the model is developed against a training dataset of known inputs (eg, Sample A, Sample B, Sample C) and optimized to correctly predict the output for a given input. In general, the learning phase may be supervised, semi-supervised, or unsupervised, which means that less and less "correct" output is provided in response to training inputs. .. In the supervised learning phase, all of the output is provided to the model, and the model is guided to develop general rules or algorithms that map the inputs to the outputs. In the unsupervised learning phase, on the other hand, the required output is not provided for the inputs, so the model may develop its own rules for discovering relationships in the training dataset. The semi-supervised learning phase provides an incompletely labeled training set, some of the output is known to the training dataset and some are unknown.
The model may be run over several epochs in the light of the training data set, in which the training data set is repeatedly fed to the model to refine the model results. For example, in the supervised learning phase, a model is developed to predict the output for a given set of inputs, and the largest number of inputs for the training data set corresponds to that given input. Evaluate the model over several epochs to more reliably provide the identified output. In another example, during the unsupervised learning phase, the model is developed to cluster the dataset into n groups, how consistently the model puts a given input into a given group, and the model Evaluate the model over several epochs to ensure that n required clusters are generated across each epoch.
[0026] In various embodiments, cross-validation is applied in addition to each training phase, where a portion of the training data set is used as the evaluation data set. For example, the training dataset may be divided into k segments, where (k-1) segments are used for the training epoch, and the remaining segments show how well the trained model worked. Used to determine. In this way, each model is trained against any possible combination of input parameters, thus each model is trained k times, and the best model parameters are based on the average performance of each model over the epoch. Be selected.
[0027] When the epoch is executed, the models are evaluated and the values of the variables in each model are adjusted in an attempt to further refine the model. In various embodiments, the assessment is biased against false negatives, biased against false positives, or evenly biased against the overall accuracy of the model. .. The above values may be adjusted in several ways depending on the machine learning technique used. For example, in a genetic or evolutionary algorithm, the values corresponding to the model that best predicts the required output are used to develop the model values for use during subsequent epochs, which is an addition. It may include random variants / mutations to obtain an algorithmic data point. Those skilled in the art will be familiar with some other machine learning algorithms applicable with this disclosure, including linear regression, random forest, decision tree learning, neural networks, and the like.
[0028] The model develops a rule or algorithm over several epochs by varying the values of one or more variables that affect the input so that they are more closely associated with the desired result. However, training datasets are subject to change and are preferably so large that perfect accuracy and accuracy may not be achievable. Therefore, some epochs that make up the learning phase may be set as a given number of trials, or a fixed time / computational budget, or when the accuracy of a given model is high or low enough. , Or when the plateau of accuracy has been reached, the epoch may be terminated before the number / budget is reached. For example, if the training phase is designed to run n epochs and generate a model with at least 95% accuracy, and such a model is generated before the nth epoch, the training phase ends prematurely. Then, the generated model that satisfies the accuracy threshold of the final goal may be used. Similarly, if a given model is inaccurate enough to meet a random probability threshold (eg, the model is only 55% accurate in determining true / false output for a given input). The learning phase of the model may be terminated early, but other models in the learning phase may continue training. Similarly, if a given model continues to provide similar accuracy across multiple epochs, or if the model results fluctuate and reach a performance plateau, then the learning phase of that given model is the number of epochs. / You may gather before reaching the calculation budget.
[0029] When the learning phase is complete, the model is finalized. The established model is evaluated against the test criteria. In the first example, a test data set containing known outputs for that input is fed to the determined model to determine the accuracy of the model when dealing with untrained data. In the second example, the false positive rate, the false negative rate may be used to evaluate the model after confirmation. The third example uses the demarcation between clusterings to select the model that produces the clearest boundaries for its own data cluster. Another example evaluates additional indicators of the model, such as areas under precision and recall curve.
[0030] The development model 180 (and thus the generative model 120) is the first predictive model developed by the model feature configurator 185 based on the choices made by the management user. The management user has one or more features of the security signal 115 to be monitored on the device of the online service 110 and those features to represent whether a given security signal 115 is malicious or harmless. Choose how to analyze. In various aspects, the feature is a structured text file (eg, Extendable Markup Original (XML) or Java® Script Object) that the admin user can select from it to define a feature set for the new development model 180. Provided within (using Notation (JSON) tags). Based on the feature configuration, features are dynamically extracted as feature vectors from a given set of security signals for a device. For different models, different features may be extracted based on the feature composition of each model. Therefore, a structured text file allows the admin user to add or modify features and how to inspect those features to the model without having to add or modify the code to the code base. be able to. A structured text file can call a code segment from the code base and extend or modify the code segment to provide a new feature type for the admin user to choose. For example, the number of different values in a dataset (Count), the maximum value in a dataset (Max), as a feature check type for an administrative user to use for a given parameter or data field from security signal 115. You may select the number of values that appear most frequently in the list (MaxCount), the maximum sum of the values in the list that do not exceed the limit (MaxSum), and so on. Examples of data fields / parameters to observe in a security signal are, but are not limited to, the signal type (eg, data extraction, login attempt, request to access a given file), port used, process /. The number of bytes used in the communication, the number of bytes transferred to or from a given Internet Protocol (IP) address and port pair, user identifier, given IP address or action is blacklisted or white. Includes whether it is on the list, etc.
[0031] The model evaluator 175 is configured to evaluate the development model 180 and determine which model to use as the generative model 120 within the security system 100. In various embodiments, it is determined whether the generative model 120 is reincorporated into the development model 180 for evaluation or the accuracy threshold of the generative model 120 is used to replace a given generative model 120 with the development model 180. do. In another aspect, the development model 180 is compared to the generative model 120 with respect to other indicators such as accuracy and the area of the lower part of the fit and recall curves, where the best model is the generative model. Select as an promoted model 190 to use as 120. Models are continually developed as Model Evaluator 175 determines the effectiveness of each model to properly identify malicious signals as malicious and to properly identify harmless signals as harmless. It may be promoted from model 180 to generative model 120 (and demoted from generative model 120 to development model 180). In various embodiments, the top n most accurate development models 180, or all development models 180 that exceed the accuracy threshold, are promoted to the generative model 120 as the promoted model 190. In other embodiments, the management user may manually promote the development model 180 to the generative model 120, for example, if there is no other model to monitor a given feature of the security signal 115.
[0032] The security system 100, model training and selection system 105, and their components exemplify a large number of computing systems, including desktop computer systems, wired and wireless computing systems, and mobile. Computing systems (eg mobile phones, netbooks, tablets or slate computers, notebook computers, and laptop computers), portable devices, multiprocessor systems, microprocessor-based or programmable consumer appliances, minis. Computers, printers, and mainframe computers are included without limitation. The hardware of these computing systems will be described in detail with reference to Figure 4.
[0033] The components of Security System 100 and Model Training and Selection System 105 are shown remotely from each other for illustration purposes, but some of these devices may have different configurations. It should be noted that it is possible to be hosted locally to the exemplified device, and each exemplified device may represent multiple individuals of that device. Various servers and intermediaries known to those of skill in the art may exist between the components exemplified in FIGS. 1A and 1B to relay communication between these systems, which is a novel aspect of the present disclosure. It is not illustrated so as not to distract from.
[0034] FIG. 2 is a flow chart illustrating the general steps associated with the exemplary method 200 of developing a training data set for training a predictive model used to secure an online service 110. Method 200 starts with operation 210, where the security signal 115 is collected. In various embodiments, the security signal 115 is received or received in real time (or near real time with processing and transmission delays), eg by a batch process that checks for security events every m minutes, etc. It may be cached in the database for periodic inspection. The security signal 115 includes monitored events and parameters of various actions that occur on the machine within the online service 110.
[0035] This monitored event and parameter is used in operation 220 to identify whether a given security signal 115 corresponds to a malicious action or a harmless action. In various embodiments, the collected security signals 115 are designated for use with the live online service 110 (ie, generative model 120) to determine if each security signal 115 is malicious or harmless. It is supplied to the predictive model. These verdicts are presented to the analyst user, who can act on that verdict to secure the online service 110 from malicious persons, but the verdicts made by the predictive model. May be canceled, which means that the verdict is false positive or false negative. Similarly, in an embodiment using the automated attacker 140 to simulate an attack on the online service 110, the automated attacker 140 provides a notification that identifies the security signal 115 generated in response to the attack as malicious. Therefore, those security signals 115 are treated as malicious regardless of the detection result from the predictive model.
[0036] At operation 230, set the rolling window 130 to a time frame from the current time to analyze the security signal 115 associated with the latest exploits and attacks running against the online service 110. Define. The rolling window 130 defines a set of security signals 115 that fall within a specified time period from the current time, the security signals 115 being collected in the last d days. A multi-day window is used to train and predict slow attacks, and slow-acting attacks are carried out over multiple days to avoid detection by traditional security systems. As the security signal 115 is collected, recent security signals have been added to the set of security signals 115 corresponding to the rolling window 130, and the security signal 115 collected prior to the specified period corresponding to the rolling window 130 , Is continuously removed from the set of security signals 115.
[0037] In some embodiments, the past signal 135 is optionally received in action 240. Past signal 135 has been designated as a record-critical security signal 115, or for training purposes, representing a particular attack type, regardless of whether similar attacks or use cases were seen within the duration of rolling window 130. Curated by the analyst user from a previously observed security signal 115 to include harmless use cases. In one example, a record-dangerous exploit may add a security signal 115 associated with the detection of the exploit to a past signal 135 to stay alert to the exploit. In another example, the developer discovered a zero-day exploit and has not yet figured out if a malicious person is using it, but the exploit has never been seen. Even if not, an exemplary security signal 115 may be provided to mimic the actions of a zero-day exploit for use as a past signal 135, in order to be proactive against the exploit. In yet another example, a security signal 115 that is frequently false positive may be added to the past signal 135 to ensure that the predictive model is trained against this particular security signal 115. If available, the past signal 135 is added to the set of security signals 115 collected within the rolling window 130.
[0038] Proceeding to operation 250, method 200 takes the collected malicious and harmless signals that enter the rolling window 130 and the past signals 135 if added to the set in optional operation 240. Balance. When balancing malicious signals, the attack type of each signal is determined so that the relative quantities of the signals representing each attack type are balanced (ie, equalized), thereby being malicious. Make sure that no given attack type is shown more or less than it really is in a set of signals. When balancing the harmless signals, the harmless signals received from the device that generated the malicious signal in the rolling window 130 are discarded and each harmless received from each type of device in the online service 110. The relative quantities of the signals in are balanced so that no given device type is shown more or less than it really is in a population of harmless signals.
[0039] In addition, since a set of malicious signals is expected to be less numerous than a set of harmless signals, operation 260 selects a portion of the set of harmless signals to intersect the malicious signals. By combining, a new, larger, malicious set of signals may be generated, whereby the two sets will contain the desired ratio of malicious signal vs. harmless signal. In various embodiments, once the set of malicious signals and the set of harmless signals are in the desired ratio (eg equilibrium), the two sets are used together as a training set.
[0040] At 270, a predictive model of training sets for various attack scenarios, consisting of balanced malicious and harmless signals (and, in some cases, past signals 135) generated within the rolling window 130. Make it available for training. For example, the generative model 120 used to analyze the security signal 115 updates the contents of the rolling window 130 over time to better evaluate the attacks and exploits that are being actively used against the online service 110. As it grows, it is continuously retrained and / or replaced with a different predictive model. Therefore, method 200 may exit after operation 270 or return to operation 210 to continue collecting security signals 115 to supply training data sets periodically or constantly based on rolling window 130. ..
[0041] FIG. 3 is a flow chart showing the general steps involved in the exemplary method 300 of training and selecting a predictive model for use in securing an online service 110. Method 300 starts at operation 310, where it receives a training dataset of balanced malicious and harmless signals, such as those developed according to Method 200. In various embodiments, the method 300 is called periodically (eg, every h hours) or in response to an update to the rolling window 130 (and thus the training dataset), or in response to a user command.
[0042] Proceed to operation 320 to divide the training data set into an evaluation subset and a learning subset. In various embodiments, the size of the evaluation subset for the training dataset may vary, but is generally smaller than the training subset. For example, the evaluation subset may be one-third of the initial training set, so the learning subset is the remaining two-thirds of the initial training set. Those skilled in the art will recognize that other proportions of the training data set may be set aside for use as a subset for evaluation.
[0043] At operation 330, it receives a configuration feature and generates a development model 180 as a potential predictive model to use at generation time (ie, as a generative model 120) to secure the online service 110. A management user, such as a security analyst, selects one or more parameters to monitor within the online service 110 via the security signal 115 and a feature type for inspecting those parameters. Security signal 115 includes, but is not limited to, event logs, network traces, error reports, special event listener reports, atomic detection, and combinations thereof, and parameters related to selected features are included in security signal 115. It may contain any of the elements to be used.
[0044] For example, if the security signal 115 contains a network trace, the parameters of the sender / receiver address pair may be selected and evaluated according to the feature type of "count" and the pair will be seen in the training set. The number of times it is done increments the score / value to be evaluated for that feature. In another example, if the security signal 115 contains a network trace, a parameter of the number of bytes transmitted between the sender / receiver pair is provided as a score / value to be evaluated for that feature. In a further example, a parameter for the balance of transmission between the sender / receiver pair, which indicates the relative upload / download ratio, is provided as a value / score to be evaluated for that feature. Those skilled in the art will recognize that the above is a non-restrictive example. It is envisioned that other parameters and other feature types of such parameters that allow them to be evaluated by predictive models will be used with the present application.
[0045] Proceeding to operation 340, a development model 180 is created based on the received feature configuration and refined according to the learning subset using one or more machine learning algorithms. Each predictive model is created to accept a particular feature vector (identifying the feature selected by the management user), where each feature constituting the feature vector is associated with a coefficient. Each feature vector is dynamically extracted from the security signal 115 based on the feature configuration. The value of the coefficient is adjusted over a number epoch of the machine learning algorithm so that when a given development model 180 receives the input of the feature vector, is it malicious that matches the output specified in the learning subset? The interaction between the various feature values may be adjusted to ensure that the output is harmless.
[0046] Proceed to motion 350, where motion 340 evaluates the refined predictive model for the training dataset against an evaluation subset divided from the training dataset in motion 320. The evaluation subset includes an input (security signal 115 collected from online service 110) along with a known output of whether the signal is malicious or harmless. In addition, the input / output pairs of the evaluation subset have not been used to directly train the development model 180 and therefore to determine if the unknown signal is malicious or harmless. Provides testing to see if the development model 180 provides general functional rules.
[0047] The promotion threshold is applied to the development model 180 to determine whether a given development model 180 is promoted to the generative model 120. The promotion threshold identifies how accurate the development model 180 needs to be in predicting whether the signal is malicious or harmless based on the feature vector extracted from the security signal 115. In some embodiments, the promotion threshold is set as a constant, eg, an accuracy of at least n%, a given fit rate on the test data, the area of the lower part of the recall curve, and the like. In another aspect, the promotion threshold is set by the accuracy of the current generative model 120 for a given feature vector or attack type, and the generative model 180 replaces the generative model 120 within the security system 100. Must be more accurate than the current generative model 120.
[0048] In operation 360, the development model 180 and the re-evaluated generative model 120 with the best performance according to the evaluation subset and promotion threshold are promoted for use in the security system 100 to protect the online service 110. Will be done. Generative model 120 that no longer meets the promotion threshold or has been replaced by development model 180 may be deleted or demoted to development model 180 for further training and amendment, and later reassessed. Method 300 may then be terminated.
[0049] Although embodiments have been described in the general context of program modules that are executed in the context of application programs that are executed on a computer's operating system, those skilled in the art have described the embodiments as with other program modules. It will be recognized that they may be implemented in combination. In general, program modules include routines, programs, components, data structures, and other types of structures that perform specific tasks or implement specific abstract data types.
[0050] The embodiments and functionality described herein can operate through a wide variety of computing systems, including desktop computer systems, wired and wireless computing systems, and mobile computing systems. (Eg mobile phones, netbooks, tablets or slate computers, notebook computers, and laptop computers), portable devices, multiprocessor systems, microprocessor-based or programmable consumer appliances, minicomputers, and Mainframe computers are included without limitation.
[0051] In addition, according to one aspect, the aspects and functionality described herein operate across distributed systems (eg, cloud-based computing systems), in which application functions, memory. , Data storage and retrieval, and various processing functions are operated remotely from each other through distributed computing networks such as the Internet or intranets. According to one aspect, various types of user interfaces and information are displayed via the built-in computing device display or via a remote display unit associated with one or more computing devices. For example, different types of user interfaces and information are displayed on and interacted with on the wall on which the different types of user interfaces and information are projected. Interactions with various computing systems that the implementation is carried out with are keystroke input, touch screen input, voice or other voice input, because the associated computing device controls the functionality of the computing device. Includes gesture input when equipped with a detection (eg, camera) function that captures and interprets user gestures.
[0052] FIG. 4 and related description provide a description of the various operating environments in which the example is implemented. However, the devices and systems exemplified and described with respect to FIG. 4 are for purposes of illustration and illustration and are of the vast number of computing device configurations used to implement the embodiments described herein. Not a limit.
[0053] FIG. 4 is a block diagram illustrating the physical components (ie, hardware) of the computing device 400 that can be implemented with the example of the present disclosure. In a basic configuration, the computing device 400 includes at least one processing unit 402 and system memory 404. According to one aspect, depending on the configuration and type of compute device 400, the system memory 404 is, but is not limited to, volatile storage (eg, random access memory), non-volatile storage (eg, read-only memory), flash. A memory storage device that includes memory, or a combination of such memories. According to one aspect, the system memory 404 includes an operating system 405 and one or more program modules 406 suitable for running software applications 450. According to one aspect, the system memory 404 includes a security system 100, a model training and selection system 105, and any model used or generated by them. The operating system 405 is suitable for controlling the operation of the computing device 400, for example. Further, the embodiment is performed in the context of a graphics library, other operating system, or any other application program and is not limited to any particular application or system. This basic configuration is illustrated in FIG. 4 by the components within the dashed line 408. According to one aspect, the computing device 400 has additional features or functionality. For example, according to one aspect, the computing device 400 includes additional data storage devices (removable and / or non-removable) such as, for example, magnetic disks, optical discs, or tapes. Such additional storage is illustrated in FIG. 4 by removable storage 409 and non-removable storage 410.
[0054] As described above, according to one aspect, a plurality of program modules and data files are stored in the system memory 404. While running on the processing unit 402, the program module 406 (eg, security system 100, model training and selection system 105) is, but is not limited to, the steps 200 and 300 of methods 200 and 300 exemplified in FIGS. 2 and 3, respectively. Perform a process that includes one or more of. According to one aspect, other program modules are used according to the examples, such as e-mail and contact applications, document processing applications, table computing applications, database applications, slide presentation applications, drawing or computer assisted application programs. And so on.
[0055] According to one aspect, the computing device 400 has one or more input devices 412 such as a keyboard, mouse, pen, sound input device, touch input device and the like. An output device 414 such as a display, a speaker, and a printer is also included according to one aspect. The above devices are examples, and others may be used. According to one aspect, the computing device 400 includes one or more communication connections 416 that allow communication with other computing devices 418. Examples of suitable communication connections 416 include, but are not limited to, radio frequency (RF) transmitters, receivers, and / or transceiver circuits, universal serial buses (USB), parallel ports, and / or serial ports. Is done.
[0056] As used herein, the term computer-readable medium includes computer storage media. Computer storage media include volatile and non-volatile, removable and non-removable media implemented by any method or technique for storing information such as computer readable instructions, data structures, or program modules. System memory 404, removable storage 409, and non-removable storage 410 are all examples of computer storage media (ie, memory storage). According to one aspect, the computer storage medium is RAM, ROM, electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, CD-ROM, digital versatile disk (DVD) or Includes other optical storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any manufactured product that can be used to store information and is accessible from the computing device 400. According to one aspect, any such computer storage medium is part of the computing device 400. Computer storage media do not include carrier waves or other propagating data signals.
[0057] According to one aspect, the communication medium is any information transmission medium realized by computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transfer mechanism. including. In one aspect, the term "modulated data signal" refers to a signal in which one or more characteristics are set or altered in such a way that information is encoded in the signal. As an example, but not a limitation, communication media include wired media such as wired networks and direct wiring connections, and radio media such as acoustic, radio frequency (RF), infrared, and other wireless media.
[0058] For example, the implementation form has been described above with reference to a block diagram and / or an operation diagram of a method, a system, and a computer program product according to each aspect. The functions / operations described in the blocks may be performed in a different order as shown in any of the flowcharts. For example, two blocks shown in succession may actually be executed at substantially the same time, or the blocks may in some cases be executed in reverse order depending on the associated functionality / behavior. ..
[0059] The description and illustration of one or more examples provided in the present application are not intended to limit or limit the claims in any way. The embodiments, examples, and details provided in the present application are believed to be sufficient to convey the concept and allow others to create and use the best forms. Implementations should not be construed as being limited to any of the embodiments, examples, or details provided in this application. Various features (both structural and methodological features), whether illustrated and described in combination and illustrated and described separately, are examples with a particular set of features. It is intended to be selectively included or omitted for generation. Those skilled in the art who have provided the description and examples of the present application fall within the scope of the broader aspect of the general invention concept realized in the present application, and do not deviate from the broader range. , And an alternative example can be envisioned.
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| JP2004312083A | Cites | Japan |
| US09306962B1 | Cites | United States of America |
| 山田明ほか,亜種攻撃を検知できる侵入検知システムの提案,コンピュータセキュリティシンポジウム,日本,2003年10月29日,pp.659-664 | Non-patent | – |
30 members in 18 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 15419933 | United States of America | – | |
| 201715419933 | United States of America | A | |
| 201715419933 | United States of America | A | |
| 2018014606 | United States of America | W | |
| 2018014606 | United States of America | W | |
| 15419933 | – | – | – |
| US201715419933 | – | – | – |
| US2018014606 | – | – | – |
| WO2018US14606 | – | – | – |
Members30
| Document | Office | Kind | |
|---|---|---|---|
| ZA201903697A0 | South Africa | A0 | |
| CA3049265A1 | Canada | A1 | |
| US2018219887A1 | United States of America | A1 | |
| WO2018140335A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2018212470A1 | Australia | A1 | |
| CO2019007878A2 | Colombia | A2 | |
| SG11201906575QA | Singapore | A | |
| US10397258B2 | United States of America | B2 | |
| MX2019008799A | Mexico | A | |
| CN110249331A | China | A | |
| KR20190109427A | Republic of Korea | A | |
| IL268052A | Israel | A | |
| US2019342319A1 | United States of America | A1 | |
| PH12019550118A1 | Philippines | A1 | |
| EP3574430A1 | European Patent Office (EPO) | A1 | |
| CL2019002045A1 | Chile | A1 | |
| BR112019013603A2 | Brazil | A2 | |
| JP2020505707A | Japan | A | |
| ZA201903697B | South Africa | B | |
| EP3574430B1 | European Patent Office (EPO) | B1 | |
| RU2019126640A | Russian Federation | A | |
| RU2019126640A3 | Russian Federation | A3 | |
| RU2758041C2 | Russian Federation | C2 | |
| AU2018212470B2 | Australia | B2 | |
| IL268052B | Israel | B | |
| JP7086972B2This record | Japan | B2 | |
| KR102480204B1 | Republic of Korea | B1 | |
| US11689549B2 | United States of America | B2 | |
| NZ754552A | New Zealand | A | |
| CA3049265C | Canada | C |
11 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Notification of acceptance of power of attorneyJAPANESE INTERMEDIATE CODE: R3D02RD02 | RD02 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 7086972
- Publication, DOCDB
- 7086972
- Publication, EPODOC
- JP7086972B
- Application
- 2019541304
- Application, DOCDB
- 2019541304
- Application, EPODOC
- JP20190541304
Titles2
- Japanese
- 侵入検出のための継続的な学習
- English
- Continuous learning for intrusion detection
Classification
- CPC, 4
- G06F21/55
- H04L63/1425
- H04L63/14
- G06N7/01
- IPC, 2
- G06F21 55
- G06N20 00
