System and method to detect attacks on mobile wireless networks based on network controllability analysis

US10091218B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10091218-B2
Application numberUS-201615075058-A
CountryUS
Kind codeB2
Filing dateMar 18, 2016
Priority dateJan 23, 2012
Publication dateOct 2, 2018
Grant dateOct 2, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Described is a system for detecting attacks of misinformation on communication networks. Network controllability metrics on a graphical representation of a communication network are computed. Changes in the network controllability metrics are detected, and attack of misinformation on the communication network are detected based on the detected changes in the network controllability metrics.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for detecting and mitigating attacks of misinformation on communication networks, the system comprising: one or more processors and a non-transitory memory having instructions encoded thereon such that when the instructions are executed, the one or more processors perform operations of: computing a plurality of network controllability metrics on a representation of a communication network comprising a plurality of nodes; detecting changes in the plurality of network controllability metrics; using the detected changes to detect an attack of misinformation on the communication network, wherein given a set of examples of network controllability metric data representing a baseline behavior and a set of examples of network controllability metric data representing an attack behavior, a machine learning classifier determines a threshold for attack detection based on differences between the baseline behavior and the attack behavior; attributing the attack to an attacking node in the communication network; and performing a mitigation action that isolates the attacking node from the communication network. 2. The system as set forth in claim 1 , wherein the representation includes network topology, network dependencies, and application dependencies within the communication network. 3. The system as set forth in claim 1 , wherein the plurality of network controllability metrics are computed as a function of a pattern of communication between the plurality of nodes of the communication network during a given time window. 4. The system as set forth in claim 1 , wherein each network controllability metric is represented as a diode in a diode pattern panel, wherein network controllability metrics displaying attack behavior, as determined by the threshold for attack detection, are highlighted in the diode pattern panel. 5. The system as set forth in claim 1 , wherein the mitigation action further comprises informing every other node in the communication network to ignore anything that the attacking node transmits, and not to send anything to, or through, the attacking node. 6. The system as set forth in claim 1 , wherein the one or more processors further perform operations of: outputting features representing each of the plurality of network controllability metrics; converting each feature into a binary indication of whether a value is anomalous or not anomalous; and using the binary indication to detect changes in the plurality of network controllability metrics. 7. The system as set forth in claim 1 , wherein the representation is a graphical representation of network topology, network dependencies, and application dependencies within the communication network. 8. The system as set forth in claim 1 , wherein the plurality of network controllability metrics are computed on a graphical representation of a pattern of communication between the plurality of nodes of the communication network during a given time window. 9. A computer-implemented method for detecting and mitigating attacks of misinformation on communication networks, comprising: an act of causing one or more processors to execute instructions stored on a non-transitory memory such that upon execution, the one or more processors perform operations of: computing a plurality of network controllability metrics on a representation of a communication network comprising a plurality of nodes; detecting changes in the plurality of network controllability metrics; using the detected changes to detect an attack of misinformation on the communication network, wherein given a set of examples of network controllability metric data representing a baseline behavior and a set of examples of network controllability metric data representing an attack behavior, a machine learning classifier determines a threshold for attack detection based on differences between the baseline behavior and the attack behavior; attributing the attack to an attacking node in the communication network; and performing a mitigation action that isolates the attacking node from the communication network. 10. The method as set forth in claim 9 , wherein the representation includes network topology, network dependencies, and application dependencies within the communication network. 11. The method as set forth in claim 9 , wherein the plurality of network controllability metrics are computed as a function of a pattern of communication between the plurality of nodes of the communication network during a given time window. 12. The method as set forth in claim 9 , wherein each network controllability metric is represented as a diode in a diode pattern panel, wherein network controllability metrics displaying attack behavior, as determined by the threshold for attack detection, are highlighted in the diode pattern panel. 13. A computer program product for detecting and mitigating attacks of misinformation on communication networks, the computer program product comprising: computer-readable instructions stored on a non-transitory computer-readable medium that are executable by a computer having one or more processors for causing the processor to perform operations of: computing a plurality of network controllability metrics on a representation of a communication network comprising a plurality of nodes; detecting changes in the plurality of network controllability metrics; using the detected changes to detect an attack of misinformation on the communication network, wherein given a set of examples of network controllability metric data representing a baseline behavior and a set of examples of network controllability metric data representing an attack behavior, a machine learning classifier determines a threshold for attack detection based on differences between the baseline behavior and the attack behavior; attributing the attack to an attacking node in the communication network; and performing a mitigation action that isolates the attacking node from the communication network. 14. The computer program product as set forth in claim 13 , wherein the representation includes network topology, network dependencies, and application dependencies within the communication network. 15. The computer program product as set forth in claim 13 , wherein the plurality of network controllability metrics are computed as a function of a pattern of communication between the plurality of nodes of the communication network during a given time window. 16. The computer program product as set forth in claim 13 , wherein each network controllability metric is represented as a diode in a diode pattern panel, wherein network controllability metrics displaying attack behavior, as determined by the threshold for attack detection, are highlighted in the diode pattern panel.

Assignees

Inventors

Classifications

  • Countermeasures against malicious traffic (countermeasures against attacks on cryptographic mechanisms H04L9/002) · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • Machine learning · CPC title

  • Probabilistic graphical models, e.g. probabilistic networks · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10091218B2 cover?
Described is a system for detecting attacks of misinformation on communication networks. Network controllability metrics on a graphical representation of a communication network are computed. Changes in the network controllability metrics are detected, and attack of misinformation on the communication network are detected based on the detected changes in the network controllability metrics.
Who is the assignee on this patent?
Hrl Lab Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/1416. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 02 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).