System and method to detect attacks on mobile wireless networks based on motif analysis

US9979738B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9979738-B2
Application numberUS-201615075052-A
CountryUS
Kind codeB2
Filing dateMar 18, 2016
Priority dateJan 23, 2012
Publication dateMay 22, 2018
Grant dateMay 22, 2018

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Described is a system for detecting attacks on networks. A hierarchical representation of activity of a communication network is used to detect and predict sources of misinformation in the communication network. The hierarchical representation includes temporal patterns of communication between at least one pair of nodes, each temporal pattern representing a motif, having a size, in the hierarchical representation. Changes in motifs provide a signal for a misinformation attack.

First claim

Opening claim text (preview).

What is claimed is: 1. A system for detecting attacks on networks, the system comprising: one or more processors and a non-transitory memory having instructions encoded thereon such that when the instructions are executed, the one or more processors perform operations of: detecting and predicting sources of misinformation in a communication network using a hierarchical representation of activity of the communication network; wherein the hierarchical representation comprises a plurality of nodes and temporal patterns of communication between at least one pair of nodes, each temporal pattern representing a motif, having a size, in the hierarchical representation, and wherein changes in motifs provide a signal for a misinformation attack. 2. The system as set forth in claim 1 , wherein the one or more processors further perform an operation of generating a visual representation on a display relating to motifs of interest to identify a misinformation attack. 3. The system as set forth in claim 2 , wherein a misinformation attack is characterized by an over-representation of motifs having a predetermined size. 4. The system as set forth in claim 3 , wherein a size threshold for detection of a misinformation attack is set by learning a maximum frequency of motifs of each size in a normal baseline operation of the communication network. 5. The system as set forth in claim 4 , wherein if a frequency of any motif size surpasses double the maximum frequency, a misinformation attack signal is detected. 6. The system as set forth in claim 5 , wherein the one more processors further perform operations of: introducing a motif attribution measure at each node i of the communication network; and for each node i, defining m i as a frequency of sub-graphs to which it contributes; wherein a m i greater than double the maximum frequency indicates a likelihood that node i is an attacker. 7. The system as set forth in claim 1 , wherein the hierarchical representation comprises a plurality of data tables that describe applications and services running on the communication network and a set of inter-dependencies between the applications and services. 8. A computer-implemented method for detecting attacks on networks, comprising: an act of causing one or more processors to execute instructions stored on a non-transitory memory such that upon execution, the one or more processors perform operations of: detecting and predicting sources of misinformation in a communication network using a hierarchical representation of activity of the communication network; wherein the hierarchical representation comprises a plurality of nodes and temporal patterns of communication between at least one pair of nodes, each temporal pattern representing a motif, having a size, in the hierarchical representation, and wherein changes in motifs provide a signal for a misinformation attack. 9. The method as set forth in claim 8 , wherein the one or more processors further perform an operation of generating a visual representation on a display relating to motifs of interest to identify a misinformation attack. 10. The method as set forth in claim 9 , wherein a misinformation attack is characterized by an over-representation of motifs having a predetermined size. 11. The method as set forth in claim 10 , wherein a size threshold for detection of a misinformation attack is set by learning a maximum frequency of motifs of each size in a normal baseline operation of the communication network. 12. The method as set forth in claim 11 , wherein if a frequency of any motif size surpasses double the maximum frequency, a misinformation attack signal is detected. 13. The method as set forth in claim 12 , wherein the one or more processors further perform operations of: introducing a motif attribution measure at each node i of the communication network; and for each node i, defining m i as a frequency of sub-graphs to which it contributes; wherein a m i greater than double the maximum frequency indicates a likelihood that node i is an attacker. 14. The method as set forth in claim 8 , wherein the hierarchical representation comprises a plurality of data tables that describe applications and services running on the communication network and a set of inter-dependencies between the applications and services. 15. A computer program product for detecting attacks on networks, the computer program product comprising: computer-readable instructions stored on a non-transitory computer-readable medium that are executable by a computer having one or more processors for causing the processor to perform operations of: detecting and predicting sources of misinformation in a communication network using a hierarchical representation of activity of the communication network; wherein the hierarchical representation comprises a plurality of nodes and temporal patterns of communication between at least one pair of nodes, each temporal pattern representing a motif, having a size, in the hierarchical representation, and wherein changes in motifs provide a signal for a misinformation attack. 16. The computer program product as set forth in claim 15 , further comprising instructions for causing the one or more processors to perform an operation of generating a visual representation on a display relating to motifs of interest to identify a misinformation attack. 17. The computer program product as set forth in claim 16 , wherein a misinformation attack is characterized by an over-representation of motifs having a predetermined size. 18. The computer program product as set forth in claim 17 , wherein a size threshold for detection of a misinformation attack is set by learning a maximum frequency of motifs of each size in a normal baseline operation of the communication network. 19. The computer program product as set forth in claim 18 , wherein if a frequency of any motif size surpasses double the maximum frequency, a misinformation attack signal is detected. 20. The computer program product as set forth in claim 19 , further comprising instructions for causing the one or more processors to perform operations of: introducing a motif attribution measure at each node i of the communication network; and for each node i, defining m i as a frequency of sub-graphs to which it contributes; wherein a m i greater than double the maximum frequency indicates a likelihood that node i is an attacker. 21. The computer program product as set forth in claim 15 , wherein the hierarchical representation comprises a plurality of data tables that describe applications and services running on the communication network and a set of inter-dependencies between the applications and services. 22. The system as set forth in claim 1 , wherein upon detection of an attack of misinformation on the communication network, the one or more processors further perform an operation of performing a mitigation action. 23. The system as set forth in claim 22 , wherein the mitigation action comprises isolating an attacking node from the rest of the communication network.

Assignees

Inventors

Classifications

  • the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title

  • Self-organising networks, e.g. ad-hoc networks or sensor networks · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • Integrity · CPC title

  • Anti-theft arrangements, e.g. protection against subscriber identity module [SIM] cloning · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9979738B2 cover?
Described is a system for detecting attacks on networks. A hierarchical representation of activity of a communication network is used to detect and predict sources of misinformation in the communication network. The hierarchical representation includes temporal patterns of communication between at least one pair of nodes, each temporal pattern representing a motif, having a size, in the hierarc…
Who is the assignee on this patent?
Hrl Lab Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/1416. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue May 22 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).