System and method for modeling large user entity behavior with zero occupancy space

By encoding network flow records into multi-dimensional vectors and storing these vectors, the problem of high storage space cost in traditional network behavior monitoring systems is solved, and a behavior model of saving a large number of network endpoints in a small amount of storage space is realized.

CN111615695BActive Publication Date: 2025-05-30EXTREME NETWORKS INC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN201880087164.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2018-07-11
Filing Date
2018-12-12
Publication Date
2025-05-30
Estimated Expiration
2038-12-12

AI Technical Summary

Technical Problem

Traditional network behavior monitoring systems require storing large amounts of network flow records, resulting in high storage space costs, especially as small devices and IoT devices surge, monitoring all network devices becomes impractical.

Method used

By reducing network flow records to vectors, receiving multiple records using the control circuit system, determining records corresponding to each network endpoint, and assigning a dedicated queue to each network endpoint, encode records into multi-dimensional vectors using word/document embedding algorithms such as doc2vec, and storing these vectors in place of the original records.

Benefits of technology

A behavioral model of saving millions or more network endpoints in a small amount of storage space is implemented, reducing storage costs and avoiding the storage risk of sensitive information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111615695B_ABST
    Figure CN111615695B_ABST
Patent Text Reader

Abstract

This disclosure relates to systems and methods for reducing storage space used in tracking the behavior of multiple network endpoints by modeling the behavior with a behavior model. To this end, a control circuitry may determine a respective network endpoint among the multiple network endpoints corresponding to each respective record among the multiple received records. The control circuitry may then assign a dedicated queue to each respective network endpoint and send each record to each dedicated queue, where each record corresponds to the respective network endpoint to which the respective dedicated queue is assigned. The control circuitry may then determine a respective behavior model for each respective network endpoint and may store each respective behavior model in a memory.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] Traditionally, monitoring the network behavior of many network endpoint devices using a central server requires storing a large number of network flow records for analysis. For example, existing systems require storing Netflow and Internet Protocol Flow Information Export ("IPFIX") records, Hypertext Transfer Protocol ("HTTP") proxy logs, etc. in a "big data" backend for subsequent processing. This involves significant costs because storing these records requires using a large amount of storage space (totaling many terabytes) and the real estate to accommodate this storage space (i.e., the "big data" facility) is also expensive. The explosion of gadgets and other devices that have become network-connected (e.g., Internet of Things devices) exacerbates this problem, which multiplies the number of network endpoints to be monitored, making it impractical to store network flows for all network devices for the purpose of behavior monitoring. Summary of the Invention

[0002] Systems and methods for monitoring the behavior of network endpoints without a "big data" storage backend are disclosed herein. Specifically, the systems and methods disclosed herein reduce the records of network flows to vectors, enabling the system to save the behavior models of millions or more network endpoints using only a small amount of storage space (e.g., a few gigabytes of storage space).

[0003] In some aspects of the present disclosure, a control circuitry receives a plurality of records, each respective record of the plurality of records corresponding to a respective network endpoint of a plurality of network endpoints. Each respective record may identify a respective single network flow originating from the respective network endpoint corresponding to the respective record. The control circuitry may determine the respective network endpoint of the plurality of network endpoints corresponding to each respective record of the plurality of records.

[0004] The control circuitry may assign a respective dedicated queue to each respective network endpoint. For example, the control circuitry may designate a single first-in, first-out ("FIFO") queue for all records originating from a given network endpoint. The control circuitry may then send each record of the plurality of records to the respective dedicated queue, each record of the plurality of records corresponding to the respective network endpoint to which the respective dedicated queue is assigned.

[0005] The control circuit system can determine a corresponding behavior model for each corresponding network endpoint based on each record of each corresponding dedicated queue for each corresponding network endpoint, and can store each corresponding behavior model in a memory. In some embodiments, when determining the corresponding behavior model, the control circuit system can identify a plurality of modules programmed to determine the behavior model, and can identify an idle module among the plurality of modules. The control circuit system can command the idle module to determine the corresponding behavior model. The module can be a software instance of an algorithm for determining a behavior model based on records of a given queue.

[0006] In some embodiments, when determining the corresponding behavior model, the control circuit system encodes the data of a set of corresponding records into a multi-dimensional vector of floating-point values. The control circuit system can determine whether a given multi-dimensional vector represents abnormal behavior of a given corresponding network endpoint. In response to determining that the given multi-dimensional vector represents abnormal behavior of the given corresponding network endpoint, the control circuit system can alert a network administrator or execute a set of predefined actions.

[0007] When encoding the data of each corresponding record within a corresponding dedicated queue, the control circuit system can extract corresponding data from corresponding fields of each corresponding individual network flow, concatenate the corresponding data into a string, and convert the string into a vector. Each corresponding data point can form a point in the vector. The control circuit system can use the vector as the corresponding behavior model.

[0008] When converting the string into a vector, the control circuit system can form a document with the string. Then, the control circuit system can feed the document into a word / document embedding algorithm (e.g., document-to-vector (“doc2vec”), FastText, etc.), and can use the doc2vec algorithm to analyze the document using a shallow neural network. Then, the control circuit system can output a vector based on the analysis.

[0009] In some embodiments, the plurality of records have a first data size, wherein the sum of the data sizes of each corresponding behavior model has a second data size, and wherein the second data size is two or more orders of magnitude smaller than the first data size. For example, while the plurality of records can total hundreds of terabytes of data, the vectors representing the records can together total several gigabytes of data.

[0010] In some embodiments, the control circuitry can receive a command from a network administrator to view the corresponding behavior model of a given network endpoint. In response to receiving the command, the control circuitry can generate a graphical representation of the corresponding behavior model of the given network endpoint for display. Additionally, the control circuitry can identify different network endpoints with corresponding behavior models that exhibit behavior similar to that of the given network endpoint, and can generate the corresponding behavior models of the different network endpoints for simultaneous display with the graphical representation of the corresponding behavior model of the given network endpoint.

[0011] In some aspects, systems and methods are included for reducing the storage space used in tracking the behavior of multiple network endpoints by using a hash table and modeling behavior with behavior models. The control circuitry can receive a plurality of records, each corresponding record of the plurality of records corresponding to a respective one of the plurality of network endpoints. The control circuitry can identify the respective network endpoint of the plurality of network endpoints corresponding to each corresponding record of the plurality of records, and can encode each corresponding record into a corresponding word.

[0012] In some embodiments, the control circuitry assigns a respective block to a respective hash table for each corresponding record, and adds the corresponding word corresponding to each network endpoint corresponding to each respective block to a respective linked list record for each respective block. The control circuitry determines a corresponding behavior model for each respective network endpoint based on each respective linked list for each respective block, and stores each corresponding behavior model in a memory.

[0013] When assigning a respective block to a respective hash table for each corresponding record, the control circuitry can monitor the records of the plurality of records corresponding to unknown network endpoints. In response to detecting an unknown network endpoint from the monitoring, the control circuitry can add the block corresponding to the unknown network endpoint to the hash table.

[0014] In some embodiments, the control circuitry can determine a corresponding behavior model for each respective network endpoint based on each respective linked list for each respective block in response to detecting that a threshold amount of words has been accumulated for a given respective network endpoint. In some embodiments, when determining a corresponding behavior model for each respective network endpoint based on each respective linked list for each respective block, the control circuitry can feed the hash table through a word / document embedding algorithm such as the FastText algorithm. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] The above and other objects and advantages of the present disclosure will become apparent when the following detailed description is considered in conjunction with the accompanying drawings, in which like reference numerals refer to like components throughout, and in which:

[0016] Figure 1depicts a system for reducing the storage space used in tracking the behavior of multiple network endpoints by modeling behavior with a behavior model, according to some embodiments of the present disclosure;

[0017] Figure 2 depicts an example document according to some embodiments of the present disclosure, the example document including flow words corresponding to a given network endpoint;

[0018] Figure 3 depicts an illustrative two - dimensional projection of a higher - dimensional vector space according to some embodiments of the present disclosure;

[0019] Figure 4 is an illustrative depiction of a projection on a 3D space of multiple endpoint vectors, according to some embodiments of the present disclosure;

[0020] Figure 5 depicts an illustrative flowchart of a process for reducing the storage space used in tracking the behavior of multiple network endpoints by modeling behavior with a behavior model, according to some embodiments of the present disclosure;

[0021] Figure 6 depicts an illustrative flowchart of a process for determining corresponding behavior modules, according to some embodiments of the present disclosure;

[0022] Figure 7 depicts an illustrative flowchart of a process for warning a network administrator of abnormal network endpoint behavior, according to some embodiments of the present disclosure;

[0023] Figure 8 depicts an illustrative flowchart of a process for generating vectors for modeling endpoint device behavior using a word / document embedding algorithm, according to some embodiments of the present disclosure;

[0024] Figure 9 depicts an illustrative flowchart of a process for generating a visual representation of a behavior model for display, according to some embodiments of the present disclosure;

[0025] Figure 10 depicts a system for reducing the storage space used in tracking the behavior of multiple network endpoints by modeling behavior with a behavior model using a hash table, and

[0026] Figure 11 depicts an illustrative flowchart of a process for reducing the storage space used in tracking the behavior of multiple network endpoints by modeling behavior with a behavior model using a hash table, according to some embodiments of the present disclosure. Detailed Description

[0027] Figure 1depicts a system for reducing the storage space used in tracking the behavior of multiple network endpoints by modeling behavior with a behavior model, according to some embodiments of the present disclosure. As Figure 1 depicted in, server 100 is used to model the behavior of network endpoints (e.g., network endpoints 112 and 114) of network 110. Although server 100 is described as a single server including several components, this is for convenience only. The components of server 100 may be distributed across multiple servers and databases. As used herein, a network endpoint may be any end device, such as a consumer electronic device (e.g., a smart phone, a personal computer, etc.), an Internet of Things device, or any other user-facing device connected to network 110.

[0028] The control circuitry 102 of server 100 receives records from network endpoints (e.g., network devices 112 and 114) of network 110 via the communication circuitry 120. The communication circuitry 120 may be any known receiver, transmitter, transceiver, or any other known device for transmitting and / or receiving data. As used herein, the term "record" may refer to a log of network activities. Examples of records are Netflow records, IPFIX records, HTTP proxy logs, etc. In some embodiments, each record identifies a single network flow. In some embodiments, the control circuitry 102 may augment the records to include additional metadata, such as application identifiers, HTTP / HTTPs (HTTP Secure) header values, Transport Layer Security ("TLS") certificate details, etc. The control circuitry 102 may augment the records through fingerprinting processing and / or may perform such augmentation by ingesting bidirectional IPFIX records.

[0029] The records may be received at buffer 130. The control circuitry 102 may determine which network endpoint each record corresponds to. For example, the control circuitry 102 may distinguish between records corresponding to network endpoint 112 and records corresponding to network endpoint 114. Then, the control circuitry 102 may assign a different queue to each network endpoint such that records corresponding to each different network endpoint are sent from buffer 130 to the designated queue of queue 140. As Figure 1 depicted in, records corresponding to network endpoint 112 may be sent to queue 142, and records corresponding to network endpoint 114 may be sent to queue 144. The control circuitry 102 may instantiate multiple queues n as needed to use dedicated queues for each network endpoint receiving records. In some embodiments, queue 140 is a FIFO queue. In other embodiments, queue 140 may be any form of queue.

[0030] In some embodiments, control circuitry 102 schedules the processing of records in queue 140, where the processing is performed by module 150. Module 150 is not dedicated to a given queue. As an example, queue 144 can be assigned to module 152 for processing, as Figure 1 depicted. When any module in module 154 finishes processing records from a given queue, module 154 returns to an idle state.

[0031] In some embodiments, control circuitry 102 identifies idle modules and commands each idle module to process records from a specific queue. When selecting which queue of queue 150 an idle module should be assigned to, control circuitry can determine which queues are size-overflowed by determining which queues have a record count exceeding a threshold. In some embodiments, the threshold is configured by a network administrator. In some embodiments, the threshold is a default value. Control circuitry 102 can prioritize these queues by first assigning idle modules to queues having a record count exceeding the threshold. Control circuitry can assign the remaining idle modules based on any known load balancing scheme (e.g., based on which queues have the most records) or arbitrarily assign the remaining idle modules.

[0032] In some embodiments, as a result of processing records of a given queue of queue 140, module 150 generates a behavior model. A given module (e.g., module 154) can generate a behavior model by encoding the data of the record into a multi-dimensional vector. In some embodiments, to encode the data, control circuitry 102 instructs a module of module 150 (e.g., module 152) to extract data from a subset of fields of a record of a given queue (e.g., queue 144). Control circuitry 102 instructs the module (e.g., module 152) to generate a string from the extracted data (the string is also referred to herein as a "flow word"). Then, control circuitry 202 can cascade the "flow words" derived from the queue to form a document.

[0033] Figure 2 An example document in accordance with some embodiments of the present disclosure is depicted, the example document including flow words corresponding to a given network endpoint. In document 202, each of the above-mentioned flow words is separated by a space or an underscore. Each flow word has a known meaning mapped in a storage device at server 100 (e.g., at storage circuitry 160). Exemplary meanings 204 are described with reference to each flow word of document 202 and are self-explanatory. Figure 2 The flow word fields shown are merely illustrative; any suitable set of fields can be used.

[0034] After forming the document, the control circuitry 102 feeds the document into the doc2vec algorithm. The doc2vec algorithm is described in detail in the publication titled “Distributed Representations of Sentences and Documents” by Le and Mikolov, published in 2014, the disclosure of which is incorporated herein by reference in its entirety. Doc2vec is based on the word2vec algorithm, which is described in the publication titled “Efficient Estimation of Word Representations in Vector Space” by Mikolov, Chen, Corrado, and Dean, published in 2013, the disclosure of which is incorporated herein by reference in its entirety. Word2vec is further described in U.S. Patent No. 9,037,464, issued on May 19, 2015, the disclosure of which is incorporated herein by reference in its entirety.

[0035] Briefly, when the control circuitry 102 feeds the document into the doc2vec algorithm, the control circuitry 102 uses a shallow neural network to generate a vector encoding for each word that appears in the given document and for the document itself. As described in the above-mentioned publications describing the doc2vec and word2vec algorithms, in one embodiment of the disclosure, the control circuitry 102 implements the “Paragraph Vector–Distributed Bag of Words” formulation of the doc2vec algorithm. This requires the control circuitry 102 to implement a sliding window (e.g., having a configurable size or a default size) that iterates over the document by selecting a subset of the words of the document. The control circuitry 102 then applies stochastic gradient descent to calculate the weights and biases that are most suitable for the shallow neural network in predicting the target identifier for the endpoint. The control circuitry 102 then averages the set of weights for each word to form a vector representing the network endpoint corresponding to the document. The endpoint vector can be represented as an array of floating-point values. In some embodiments, the vector is formed from three hundred to five hundred floating-point values.

[0036] The control circuitry 102 causes each vector to be stored by the storage circuitry 160 into the memory. Also, as described above, since the size of the vectors is limited, it is possible to perform behavioral modeling without using "big data" tools. There are other advantages to avoiding storing the records themselves. Namely, these records often include sensitive private information about the user (e.g., personally identifiable information, financial information, etc.). Thus, if these records are accessed inappropriately (e.g., through hacking or malware operations), legal and privacy issues can arise. As disclosed herein, storing vectors instead of the records themselves avoids these risks by avoiding storing such sensitive information while still maintaining the ability to monitor the behavior of network endpoints.

[0037] The storage circuitry 160 can be any medium capable of storing data. The computer-readable medium can be transient (including but not limited to propagated electrical or electromagnetic signals), or it can be non-transient (including but not limited to volatile and non-volatile computer memories or storage devices such as hard disks, floppy disks, USB drives, DVDs, CDs, media cards, register memories, processor caches, random access memories ("RAM"), etc.). The control circuitry 102 can be based on any suitable processing circuitry, such as one or more microprocessors, microcontrollers, digital signal processors, programmable logic devices, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), etc., and can include multi-core processors (e.g., dual-core, quad-core, six-core or any suitable number of cores) or supercomputers. In some embodiments, the processing circuitry can be distributed across multiple separate processors or processing units, where the multiple separate processors or processing units are, for example, multiple of the same type of processing unit (e.g., two Intel Core i7 processors) or multiple different processors (e.g., an Intel Core i5 processor and an Intel Core i7 processor). In some embodiments, the control circuitry 102 executes instructions stored in the memory (i.e., the storage circuitry 160).

[0038] After the storage of the endpoint vectors, the control circuitry 102 can receive a request from a network administrator to view a given endpoint vector. The control circuitry 102 can respond to such a request by using the application programming interface ("API") 170 to output a visual depiction of the behavioral model.

[0039] In some embodiments, the control circuitry 102 may track the behavior of network endpoints over time. For example, by periodically performing word / document embedding calculations (e.g., Doc2Vec or FastText) over time for a given network endpoint, the control circuitry 102 may identify repeating patterns of the endpoint. Differences in network behavior will be indicated by the movement of the resulting vectors to different locations in the multi-dimensional space from subsequent calculations. The control circuitry 102 may implement a Kalman filter to track the point location over time, or derive a multivariate Gaussian distribution to determine the probability of a point corresponding to the behavior of the network endpoint at a given location in the multi-dimensional space, or use a recurrent neural network to learn how the behavior changes over time. If the point is in a region of low probability values, then the control circuitry 102 may determine that the network endpoint is engaging in abnormal behavior and may alert the network administrator of the anomaly.

[0040] Figure 3 Depicts an illustrative two-dimensional projection of a higher-dimensional vector space in accordance with some embodiments of the present disclosure. Each of the concentric ellipses depicted in the vector space 300 corresponds to a different probability value of where a network administrator expects a given network endpoint to be located. The point 302 labeled with the character "A" illustrates the location that the control circuitry 102 would consider to be normal behavior of the endpoint. However, if the control circuitry 102 determines that the location described by the endpoint vector has moved to the point 306 labeled as "A'", then the control circuitry 102 may alert the network administrator of abnormal behavior. The control circuitry 102 may determine to issue an alert based on the point 306 being outside the boundaries of the normality threshold 304, which may be configured by the network administrator or may be a default value.

[0041] Figure 4 Is an illustrative depiction of a projection onto a 3D space of multiple endpoint vectors in accordance with some embodiments of the present disclosure. In some embodiments, a network administrator may request to view the typical behavior of endpoints in a large heterogeneous network in order to identify clusters of endpoints with similar behavior and quantify their number. The control circuitry 102 that receives such a request may output a visualization of such a 3D space using the API 170, for example, by depicting clusters 402, 404, 406, and 408. Each of these clusters is depicted close to each other due to having similar network behavior.

[0042] Figure 5 Depicts an illustrative flow chart of a process for reducing the storage space used in tracking the behavior of multiple network endpoints by modeling the behavior with a behavior model. The process 500 begins at 502, where the control circuitry (e.g., the control circuitry 102 of the server 100) receives a plurality of records, each corresponding record of the plurality of records corresponding to a respective network endpoint of the plurality of network endpoints.

[0043] Processing 500 continues to 504, where control circuitry 102 determines a corresponding network endpoint among a plurality of network endpoints (e.g., network endpoints 112 and 114 of network 110) corresponding to each respective record of a plurality of records. At 506, control circuitry 102 assigns a corresponding dedicated queue (e.g., queues 142 and 144 of queue 140) to each respective network endpoint.

[0044] At 508, control circuitry 102 sends each record of the plurality of records to each respective dedicated queue, where each record of the plurality of records corresponds to the respective network endpoint to which the respective dedicated queue is assigned. At 510, control circuitry 102 determines a corresponding behavior model for each respective network endpoint based on each record of each respective dedicated queue corresponding to each respective network endpoint. Control circuitry 102 may perform this determination using any module in module 150. At 512, control circuitry 102 stores each corresponding behavior model in a memory (e.g., using storage circuitry 160).

[0045] Figure 6 An illustrative flowchart of a process for determining a corresponding behavior module in accordance with some embodiments of the present disclosure is depicted. Process 600 begins at 602, where control circuitry 102 initiates a subroutine for determining a corresponding behavior model (e.g., a subroutine for implementing Figure 5 of 510). At 604, control circuitry 102 identifies a plurality of modules (e.g., module 150) programmed to determine behavior models. At 606, control circuitry 102 identifies an idle module among the plurality of modules, and at 608, control circuitry 102 commands the idle module to determine a corresponding behavior model.

[0046] Figure 7 An illustrative flowchart of a process for warning a network administrator of abnormal network endpoint behavior in accordance with some embodiments of the present disclosure is depicted. Process 700 begins at 702, where control circuitry 102 determines whether a given floating-point value represents abnormal behavior of a given corresponding network endpoint (e.g., network endpoint 112). If the determination is negative, then control circuitry 102 determines that the network endpoint is operating normally. If the determination is positive, then process 700 proceeds to 704, where control circuitry 102 warns the network administrator (e.g., using API 170) to perform a predefined set of actions or similar actions.

[0047] Figure 8Illustrates an illustrative flowchart of a process for generating vectors for modeling endpoint device behavior using a word / document embedding algorithm (e.g., doc2vec). The process 800 begins at 802, where the control circuitry 102 extracts corresponding data from corresponding fields of each respective individual network flow. At 804, the control circuitry 102 concatenates the corresponding data into a string. At 806, the control circuitry 102 forms a document (e.g., document 202) having the string. At 808, the control circuitry 102 feeds the document into a word / document embedding algorithm (e.g., doc2vec or FastText). At 810, the control circuitry 102 analyzes the document using a shallow neural network with the word / document embedding algorithm. At 812, the control circuitry 102 outputs a vector (e.g., outputs to the memory 160 or outputs to the API 170 for generating a visual representation).

[0048] Figure 9 Illustrates an illustrative flowchart of a process for generating a visual representation of a behavior model for display in accordance with some embodiments of the present disclosure. The process 900 begins at 902, where the control circuitry 102 determines whether a command to view a corresponding behavior model for a given network endpoint has been received. If the determination is negative, then the process 900 ends. If the determination is positive, then the process 900 continues to 904, where the control circuitry 102 generates a graphical representation (e.g., the representation depicted in Figure 3 for display of the corresponding behavior model for the given network endpoint. At 906, the control circuitry 102 identifies different network endpoints having corresponding behavior models showing behavior similar to the behavior of the given network endpoint. At 908, the control circuitry 102 generates corresponding behavior models (e.g., the representations depicted in Figure 4 for simultaneous display with the graphical representation of the corresponding behavior model for the given network endpoint).

[0049] Figure 10 Illustrates a system for reducing storage space used in tracking the behavior of multiple network endpoints by modeling behavior with a behavior model using a hash table in accordance with some embodiments of the present disclosure. Figure 10Including server 1000, which acts in the same way as server 100 works as described above. Server 1000 receives records from network endpoints of network 1014 (e.g., network endpoint 1012 and network endpoint 1014). Network 1014 acts in the same way as network 110 works as described above. Network endpoints 1012 and 1014 act in the same way as network endpoints 112 and network endpoint 1014 work as described above. Server 1000 uses communication circuitry 1020 to receive records, and the communication circuitry 1020 acts in the same way as communication circuitry 120 works as described above.

[0050] Ingest module 1030 receives records from network 1010 and operates in the manner described above. For example, the operation of control circuitry 102 in conjunction with buffer 130 as described above is equivalent to the way control circuitry 1002 interacts with ingest module 1030. Records ingested by ingest module 1030 are forwarded to word encoding module 1040. Word encoding module 1040 encodes the records into words in the manner described previously. For example, word encoding will result in the generation of streaming words, such as Figure 2 the streaming words depicted in

[0051] After encoding records from network endpoints into words, control circuitry 1002 modifies hash table 1050 to include records corresponding to each network endpoint. For example, control circuitry 1002 can determine whether a network endpoint (e.g., endpoint 10 corresponding to endpoint 1014 in network 1010) already has an entry on the hash table. If control circuitry 1002 determines that there is no entry for endpoint 10 on hash table 1050, then control circuitry 1002 adds a block (such as block 1052) to hash table 1050 for endpoint 10. For each network endpoint, control circuitry 1002 associates the words encoded by word encoding module 1040 to a linked list (e.g., linked list 1054) corresponding to the given network endpoint.

[0052] After filling the hash table 1050, the control circuitry 1002 may feed the hash table 1050 into the language model 1060. In some embodiments, the control circuitry 1002 determines that the hash table 1050 is filled based on the elapse of a threshold amount of time, which may be configured by a network administrator or may be a default amount of time. In some embodiments, the control circuitry 1002 determines that the hash table 1050 is filled based on the filling of a threshold number of words (e.g., one million words). This may be the words in the aggregation for all endpoints or may be the words in the aggregation for a single endpoint. The language model 1060 generates a behavior model for each endpoint based on the words filled for each endpoint. The behavior model is generated based on an algorithm derived from "FastText", which is described in the publication titled "Enriching Word Vectors with Subword Information" by P. Bojanowski, E. Grave, A. Joulin, and T. Mikolov and published in 2016, the disclosure of which is incorporated herein by reference in its entirety. FastText itself is based on the word2vec algorithm discussed above. The control circuitry 1002 commands that the behavior model generated using the language model 1060 be stored in the model repository 1070, which operates in the manner described above for the storage circuitry 160. The control circuitry 1002 may use the API in any of the ways described above with respect to the API 170 such that the behavior model 1080 is output to the user.

[0053] Figure 11 Depicted is an illustrative flowchart of a process for reducing the storage space used to track the behavior of multiple network endpoints by modeling behavior with a behavior model using a hash table in accordance with some embodiments of the present disclosure. Process 1100 begins at 1102, where the control circuitry (e.g., control circuitry 1002) receives a plurality of records (e.g., from network endpoints 1012 of network 1014), each respective record of the plurality of records corresponding to a respective network endpoint of the plurality of network endpoints. Process 1000 continues to 1104, where the control circuitry 1002 determines the respective network endpoint of the plurality of network endpoints corresponding to each respective record of the plurality of records.

[0054] At 1106, the control circuitry 1002 encodes each respective record into a respective word. At 1108, the control circuitry 1002 assigns a respective block to a respective hash table (e.g., hash table 1050) for each respective record. At 1110, the control circuitry 1002 adds the respective word corresponding to the network endpoint associated with each respective block to a respective linked list record (e.g., using linked list 1054) for each respective block. At 1112, the control circuitry 1002 determines a respective behavior model (e.g., using language model 1060) for each respective network endpoint based on each respective linked list for each respective block. At 1114, the control circuitry 1002 stores each respective behavior model into a memory (e.g., using model repository 1070).

[0055] For the sake of brevity, in the Figures 3 - 9 and Figure 11 descriptions, there is no repeated description of the elements described in detail in processes 300 - 900 and 1100 regarding Figure 1 and Figure 2 However, the above elements are intended to perform the Figures 3 - 9 and Figure 11 corresponding descriptions.

[0056] Systems, methods, and apparatuses for generating and storing zero - footprint behavior models for network endpoints (e.g., from network 110) have been described above. The above embodiments of the present disclosure are given for purposes of illustration and not limitation. Additionally, the present disclosure is not limited to a particular implementation. For example, one or more steps of the above methods can be performed in a different order (or concurrently) and still achieve the desired result. Further, the present disclosure can be implemented in hardware (such as on an application - specific integrated circuit (ASIC) or a field - programmable gate array (FPGA)). The present disclosure can also be implemented in software by encoding transient or non - transient instructions for performing the above - described processes in one or more transient or non - transient computer - readable media.

[0057] As mentioned herein, the term "responsive to" means being initiated as a result thereof. For example, performing a first action responsive to a second action can include an intervening step between the first action and the second action.

Claims

1. A method for reducing the storage space used in tracking the behaviors of multiple network endpoints by modeling behaviors with behavior models, the method comprises: receiving a plurality of records, each corresponding record in the plurality of records corresponding to a corresponding network endpoint among the plurality of network endpoints; determining the corresponding network endpoint among the plurality of network endpoints corresponding to each corresponding record in the plurality of records; assigning a corresponding dedicated queue to each corresponding network endpoint; sending each record in the plurality of records to each corresponding dedicated queue, each record in the plurality of records corresponding to the corresponding network endpoint to which the corresponding dedicated queue is assigned; for each corresponding network endpoint, generating a corresponding vector representing a corresponding behavior model using the records of the corresponding dedicated queue corresponding to the corresponding network endpoint, wherein generating the corresponding vector further comprises: encoding each corresponding record in the records within the corresponding dedicated queue into a corresponding string, wherein encoding each corresponding record comprises: extracting data from a subset of fields of the corresponding record, and concatenating the data into the corresponding string; forming a document having each string encoded from the corresponding record in the records in the corresponding dedicated queue; feeding the document into a document-to-vector doc2vec algorithm; using the doc2vec algorithm to analyze the document; and outputting the corresponding vector based on the analysis; storing each corresponding vector in a memory; and determining an abnormal behavior state of the network endpoint by comparing the corresponding vector of the network endpoint among the plurality of network endpoints with a normal threshold in a multi-dimensional space.

2. The method according to claim 1, wherein generating a corresponding vector representing a corresponding behavior model comprises: identifying a plurality of modules programmed to generate a corresponding vector representing a corresponding behavior model; identifying the idle modules among the plurality of modules; and commanding the idle modules to generate a corresponding vector representing a corresponding behavior model.

3. The method according to claim 1, wherein using the doc2vec algorithm to analyze the document comprises: using the doc2vec algorithm and using a shallow neural network to analyze the document.

4. The method according to claim 1, further comprises: tracking the behavior of each corresponding network endpoint over time by indicating differences in network behavior through the movement of the corresponding vector of the network endpoint from subsequent calculations to different positions in a multi-dimensional space.

5. The method according to claim 4, wherein a Kalman filter is used to perform the tracking.

6. The method according to claim 1, wherein each corresponding record identifies a corresponding single network flow originating from the corresponding network endpoint corresponding to the corresponding record.

7. The method according to claim 1, wherein generating a corresponding vector representing a corresponding behavior model further comprises: identifying a plurality of modules programmed to generate a corresponding vector representing a corresponding behavior model; identifying the idle modules among the plurality of modules; determining a first dedicated queue each having a record number exceeding a threshold; and assigning a first portion of the identified idle modules to the first dedicated queue.

8. The method according to claim 7, wherein generating a corresponding vector representing a corresponding behavior model further comprises: Based on the load balancing scheme, assign the second part of the identified idle modules to the second dedicated queue.

9. The method according to claim 1, wherein the plurality of records have a first data size, wherein the sum of the data sizes of each corresponding behavior model has a second data size, and wherein the second data size is two or more orders of magnitude smaller than the first data size.

10. A system for reducing the storage space used in tracking the behavior of multiple network endpoints by modeling behavior with behavior models, the system comprising: a storage circuitry; a communication circuitry; and a control circuitry configured to: receive, by the communication circuitry, a plurality of records, each corresponding record of the plurality of records corresponding to a corresponding network endpoint among the plurality of network endpoints; determine the corresponding network endpoint among the plurality of network endpoints corresponding to each corresponding record of the plurality of records; assign a corresponding dedicated queue to each corresponding network endpoint; send each record of the plurality of records to each corresponding dedicated queue, each record of the plurality of records corresponding to the corresponding network endpoint to which the corresponding dedicated queue is assigned; for each corresponding network endpoint, generate a corresponding vector representing a corresponding behavior model using the records of the corresponding dedicated queue corresponding to the corresponding network endpoint, wherein generating the corresponding vector further comprises: encoding each corresponding record in the records within the corresponding dedicated queue into a corresponding string, wherein encoding each corresponding record comprises: extracting data from a subset of the fields of the corresponding record and concatenating the data into the corresponding string; forming a document having each corresponding string encoded from the corresponding records in the corresponding dedicated queue; feeding the document into a document-to-vector doc2vec algorithm to output the corresponding vector; using the doc2vec algorithm to analyze the document; and outputting the corresponding vector based on the analysis; store each corresponding vector in a memory by the storage circuitry; and determine the abnormal behavior state of the network endpoint by comparing the corresponding vector of the network endpoint among the plurality of network endpoints with a normal threshold in a multi-dimensional space.

11. The system according to claim 10, wherein in order to generate a corresponding vector representing a corresponding behavior model, the control circuitry is further configured to: identify a plurality of modules programmed to generate a corresponding vector representing a corresponding behavior model; identify the idle modules among the plurality of modules; and command the idle modules to generate a corresponding vector representing a corresponding behavior model.

12. The system according to claim 10, wherein the control circuitry is further configured to: track the behavior of each corresponding network endpoint over time by indicating the difference in network behavior by the movement of the corresponding vector from a subsequent calculation to different positions in a multi-dimensional space.

13. The system according to claim 10, wherein each corresponding record identifies a corresponding single network flow originating from the corresponding network endpoint corresponding to the corresponding record.

14. The system according to claim 10, wherein in order to generate a corresponding vector representing a corresponding behavior model, the control circuitry is further configured to: Identify a plurality of modules programmed to generate respective vectors representing respective behavior models; Identify idle modules among the plurality of modules; Determine a first dedicated queue each having a record count exceeding a threshold; And Assign a first portion of the identified idle modules to the first dedicated queue.

15. The system of claim 14, wherein, to generate the respective vectors representing the respective behavior models, the control circuitry is further configured to: Assign a second portion of the identified idle modules to a second dedicated queue based on a load balancing scheme.

16. The system of claim 10, wherein the plurality of records have a first data size, wherein the sum of the data sizes of each respective behavior model has a second data size, and wherein the second data size is smaller than the first data size by two or more orders of magnitude.

17. A non-transitory computer-readable medium having instructions stored thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations for executing the method according to any one of claims 1-9.

Citation Information

Patent Citations

  • Computing numeric representations of words in a high-dimensional space

    US9037464B1

  • Method for recording event logs and database engine

    CN103729442A

  • Behavioral analysis to automate direct and indirect local monitoring of internet of things device health

    CN107409073A