Patent · US Active

ML-based encrypted file classification for identifying encrypted data movement

US11947682B2 · kind B2 · utility

1Cited by
45References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 7, 2022
Grant dateApr 2, 2024
Priority date
Expiry dateJul 7, 2042

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1425
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

The disclosed technology teaches facilitate User and Entity Behavior Analytics (UEBA) by classifying a file being transferred as encrypted or not. The technology involves monitoring movement of a files by a user over a wide area network, detecting file encryption for the files using a trained classifier, wherein the detecting includes processing by the classifier some or all of the following features extracted from each of the files: a chi-square randomness test; an arithmetic mean test; a serial correlation coefficient test; a Monte Carlo-Pi test; and a Shannon entropy test, counting a number of the encrypted files moved by the user in a predetermined period, comparing a predetermined maximum number of encrypted files allowed in the predetermined period to the count of the encrypted files moved by the user and detecting that the user has moved more encrypted files than the predetermined maximum number, and generating an alert.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.