US 11,916,944 B2
Network anomaly detection and profiling
Daniel Bardenstein, San Francisco, CA (US)
Assigned to Palantir Technologies Inc., Denver, CO (US)
Filed by Palantir Technologies Inc., Denver, CO (US)
Filed on Nov. 22, 2021, as Appl. No. 17/456,101.
Application 17/456,101 is a continuation of application No. 16/366,274, filed on Mar. 27, 2019, granted, now 11,218,499.
Application 16/366,274 is a continuation of application No. 15/201,856, filed on Jul. 5, 2016, granted, now 10,291,637, issued on May 14, 2019.
Prior Publication US 2022/0150266 A1, May 12, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01); G06F 21/55 (2013.01)
CPC H04L 63/1425 (2013.01) [G06F 21/552 (2013.01); H04L 63/1408 (2013.01); H04L 63/1416 (2013.01); H04L 63/20 (2013.01)] 18 Claims
OG exemplary drawing
 
1. A computer system for anomaly detection and profiling, the computer system comprising:
one or more computer readable storage devices configured to store computer executable instructions; and
one or more computer processors in communication with the one or more computer readable storage devices and configured to execute the computer executable instructions to cause the computer system to:
access information indicating network activity associated with an actor;
access a data store containing a plurality of profiles, wherein at least some of the plurality of profiles are representative of groups to which previous anomalous network activity has been attributed;
identify one or more features of the network activity that are anomalous;
identify one or more attributes associated with a first profile of the plurality of profiles, the first profile associated with a first group;
compare the one or more features of the network activity to the one or more attributes associated with the first profile to generate a similarity score, wherein the similarity score is indicative of a likelihood that the network activity is associated with the first group;
based at least in part on the similarity score satisfying a threshold, associate the actor with the first profile associated with the first group;
receive one or more filter criteria usable to identify at least the first group and at least a first attribute; and
responsive to receiving the one or more filter criteria, cause display of a user interface including at least a visualization of a trend in at least values of the first attribute associated with the first group over time, wherein the values of the first attribute are based at least in part on the network activity.