Invention Grant
- Patent Title: Constructing graph models of event correlation in enterprise security systems
-
Application No.: US15725994Application Date: 2017-10-05
-
Publication No.: US10298607B2Publication Date: 2019-05-21
- Inventor: LuAn Tang , Hengtong Zhang , Zhengzhang Chen , Bo Zong , Zhichun Li , Guofei Jiang , Kenji Yoshihira
- Applicant: NEC Laboratories America, Inc.
- Applicant Address: JP Tokyo
- Assignee: NEC Corporation
- Current Assignee: NEC Corporation
- Current Assignee Address: JP Tokyo
- Agent Joseph Kolodka
- Main IPC: H04L12/24
- IPC: H04L12/24 ; H04L12/46 ; G06F21/55 ; G06F21/57 ; H04L29/06

Abstract:
Methods and systems for detecting anomalous events include detecting anomalous events in monitored system data. An event correlation graph is generated by determining a tendency for a first process to access a system target, including an innate tendency of the first process to access the system target, an influence of previous events from the first process, and an influence of processes other than the first process. Kill chains are generated from the event correlation graph that characterize events in an attack path over time. A security management action is performed based on the kill chains.
Public/Granted literature
- US20180048667A1 CONSTRUCTING GRAPH MODELS OF EVENT CORRELATION IN ENTERPRISE SECURITY SYSTEMS Public/Granted day:2018-02-15
Information query