Invention Grant
- Patent Title: Detecting cyber attacks by correlating alerts sequences in a cluster environment
-
Application No.: US15444124Application Date: 2017-02-27
-
Publication No.: US10474966B2Publication Date: 2019-11-12
- Inventor: Moshe Israel , Dotan Patrich
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Workman Nydegger
- Main IPC: G06F21/55
- IPC: G06F21/55 ; G06N20/00 ; H04L29/08 ; H04L29/06

Abstract:
Providing network entities with notifications of attacks on the entities. A method includes collecting alerts from a plurality of network entities in a cluster computing environment. Alerts are grouped into heterogeneous groups of alerts. Each group includes a plurality of different types of alerts. Each alert has corresponding properties, including at least one property identifying the type of alert. Each group of alerts corresponds to a timeline of alerts for a particular entity. Groups of alerts that correspond to a valid cyber-kill chain are identified. Different groups of alerts that correspond to a valid cyber-kill chain are correlated into clusters of groups of alerts by correlating the types of alerts and corresponding properties. At least one cluster is identified as having some characteristic of interest. Entities corresponding to groups of alerts in the cluster are notified of the characteristic of interest.
Public/Granted literature
- US20180248893A1 Detecting Cyber Attacks by Correlating Alerts Sequences in a Cluster Environment Public/Granted day:2018-08-30
Information query