Invention Grant
- Patent Title: Anomaly detection to identify security threats
-
Application No.: US15276647Application Date: 2016-09-26
-
Publication No.: US10673880B1Publication Date: 2020-06-02
- Inventor: Robert Winslow Pratt , Ravi Prasad Bulusu
- Applicant: Splunk Inc.
- Applicant Address: US CA San Francisco
- Assignee: SPLUNK INC.
- Current Assignee: SPLUNK INC.
- Current Assignee Address: US CA San Francisco
- Agency: Perkins Coie LLP
- Main IPC: G06F21/64
- IPC: G06F21/64 ; G06F12/08 ; H04L29/06 ; G06N20/00

Abstract:
Techniques are described for processing anomalies detected using user-specified rules with anomalies detected using machine-learning based behavioral analysis models to identify threat indicators and security threats to a computer network. In an embodiment, anomalies are detected based on processing event data at a network security system that used rules-based anomaly detection. These rules-based detected anomalies are acquired by a network security system that uses machine-learning based anomaly detection. The rules-based detected anomalies are processed along with machine learning detected anomalies to detect threat indicators or security threats to the computer network. The threat indicators and security threats are output as alerts to the network security system that used rules-based anomaly detection.
Information query