Invention Grant
- Patent Title: Network anomaly detection
-
Application No.: US16109379Application Date: 2018-08-22
-
Publication No.: US10735448B2Publication Date: 2020-08-04
- Inventor: Maxim Kesin , Samuel Jones
- Applicant: Palantir Technologies Inc.
- Applicant Address: US CA Palo Alto
- Assignee: Palantir Technologies Inc.
- Current Assignee: Palantir Technologies Inc.
- Current Assignee Address: US CA Palo Alto
- Agency: Knobbe Martens Olson & Bear LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06N7/00 ; H04L29/12 ; H04L29/08

Abstract:
A security system detects anomalous activity in a network. The system logs user activity, which can include ports used, compares users to find similar users, sorts similar users into cohorts, and compares new user activity to logged behavior of the cohort. The comparison can include a divergence calculation. Origins of user activity can also be used to determine anomalous network activity. The hostname, username, IP address, and timestamp can be used to calculate aggregate scores and convoluted scores.
Public/Granted literature
- US20190007441A1 NETWORK ANOMALY DETECTION Public/Granted day:2019-01-03
Information query