Invention Grant
- Patent Title: Aggregating alerts of malicious events for computer security
-
Application No.: US17456362Application Date: 2021-11-23
-
Publication No.: US11601400B2Publication Date: 2023-03-07
- Inventor: Gilad Yehudai , Itsik Mantin , Lior Fisch , Shelly Hershkovitz , Amichai Shulman , Moran Rachel Ambar
- Applicant: Imperva, Inc.
- Applicant Address: US CA San Mateo
- Assignee: Imperva, Inc.
- Current Assignee: Imperva, Inc.
- Current Assignee Address: US CA San Mateo
- Agency: Nicholson, De Vos, Webster & Elliott, LLP
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06K9/62

Abstract:
A method by a computing device implementing an attack analyzer for processing malicious events. The method includes determining a first set of features describing a malicious event detected by a firewall, determining a set of distances using a non-Euclidean distance function and the first set of features, wherein the non-Euclidean distance function is used to determine geographic origin similarity between different Internet Protocol addresses included in the first and second set of features, generating a statistical distribution object using the set of distances, wherein the statistical distribution object includes information describing a cluster that includes at least the malicious event and one or more other malicious events that are determined to be similar to the malicious event in terms of geographic origin, and transmitting information describing the cluster to a management console for presentation to an administrator on a graphical user interface.
Public/Granted literature
- US20220086125A1 AGGREGATING ALERTS OF MALICIOUS EVENTS FOR COMPUTER SECURITY Public/Granted day:2022-03-17
Information query