Invention Grant
US09407652B1 Network anomaly detection 有权
网络异常检测

Network anomaly detection
Abstract:
A security system detects anomalous activity in a network. The system logs user activity, which can include ports used, compares users to find similar users, sorts similar users into cohorts, and compares new user activity to logged behavior of the cohort. The comparison can include a divergence calculation. Origins of user activity can also be used to determine anomalous network activity. The hostname, username, IP address, and timestamp can be used to calculate aggregate scores and convoluted scores.
Public/Granted literature
Information query
Patent Agency Ranking
0/0