Invention Grant
- Patent Title: Anomaly detection in groups of network addresses
- Patent Title (中): 网络地址组异常检测
-
Application No.: US14253945Application Date: 2014-04-16
-
Publication No.: US09497206B2Publication Date: 2016-11-15
- Inventor: Ruth Bernstein , Andrey Dulkin , Assaf Weiss , Aviram Shmueli
- Applicant: Cyber-Ark Software Ltd.
- Applicant Address: IL Petach-Tikva
- Assignee: Cyber-Ark Software Ltd.
- Current Assignee: Cyber-Ark Software Ltd.
- Current Assignee Address: IL Petach-Tikva
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
A method for identifying anomalies in a group of network addresses includes building a model of the group of network addresses and identifying a network address as anomalous based on the deviation of the network address from the model. The model is built from a group of network addresses. The network addresses are input and parsed into one or more address trees. A ripeness score is maintained for each of the nodes in the address trees, based, at least in part, on the number of occurrences of the network address portion represented by the node. Nodes having respective ripeness scores within a specified range are classified as ripe nodes, and may be indicative of normal behavior, and nodes having respective ripeness scores outside the specified range of ripeness scores are classified as unripe, and may be indicative of anomalous behavior.
Public/Granted literature
- US20150304349A1 ANOMALY DETECTION IN GROUPS OF NETWORK ADDRESSES Public/Granted day:2015-10-22
Information query