Invention Grant
- Patent Title: Anomaly detection using adaptive behavioral profiles
- Patent Title (中): 使用自适应行为轮廓的异常检测
-
Application No.: US14811732Application Date: 2015-07-28
-
Publication No.: US09544321B2Publication Date: 2017-01-10
- Inventor: Igor A. Baikalov , Tanuj Gulati , Sachin Nayyar , Anjaneya Shenoy , Ganpatrao H. Patwardhan
- Applicant: Securonix, Inc.
- Applicant Address: US CA Los Angeles
- Assignee: Securonix, Inc.
- Current Assignee: Securonix, Inc.
- Current Assignee Address: US CA Los Angeles
- Agent Barry N. Young
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06N7/00

Abstract:
Anomalous activities in a computer network are detected using adaptive behavioral profiles that are created by measuring at a plurality of points and over a period of time observables corresponding to behavioral indicators related to an activity. Normal kernel distributions are created about each point, and the behavioral profiles are created automatically by combining the distributions using the measured values and a Gaussian kernel density estimation process that estimates values between measurement points. Behavioral profiles are adapted periodically using data aging to de-emphasize older data in favor of current data. The process creates behavioral profiles without regard to the data distribution. An anomaly probability profile is created as a normalized inverse of the behavioral profile, and is used to determine the probability that a behavior indicator is indicative of a threat. The anomaly detection process has a low false positive rate.
Public/Granted literature
- US20160226901A1 Anomaly Detection Using Adaptive Behavioral Profiles Public/Granted day:2016-08-04
Information query