System and method for detection of targeted attack based on information from multiple sources
Abstract:
Disclosed are methods, systems, and computer programs for detecting targeted attacks on compromised computer from multiple sources. An example method includes obtaining data from multiple computer systems and devices connected with one another in a communications network to determine a possibility of a targeted attack from a network resource, the data comprising information relating to the network resource and a set of parameters of each computer system or device in accessing the network resource; detecting discrepancies in the obtained data; forming and sending queries to a group of computer systems and devices detecting the possibility of the targeted attack with the set of parameters of the group of computer systems and devices in accessing the network resource; and calculating a probability of the targeted attack from the network resource based at least upon information received from the group of computer systems and devices in response to the queries.
Information query
Patent Agency Ranking
0/0