PATH SCANNING FOR THE DETECTION OF ANOMALOUS SUBGRAPHS, ANOMALY/CHANGE DETECTION AND NETWORK SITUATIONAL AWARENESS
    1.
    发明申请
    PATH SCANNING FOR THE DETECTION OF ANOMALOUS SUBGRAPHS, ANOMALY/CHANGE DETECTION AND NETWORK SITUATIONAL AWARENESS 审中-公开
    检测异常子进程的路径扫描,异常/变化检测和网络状况意识

    公开(公告)号:WO2013184206A3

    公开(公告)日:2014-02-20

    申请号:PCT/US2013031402

    申请日:2013-03-14

    Abstract: A system, apparatus, computer-readable medium, and computer-implemented method are provided for detecting anomalous behavior in a network. Historical parameters of the network are determined in order to determine normal activity levels. A plurality of paths in the network are enumerated as part of a graph representing the network, where each computing system in the network may be a node in the graph and the sequence of connections between two computing systems may be a directed edge in the graph. A statistical model is applied to the plurality of paths in the graph on a sliding window basis to detect anomalous behavior. Data collected by a Unified Host Collection Agent ("UHCA") may also be used to detect anomalous behavior.

    Abstract translation: 提供了一种用于检测网络中的异常行为的系统,装置,计算机可读介质和计算机实现的方法。 确定网络的历史参数以确定正常的活动水平。 网络中的多个路径被列举为表示网络的图的一部分,其中网络中的每个计算系统可以是图中的节点,并且两个计算系统之间的连接序列可以是图中的有向边。 统计模型在滑动窗口基础上应用于图中的多个路径,以检测异常行为。 统一主机收集代理(“UHCA”)收集的数据也可用于检测异常行为。

Patent Agency Ranking