会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明授权
    • Modeling and outlier detection in threat management system data
    • 威胁管理系统数据中的建模和异常值检测
    • US08528088B2
    • 2013-09-03
    • US13116613
    • 2011-05-26
    • Jeremy WrightJohn HogoboomChaim Spielman
    • Jeremy WrightJohn HogoboomChaim Spielman
    • H04L29/06
    • H04L63/1425G06F21/552H04L63/1416
    • Methods, systems, and computer-readable media for identifying potential threats on a network based on anomalous behavior in communication between endpoints are provided. Traffic data for a network is accumulated over some period of time. The traffic data is grouped by one or more keys, such as source IP address, and sets of metric values are calculated for the keys. A mixture distribution, such as a negative binomial mixture distribution, is fitted to each set of metric values, and outlying metric values are determined based on the mixture distribution(s). A list of outliers is then generated comprising key values having outlying metric values in one or more of the sets of metric values.
    • 提供了用于基于端点之间的通信中的异常行为来识别网络上的潜在威胁的方法,系统和计算机可读介质。 网络的流量数据在一段时间内累积。 交通数据由一个或多个键(例如源IP地址)分组,并且针对密钥计算度量值集合。 混合分布,例如负二项式混合分布,适合于每组度量值,并且基于混合分布来确定偏离度量值。 然后生成异常值列表,其包括在度量值集合中的一个或多个集合中具有超出度量值的密钥值。