会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 6. 发明授权
    • Systems and methods for identifying security threat sources responsible for security events
    • 用于识别负责安全事件的安全威胁源的系统和方法
    • US09571510B1
    • 2017-02-14
    • US14519565
    • 2014-10-21
    • Symantec Corporation
    • Yun ShenOlivier Thonnard
    • G06F21/57H04L29/06
    • H04L63/1416H04L63/1408H04L63/1441H04L63/306
    • The disclosed computer-implemented method for identifying security threat sources responsible for security events may include (1) identifying security-event data collected from a plurality of security events detected over a network, (2) partitioning the security-event data into a set of single-dimensional security clusters, each grouped by a common feature, (3) determining that a subset of the single-dimensional security clusters exceed a threshold level of similarity relative to one another, (4) grouping the subset of single-dimensional clusters into a multi-dimensional security cluster corresponding to a single threat source in response to determining that the subset of single-dimensional clusters exceed the threshold level of similarity relative to one another, and then (5) determining, based at least in part on grouping the single-dimensional clusters into the multi-dimensional cluster, that the single threat source is likely responsible for some of the security events. Various other methods, systems, and computer-readable media are also disclosed.
    • 用于识别负责安全事件的安全威胁源的公开的计算机实现的方法可以包括(1)识别从通过网络检测到的多个安全事件中收集的安全事件数据,(2)将安全事件数据分成一组 (3)确定单维安全集群的子集相对于彼此超过相似度的阈值水平,(4)将一维集群的子集分成 响应于确定所述单维集群的子集相对于彼此超过相似度的阈值水平,对应于单一威胁源的多维度安全集群,然后(5)至少部分地基于将 单维集群进入多维集群,单个威胁源可能会对某些安全事件负责。 还公开了各种其它方法,系统和计算机可读介质。