发明名称 |
METHOD OF DETECTING ANOMALOUS BEHAVIOUR IN A COMPUTER NETWORK |
摘要 |
Method of detecting anomalous behaviour in a computer network comprising the steps of : monitoring network traffic flowing in a computer network system, authenticating users to which network packets of the network traffic are associated, extracting parameters associated to the network packets for each user, said parameters including at least the type (T) of network services, forming symbols based on a combination of one or more of said parameters, and modelling and analysing individual user behaviour based on sequences of occurrence of said symbols (S). <IMAGE> |
申请公布号 |
EP1738551(A1) |
申请公布日期 |
2007.01.03 |
申请号 |
EP20050718490 |
申请日期 |
2005.04.19 |
申请人 |
ECOLE POLYTECHNIQUE FEDERALE DE LAUSANNE (EPFL) |
发明人 |
BELAKHDAR, OMAR;BADOS, PEDRO;FALTINGS, BOI |
分类号 |
H04L29/06;G06F21/31;G06F21/55;H04L12/26 |
主分类号 |
H04L29/06 |
代理机构 |
|
代理人 |
|
主权项 |
|
地址 |
|