发明名称 METHOD AND APPARATUS FOR DETECTING SECURITY ANOMALIES IN A PUBLIC CLOUD ENVIRONMENT USING NETWORK ACTIVITY MONITORING, APPLICATION PROFILING, AND SELF-BUILDING HOST MAPPING
摘要 The disclosed computer-implemented method for detecting security anomalies in a public cloud environment using network activity monitoring, application profiling, and self-building host mapping may include (1) collecting host information that identifies (A) at least one communication channel that has previously facilitated communication between at least one host computing platform within a cloud computing environment and at least one additional computing platform and/or (B) at least one application that has previously run on the host computing platform, (2) monitoring network traffic involving the host computing platform, (3) detecting, while monitoring the network traffic, network activity that is inconsistent with the collected host information, and then (4) determining that the detected network activity represents a potential security threat within the cloud computing environment due at least in part to the detected network activity being inconsistent with the collected host information. Various other methods, systems, and computer-readable media are also disclosed.
申请公布号 WO2017048340(A1) 申请公布日期 2017.03.23
申请号 WO2016US38301 申请日期 2016.06.20
申请人 SYMANTEC CORPORATION 发明人 MOHANTY, Shubhabrata;IYER, Sudha
分类号 H04L29/06;G06F21/55 主分类号 H04L29/06
代理机构 代理人
主权项
地址