发明名称 Dual-path distributed architecture for network security analysis
摘要 A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
申请公布号 US9591010(B1) 申请公布日期 2017.03.07
申请号 US201514929224 申请日期 2015.10.30
申请人 Splunk Inc. 发明人 Muddu Sudhakar;Tryfonas Christos;Bulusu Ravi Prasad
分类号 H04L29/06;G06N99/00 主分类号 H04L29/06
代理机构 Perkins Coie LLP 代理人 Perkins Coie LLP
主权项 1. A network security breach detection system comprising: a real-time path including a real-time analysis engine configured to receive first event data indicative of first activity on a computer network, the real-time event analysis engine configured to detect, in real time, first indicia of possible security breaches based on the first event data, and to generate, in real-time, analysis result data representing the first indicia for output to a user; a non-volatile storage system to store the real-time analysis result data; and a batch path including a batch analysis engine configured to operate concurrently with the real-time analysis engine, the batch analysis engine further configured to retrieve, from the non-volatile storage system, the real-time analysis result data and second event data indicative of second activity on the computer network, the second event data having been stored in the non-volatile storage system prior to analysis of the first event data by the real-time analysis engine, the batch analysis engine further configured to detect, in a batch mode, second indicia of possible security breaches based on the second event data and the real-time analysis result data.
地址 San Francisco CA US