发明名称 GRAPH-BASED INTRUSION DETECTION USING PROCESS TRACES
摘要 Methods and systems for detecting malicious processes include modeling system data as a graph comprising vertices that represent system entities and edges that represent events between respective system entities. Each edge has one or more timestamps corresponding respective events between two system entities. A set of valid path patterns that relate to potential attacks is generated. One or more event sequences in the system are determined to be suspicious based on the graph and the valid path patterns using a random walk on the graph.
申请公布号 WO2017019391(A1) 申请公布日期 2017.02.02
申请号 WO2016US43040 申请日期 2016.07.20
申请人 NEC LABORATORIES AMERICA, INC. 发明人 CHEN, Zhengzhang;TANG, LuAn;DONG, Boxiang;JIANG, Guofei;CHEN, Haifeng
分类号 G06F21/55 主分类号 G06F21/55
代理机构 代理人
主权项
地址