发明名称 |
Path scanning for the detection of anomalous subgraphs and use of DNS requests and host agents for anomaly/change detection and network situational awareness |
摘要 |
A system, apparatus, computer-readable medium, and computer-implemented method are provided for detecting anomalous behavior in a network. Historical parameters of the network are determined in order to determine normal activity levels. A plurality of paths in the network are enumerated as part of a graph representing the network, where each computing system in the network may be a node in the graph and the sequence of connections between two computing systems may be a directed edge in the graph. A statistical model is applied to the plurality of paths in the graph on a sliding window basis to detect anomalous behavior. Data collected by a Unified Host Collection Agent (“UHCA”) may also be used to detect anomalous behavior. |
申请公布号 |
US9560065(B2) |
申请公布日期 |
2017.01.31 |
申请号 |
US201314382992 |
申请日期 |
2013.03.14 |
申请人 |
Los Alamos National Security, LLC |
发明人 |
Neil Joshua Charles;Fisk Michael Edward;Brugh Alexander William;Hash, Jr. Curtis Lee;Storlie Curtis Byron;Uphoff Benjamin;Kent Alexander |
分类号 |
H04L29/00;H04L29/06;H04L1/00;G06N5/02;G06F21/57 |
主分类号 |
H04L29/00 |
代理机构 |
LeonardPatel PC |
代理人 |
LeonardPatel PC |
主权项 |
1. A computer-implemented method, comprising:
determining, by a computing system, historical parameters of a network to determine normal activity levels; enumerating, by the computing system, a plurality of k-paths in the network as part of a graph representing the network, wherein each computing system in the network comprises a node in the graph and a sequence of connections between two computing systems comprise a directed edge in the graph; applying, by the computing system, a Markov edge resolution model to the plurality of k-paths in the graph on a sliding window basis; and detecting, by the computing system, anomalous behavior based on the applied Markov edge resolution model. |
地址 |
Los Alamos NM US |