发明名称 Path scanning for the detection of anomalous subgraphs and use of DNS requests and host agents for anomaly/change detection and network situational awareness
摘要 A system, apparatus, computer-readable medium, and computer-implemented method are provided for detecting anomalous behavior in a network. Historical parameters of the network are determined in order to determine normal activity levels. A plurality of paths in the network are enumerated as part of a graph representing the network, where each computing system in the network may be a node in the graph and the sequence of connections between two computing systems may be a directed edge in the graph. A statistical model is applied to the plurality of paths in the graph on a sliding window basis to detect anomalous behavior. Data collected by a Unified Host Collection Agent (“UHCA”) may also be used to detect anomalous behavior.
申请公布号 US9560065(B2) 申请公布日期 2017.01.31
申请号 US201314382992 申请日期 2013.03.14
申请人 Los Alamos National Security, LLC 发明人 Neil Joshua Charles;Fisk Michael Edward;Brugh Alexander William;Hash, Jr. Curtis Lee;Storlie Curtis Byron;Uphoff Benjamin;Kent Alexander
分类号 H04L29/00;H04L29/06;H04L1/00;G06N5/02;G06F21/57 主分类号 H04L29/00
代理机构 LeonardPatel PC 代理人 LeonardPatel PC
主权项 1. A computer-implemented method, comprising: determining, by a computing system, historical parameters of a network to determine normal activity levels; enumerating, by the computing system, a plurality of k-paths in the network as part of a graph representing the network, wherein each computing system in the network comprises a node in the graph and a sequence of connections between two computing systems comprise a directed edge in the graph; applying, by the computing system, a Markov edge resolution model to the plurality of k-paths in the graph on a sliding window basis; and detecting, by the computing system, anomalous behavior based on the applied Markov edge resolution model.
地址 Los Alamos NM US