发明名称 Cyber security
摘要 Input data is received S1 that is associated with an entity associated with a computer system (10, fig. 1), e.g. a user or device. Preferably the data includes data relating to the entitys activity on the computer system. Metrics, representative of the datas characteristics, are derived S2 from the data and may reflect usage of the computer system by the entity over time, e.g. metrics relating to network traffic. The metrics are analysed S3 using one or more models, perhaps arranged to detect different types of threat. A cyber-threat risk parameter is determined S4, S5 in accordance with the analysed metrics and a model of normal behaviour of the entity, e.g. by comparing the metrics with the model. The parameter is indicative of a likelihood of a cyber-threat, preferably the probability of such likelihood, and is preferably determined using recursive Bayesian estimation. The parameter may be compared with a threshold, possibly a moving threshold, to determine whether or not there is a threat. The model of normal behaviour may be updated in accordance with the analysed metrics. Input data associated with a second entity may also be taken into consideration.
申请公布号 GB2529150(A) 申请公布日期 2016.02.17
申请号 GB20140013789 申请日期 2014.08.04
申请人 DARKTRACE LIMITED 发明人 JACK STOCKDALE;ALEX MARKHAM
分类号 G06F21/55;G06F21/56;G06F21/57;H04L29/06 主分类号 G06F21/55
代理机构 代理人
主权项
地址