发明名称 DETECTION OF MULTI-STEP COMPUTER PROCESSES SUCH AS NETWORK INTRUSIONS
摘要 Multi-step processes such as intrusions into computer networks are detected from individual activities or events such as communications by identifying anchor points (Fig 2, 220) that are likely to be part of the process, proceeding from the anchor points to extract other activitiesas a context of the anchor points, and characterizing the process from the activities in the context. The process may be characterized as sets of context activities.
申请公布号 WO2006076307(A3) 申请公布日期 2006.09.21
申请号 WO2006US00715 申请日期 2006.01.10
申请人 REGENTS OF THE UNIVERSITY OF MINNESOTA;CHANDOLA, VARUN;EILERTSON, ERIC;LIU, HAIYANG;SHANECK, MARK;CHOI, CHANGHO;SIMON, GYORGY;KIM, YONGDAE;KUMAR, VIPIN;SRIVASTAVA, JAIDEEP;ZHANG, ZHI-LI 发明人 CHANDOLA, VARUN;EILERTSON, ERIC;LIU, HAIYANG;SHANECK, MARK;CHOI, CHANGHO;SIMON, GYORGY;KIM, YONGDAE;KUMAR, VIPIN;SRIVASTAVA, JAIDEEP;ZHANG, ZHI-LI
分类号 H04L9/00 主分类号 H04L9/00
代理机构 代理人
主权项
地址