- 专利标题: Graph-based fusing of heterogeneous alerts
-
申请号: US15477603申请日: 2017-04-03
-
公开(公告)号: US10476749B2公开(公告)日: 2019-11-12
- 发明人: Kenji Yoshihira , Zhichun Li , Zhengzhang Chen , Haifeng Chen , Guofei Jiang , LuAn Tang
- 申请人: nec laboratories america, inc.
- 申请人地址: JP
- 专利权人: NEC Corporation
- 当前专利权人: NEC Corporation
- 当前专利权人地址: JP
- 代理商 Joseph Kolodka
- 主分类号: H04L12/24
- IPC分类号: H04L12/24 ; H04L29/06 ; G06F21/55
摘要:
Methods and systems for reporting anomalous events include intra-host clustering a set of alerts based on a process graph that models states of process-level events in a network. Hidden relationship clustering is performed on the intra-host clustered alerts based on hidden relationships between alerts in respective clusters. Inter-host clustering is performed on the hidden relationship clustered alerts based on a topology graph that models source and destination relationships between connection events in the network. Inter-host clustered alerts that exceed a threshold level of trustworthiness are reported.
公开/授权文献
- US20170288974A1 GRAPH-BASED FUSING OF HETEROGENEOUS ALERTS 公开/授权日:2017-10-05
信息查询