- 专利标题: Hierarchical novelty detection using intended states for network security
-
申请号: US16900240申请日: 2020-06-12
-
公开(公告)号: US11729207B2公开(公告)日: 2023-08-15
- 发明人: Zhen Mo , Vijay Ganti , Debessay Fesehaye Kassa , Barak Raz , Honglei Li
- 申请人: VMware, Inc.
- 申请人地址: US CA Palo Alto
- 专利权人: VMWARE, INC.
- 当前专利权人: VMWARE, INC.
- 当前专利权人地址: US CA Palo Alto
- 代理机构: Patterson + Sheridan, LLP
- 主分类号: H04L9/40
- IPC分类号: H04L9/40
摘要:
The disclosure provides an approach for detecting and preventing attacks in a network. Embodiments include determining a plurality of network behaviors of a process by monitoring the process. Embodiments include generating a plurality of intended states for the process based on subsets of the plurality of network behaviors. Embodiments include determining a plurality of intended state clusters by applying a clustering technique to the plurality of intended states. Embodiments include determining a state of the process. Embodiments include identifying a given cluster of the plurality of intended state clusters that corresponds to the state of the process. Embodiments include selecting a novelty detection technique based on a size of the given cluster. Embodiments include using the novelty detection technique to determine, based on the given cluster and the state of the process, whether to generate a security alert for the process.
公开/授权文献
信息查询