Invention Grant
- Patent Title: Systems and methods for reducing false positives when using event-correlation graphs to detect attacks on computing systems
- Patent Title (中): 使用事件相关图来检测对计算系统的攻击时减少误报的系统和方法
-
Application No.: US14031044Application Date: 2013-09-19
-
Publication No.: US09166997B1Publication Date: 2015-10-20
- Inventor: Fanglu Guo , Sandeep Bhatkar , Kevin Roundy
- Applicant: Symantec Corporation
- Applicant Address: US CA Mountain View
- Assignee: Symantec Corporation
- Current Assignee: Symantec Corporation
- Current Assignee Address: US CA Mountain View
- Agency: ALG Intellectual Property, LLC
- Main IPC: H04L29/00
- IPC: H04L29/00 ; H04L29/06 ; G06F21/57

Abstract:
A computer-implemented method for reducing false positives when using event-correlation graphs to detect attacks on computing systems may include (1) detecting a suspicious event involving a first actor within a computing system, (2) constructing an event-correlation graph that includes a first node that represents the first actor, a second node that represents a second actor, and an edge that represents an additional suspicious event involving the first actor and the second actor, (3) comparing the event-correlation graph with at least one additional event-correlation graph that represents events on at least one additional computing system, (4) determining that a similarity of the event-correlation graph and the additional event-correlation graph exceeds a predetermined threshold, and (5) classifying the suspicious event as benign based on determining that the similarity of the event-correlation graph and the additional event-correlation graph exceeds the predetermined threshold. Various other methods, systems, and computer-readable media are also disclosed.
Information query