-
公开(公告)号:US11245711B2
公开(公告)日:2022-02-08
申请号:US16838991
申请日:2020-04-02
申请人: Anomali Inc.
发明人: Wei Huang , Yizheng Zhou , Peizhou Guo , Mohsen Imani
IPC分类号: G06F15/173 , H04L29/06 , H04L29/08 , H04L12/26 , G06F16/22
摘要: A system and a method are disclosed for describing a mechanism for tracking malicious activity detected on a network. For example, based on network data collected from a server, the disclosed system may detect malicious activity originating from a client device directed to the server. To detect the malicious activity, network data may be captured by the server and analyzed. When malicious activity is detected, the system may track the malicious activity, using the network data, to an earliest connection date of a client device from where the malicious activity potentially originated. The earliest connection date may indicate a potential start date of the malicious activity.
-
公开(公告)号:US20200322363A1
公开(公告)日:2020-10-08
申请号:US16838991
申请日:2020-04-02
申请人: Anomali Inc.
发明人: Wei Huang , Yizheng Zhou , Peizhou Guo , Mohsen Imani
摘要: A system and a method are disclosed for describing a mechanism for tracking malicious activity detected on a network. For example, based on network data collected from a server, the disclosed system may detect malicious activity originating from a client device directed to the server. To detect the malicious activity, network data may be captured by the server and analyzed. When malicious activity is detected, the system may track the malicious activity, using the network data, to an earliest connection date of a client device from where the malicious activity potentially originated. The earliest connection date may indicate a potential start date of the malicious activity
-
公开(公告)号:US11509669B2
公开(公告)日:2022-11-22
申请号:US17569408
申请日:2022-01-05
申请人: Anomali Inc.
发明人: Wei Huang , Yizheng Zhou , Peizhou Guo , Mohsen Imani
IPC分类号: G06F15/173 , H04L9/40 , H04L67/141 , H04L43/16 , G06F16/22 , H04L43/08
摘要: A system and a method are disclosed for describing a mechanism for tracking malicious activity detected on a network. For example, based on network data collected from a server, the disclosed system may detect malicious activity originating from a client device directed to the server. To detect the malicious activity, network data may be captured by the server and analyzed. When malicious activity is detected, the system may track the malicious activity, using the network data, to an earliest connection date of a client device from where the malicious activity potentially originated. The earliest connection date may indicate a potential start date of the malicious activity.
-
公开(公告)号:US20220131881A1
公开(公告)日:2022-04-28
申请号:US17569408
申请日:2022-01-05
申请人: Anomali Inc.
发明人: Wei Huang , Yizheng Zhou , Peizhou Guo , Mohsen Imani
IPC分类号: G06F21/56 , H04L67/141 , H04L43/16 , G06F16/22 , H04L43/08
摘要: A system and a method are disclosed for describing a mechanism for tracking malicious activity detected on a network. For example, based on network data collected from a server, the disclosed system may detect malicious activity originating from a client device directed to the server. To detect the malicious activity, network data may be captured by the server and analyzed. When malicious activity is detected, the system may track the malicious activity, using the network data, to an earliest connection date of a client device from where the malicious activity potentially originated. The earliest connection date may indicate a potential start date of the malicious activity
-
-
-