-
公开(公告)号:US20240073241A1
公开(公告)日:2024-02-29
申请号:US18256438
申请日:2021-11-29
Inventor: Alfie BEARD , Pushpinder CHOUHAN , Liming CHEN
IPC: H04L9/40
CPC classification number: H04L63/1441 , H04L63/1416
Abstract: An intrusion response system (IRS) can include a knowledge-based intrusion response (IR) component configured to use knowledge of prior responses to prior behavior of at least one computer system to determine a first response to behavior of a target computer system; a prediction-based IR component configured to use at least one trained machine learning (ML) model of behavior of the target computer system to predict a second response to the behavior of the target computer system; and a response component configured to determine an output response to the behavior of the target computer system based on at least one of the first response and the second response.
-
公开(公告)号:US20230379355A1
公开(公告)日:2023-11-23
申请号:US18247128
申请日:2021-09-29
Inventor: Xiao-Si WANG , Christopher NUGENT , Pushpinder CHOUHAN , Md BISWAS
IPC: H04L9/40
CPC classification number: H04L63/1441 , H04L63/1416 , G16Y30/10
Abstract: A computer implemented security method for a set of internet-of-things (IoT) devices, the set of devices comprising network-connected sensors and actuators, wherein a data repository stores data about the devices, actions performable by each of the devices and one or more network attacks to which at least a subset of the devices are susceptible, the method comprising: defining, for each network attack, one or more responsive actions for the attack, each responsive action identifying one or more performable actions for performance by one or more devices to mitigate the attack; detecting a device in a compromised state, the compromised state being determined based on a threshold number of occurrences of an attack perpetrated against the device; selecting responsive actions for the perpetrated attack; and triggering the responsive actions to mitigate the perpetrated attack.
-