首页> 外国专利> UNSUPERVISED ENCODER-DECODER NEURAL NETWORK SECURITY EVENT DETECTION

UNSUPERVISED ENCODER-DECODER NEURAL NETWORK SECURITY EVENT DETECTION

机译:未经监督的编码器-解码器神经网络安全事件检测

摘要

A method may include a processing system having at least one processor obtaining a first plurality of domain name system traffic records, generating an input aggregate vector from the first plurality of domain name system traffic records, where the input aggregate vector comprises a plurality of features derived from the first plurality of domain name system traffic records, and applying an encoder-decoder neural network to the input aggregate vector to generate a reconstructed vector, where the encoder-decoder neural network is trained with a plurality of aggregate vectors generated from a second plurality of domain name system traffic records. In one example, the processing system may then calculate a distance between the input aggregate vector and the reconstructed vector, and apply at least one remedial action associated with the first plurality of domain name system traffic records when the distance is greater than a threshold distance.
机译:一种方法可以包括具有至少一个处理器的处理系统,该处理器获得第一多个域名系统业务记录,从第一多个域名系统业务记录生成输入聚合向量,其中输入聚合向量包括多个导出的特征从第一批多个域名系统流量记录中提取数据,并将编码器-解码器神经网络应用于输入的聚合矢量以生成重构矢量,其中,使用从第二组多个生成的多个聚合矢量训练编码器-解码器神经网络域名系统流量记录。在一个示例中,处理系统然后可以计算输入的聚合矢量和重构的矢量之间的距离,并且当该距离大于阈值距离时,应用与第一多个域名系统流量记录相关联的至少一个补救措施。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号