首页> 外国专利> System and method of detecting anomalous events based on known safe events

System and method of detecting anomalous events based on known safe events

机译:基于已知安全事件检测异常事件的系统和方法

摘要

A system and method is provided for detecting anomalous events occurring in an operating system of a computing device. An exemplary method includes detecting an event that occurs in the operating system of the computing device during execution of a software process. Moreover, the method includes determining a context of the detected event and forming a convolution of the detected event based on selected features of the determined context of the detected event. Further, the method includes determining a popularity of the formed convolution by polling a database containing data relating to a frequency of detected events occurring in client devices in a network, where the detected events of the client devices correspond to the detected event in the computing device. If the determined popularity is below a threshold value, the method determines that the detected event is an anomalous event.
机译:提供了一种用于检测在计算设备的操作系统中发生的异常事件的系统和方法。示例性方法包括在软件过程的执行期间检测在计算设备的操作系统中发生的事件。而且,该方法包括确定所检测事件的上下文,并基于所检测事件的所确定上下文的所选特征来形成所检测事件的卷积。此外,该方法包括通过轮询数据库来确定形成的卷积的流行度,该数据库包含与网络中客户端设备中发生的检测到的事件的频率有关的数据,其中客户端设备的检测到的事件与计算设备中的检测到的事件相对应。 。如果确定的流行度低于阈值,则该方法确定检测到的事件是异常事件。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号