首页> 外国专利> System And Method For Detecting And Identifying A Cyber-Attack On A Network

System And Method For Detecting And Identifying A Cyber-Attack On A Network

机译:在网络上检测和识别网络攻击的系统和方法

摘要

A method for detecting and/or identifying a cyber-attack on a network can include segmenting the network using a segmentation method with machine learning to generate one or more network segments; assigning a score to a data point within each network segment based on a presence or absence of an identified anomalous behavior of the data point; analyzing network data flow, via behavioral modeling, to provide a context for characterizing the anomalous behavior; combining, via a reinforcement learning agent, outputs of the segmentation method with behavioral modelling and assigned score to detect and/or identify a cyber-attack; providing one or more alerts to an analyst; receiving an analyst assessment of an effectiveness of the detection and/or identification; and providing the analyst assessment as feedback to the reinforcement learning agent.
机译:一种用于检测和/或识别网络上的网络攻击的方法可以包括:使用具有机器学习的分段方法对网络进行分段以生成一个或多个网络段;根据是否存在已识别的数据点异常行为,将分数分配给每个网段内的数据点;通过行为建模分析网络数据流,以提供用于表征异常行为的上下文;经由强化学习代理,将分割方法的输出与行为建模以及指定分数相结合,以检测和/或识别网络攻击;向分析师提供一个或多个警报;接收分析人员对检测和/或识别有效性的评估;并将分析员评估作为反馈提供给强化学习代理。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号