首页> 外国专利> Detection dictionary system supporting anomaly detection across multiple operating environments

Detection dictionary system supporting anomaly detection across multiple operating environments

机译:检测字典系统支持跨多个操作环境的异常检测

摘要

A detection dictionary system provides a framework for describing, detecting, and reporting anomalies across multiple operating environments each including multiple computing devices. An anomaly in an operating environment refers to one or more operations or activities in the operating environment that may be indicative of an attack on the operating environment by a malicious user or program. The framework includes guarantees, detections, properties, and detection instances. Guarantees are promises or assertions made to an entity (e.g., a business or other organization) that describes what the detection dictionary system will detect and alert on when a particular trend or anomaly is identified. A detection is a set of metadata describing how to fulfill a given guarantee. A property describes how to map the detection to a particular detection instance. A detection instance is a specific implementation of a detection as applied to a property.
机译:检测字典系统提供了用于描述,检测和报告跨多个操作环境的异常的框架,每个操作环境包括多个计算设备。操作环境中的异常是指操作环境中的一个或多个操作或活动,这些操作或活动可能表示恶意用户或程序对操作环境的攻击。该框架包括保证,检测,属性和检测实例。保证是对实体(例如,企业或其他组织)做出的承诺或主张,它们描述检测字典系统将在检测到特定趋势或异常时检测并发出警报。检测是描述如何实现给定保证的一组元数据。属性描述如何将检测映射到特定检测实例。检测实例是应用于属性的检测的特定实现。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号