首页> 外国专利> Methods and system for identifying relationships among infrastructure security-related events

Methods and system for identifying relationships among infrastructure security-related events

机译:用于识别基础设施安全相关事件之间的关系的方法和系统

摘要

A novel enterprise security solution allows for precise interception and surgical response to attack progression, in real time, as it occurs across a distributed infrastructure. The solution includes a data monitoring and management framework that continually models system level host and network activities as mutually exclusive infrastructure wide execution sequences and bucketizes them into unique execution trails. A multimodal intelligent security middleware detects indicators of compromise in real-time on top of subsets of each unique execution trail using rule based behavioral analytics, machine learning based anomaly detection, and other sources. Each detection result dynamically contributes to aggregated risk scores at execution trail level granularities. These scores can be used to prioritize and identify highest risk attack trails to end users, along with steps that such end users can perform to mitigate further damage and progression of an attack.
机译:新颖的企业安全解决方案允许在分布式基础架构中实时准确地拦截和对攻击进程进行实时响应。该解决方案包括一个数据监视和管理框架,该框架将系统级主机和网络活动连续建模为互斥的基础架构范围的执行序列,并将它们存储在唯一的执行轨迹中。多模式智能安全中间件使用基于规则的行为分析,基于机器学习的异常检测和其他来源,实时检测每个唯一执行轨迹的子集之上的危害指标。每个检测结果都以执行线索级别的粒度动态地有助于汇总风险评分。这些分数可用于为最终用户确定优先级和确定最高风险的攻击路径,以及这些最终用户可以执行的步骤来减轻进一步的破坏和攻击进程。

著录项

  • 公开/公告号US10630703B1

    专利类型

  • 公开/公告日2020-04-21

    原文格式PDF

  • 申请/专利权人 CONFLUERA INC.;

    申请/专利号US201916521855

  • 发明设计人 ABHIJIT GHOSH;NILOY MUKHERJEE;EUN-GYU KIM;

    申请日2019-07-25

  • 分类号H04L29/06;G06F21/55;G06N20;

  • 国家 US

  • 入库时间 2022-08-21 11:29:19

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号