首页> 外国专利> Systems and methods for preventing malicious network connections using correlation-based anomaly detection

Systems and methods for preventing malicious network connections using correlation-based anomaly detection

机译:使用基于相关的异常检测来防止恶意网络连接的系统和方法

摘要

The disclosed computer-implemented method may include (i) monitoring computing activity, (ii) detecting, during a specific time period, at least one malicious network connection that involves a computing device within a network, (iii) determining that no malicious network connections involving the computing device were detected during another time period, (iv) identifying a feature of the computing activity that (a) occurred during the specific time period and (b) did not occur during the other time period, (v) determining that the feature is likely indicative of malicious network activity due at least in part to the feature having occurred during the specific time period and not having occurred during the other time period, and in response to detecting the feature at a subsequent point in time, (vi) performing a security action on a subsequent network connection attempted around the subsequent point in time. Various other methods, systems, and computer-readable media are also disclosed.
机译:所公开的计算机实现的方法可以包括:(i)监视计算活动,(ii)在特定时间段内检测涉及网络内的计算设备的至少一个恶意网络连接,(iii)确定没有恶意网络连接。在另一个时间段内检测到涉及该计算设备的(iv)识别以下活动的特征:(a)在特定时间段内发生,(b)在另一个时间段内未发生,(v)确定特征很可能表示恶意网络活动,至少部分地是由于该特征已在特定时间段内发生而未在其他时间段内未发生,并且响应于在随后的时间点检测到该特征,(vi)在随后的时间点尝试对随后的网络连接执行安全操作。还公开了各种其他方法,系统和计算机可读介质。

著录项

  • 公开/公告号US10142357B1

    专利类型

  • 公开/公告日2018-11-27

    原文格式PDF

  • 申请/专利权人 SYMANTEC CORPORATION;

    申请/专利号US201615385963

  • 发明设计人 ACAR TAMERSOY;KEVIN ROUNDY;

    申请日2016-12-21

  • 分类号H04L29/06;G06N99;

  • 国家 US

  • 入库时间 2022-08-21 12:08:42

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号