首页> 外国专利> METHODS AND SYSTEMS FOR ANOMALY DETECTION USING FUNCTION SPECIFICATIONS DERIVED FROM SERVER INPUT/OUTPUT (I/O) BEHAVIOR

METHODS AND SYSTEMS FOR ANOMALY DETECTION USING FUNCTION SPECIFICATIONS DERIVED FROM SERVER INPUT/OUTPUT (I/O) BEHAVIOR

机译:使用从服务器输入/输出(I / O)行为得出的功能规范进行异常检测的方法和系统

摘要

Various embodiments include methods of protecting a computing device within a network from malware or other non-benign behaviors. A computing device may monitor inputs and outputs to a server, derive a functional specification from the monitored inputs and outputs, and use the functional specification for anomaly detection. Use of the derived functional specification for anomaly detection may include determining whether a behavior, activity, web application, process or software application program is non-benign. The computing device may be the server, and the functional specification may be used to determine whether the server is under attack. In some embodiments, the computing device may constrain the functional specification with a generic constraint, detect a new input-output pair, determine whether the detected input-output pair satisfies the constrained functional specification, and determine that the detected input-output pair is anomalous upon determining that the detected input-output pair (or request-response pair) satisfies the constrained functional specification.
机译:各种实施例包括保护网络内的计算设备免受恶意软件或其他非良性行为的影响的方法。计算设备可以监视到服务器的输入和输出,从监视的输入和输出中导出功能规范,并将该功能规范用于异常检测。所导出的功能规范用于异常检测的使用可以包括确定行为,活动,Web应用程序,过程或软件应用程序是否是非良性的。计算设备可以是服务器,并且功能规范可以用于确定服务器是否受到攻击。在一些实施例中,计算设备可以用通用约束约束功能规范,检测新的输入输出对,确定检测到的输入输出对是否满足约束的功能规范,并确定检测到的输入输出对是异常的。在确定检测到的输入-输出对(或请求-响应对)满足约束的功能规格时。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号