首页> 外国专利> MALICIOUS ACTIVITY DETECTION ON A COMPUTER NETWORK AND NETWORK METADATA NORMALISATION

MALICIOUS ACTIVITY DETECTION ON A COMPUTER NETWORK AND NETWORK METADATA NORMALISATION

机译:计算机网络上的恶意活动检测和网络元数据标准化

摘要

The invention relates to a network security and data normalisation system for a computer network, IT system or infrastructure, or similar. According to an aspect, there is provided a method for identifying abnormal user interactions within one or more monitored computer networks, comprising the steps of: receiving metadata from one or more devices within the one or more monitored computer networks; identifying from the metadata events corresponding to a plurality of user interactions with the monitored computer networks; storing user interaction event data from the identified said events corresponding to a plurality of user interactions with the monitored computer networks; updating a probabilistic model of expected user interactions from said stored user interaction event data; and testing each of said plurality of user interactions with the monitored computer networks against said probabilistic model to identify abnormal user interactions.
机译:本发明涉及用于计算机网络,IT系统或基础设施或类似物的网络安全和数据标准化系统。根据一个方面,提供了一种用于识别一个或多个受监视计算机网络内的异常用户交互的方法,该方法包括以下步骤:从一个或多个受监视计算机网络内的一个或多个设备接收元数据;从元数据中识别与被监视的计算机网络的多个用户交互相对应的事件;存储来自所识别的所述事件的用户交互事件数据,所述事件对应于与所监视的计算机网络的多个用户交互;从所述存储的用户交互事件数据更新预期用户交互的概率模型;根据所述概率模型测试与所述受监视计算机网络的所述多个用户交互中的每一个,以识别异常用户交互。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号