首页> 外国专利> Data mining to identify malicious activity

Data mining to identify malicious activity

机译:数据挖掘以识别恶意活动

摘要

Systems and methods may determine suspicious network traffic. A monitoring system comprising a processor in communication with a network may monitor network traffic to or from an asset associated with the network. The monitoring system may assess the network traffic to determine a source and/or destination for the network traffic anchor content of the network traffic. The monitoring system may determine whether the network traffic is suspicious network traffic based on the assessed source and/or destination and/or content. When the network traffic is determined to be suspicious network traffic, the monitoring system may capture metadata associated with the suspicious network traffic and store the metadata in a database in communication with the processor. When the network traffic is not determined to be suspicious network traffic, the monitoring system may disregard metadata associated with the network traffic.
机译:系统和方法可能确定可疑网络流量。包括与网络通信的处理器的监视系统可以监视去往或来自与网络相关联的资产的网络流量。监视系统可以评估网络流量以确定网络流量的源和/或目的地锚定网络流量的内容。监视系统可以基于所评估的源和/或目的地和/或内容来确定网络流量是否为可疑网络流量。当确定网络流量为可疑网络流量时,监视系统可以捕获与可疑网络流量关联的元数据,并将元数据存储在与处理器通信的数据库中。当网络流量未确定为可疑网络流量时,监视系统可以忽略与网络流量关联的元数据。

著录项

  • 公开/公告号US9894088B2

    专利类型

  • 公开/公告日2018-02-13

    原文格式PDF

  • 申请/专利权人 DAMBALLA INC.;

    申请/专利号US201314015582

  • 发明设计人 ANDREW HOBSON;JOSEPH WARD;

    申请日2013-08-30

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 12:57:28

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号