首页> 外国专利> COMPUTER SECURITY ATTACK DETECTION USING DISTRIBUTION DEPARTURE

COMPUTER SECURITY ATTACK DETECTION USING DISTRIBUTION DEPARTURE

机译:使用分布区进行计算机安全攻击检测

摘要

Described technologies automatically detect computing system security attacks. Departure of occurrence distributions, which are based on leading digit(s) of digital item occurrence data, from model distributions that correspond to particular data sources, indicates a presence likelihood for particular attack types. Some model distributions exhibit Benford's Phenomenon. Described mechanisms detect security attack types such as ransomware, bitcoin mining, and others, using particular corresponding data sources such as file extensions, processor statistics, etc. Mechanisms detect security attacks without a captured baseline of healthy normal behavior, and without relying on malware code signatures. When an item occurrence distribution departs from a model distribution by at least a predefined degree, the technology electronically raises a security attack alert. Then countermeasures may be asserted for a possible type X security attack on the computing system. Countermeasures may include more computationally intensive tests for determining the precise extent or precise nature of an attack, for instance.
机译:所描述的技术可自动检测计算系统的安全攻击。基于数字项目出现数据的前导数字的出现分布与对应于特定数据源的模型分布的偏离指示了特定攻击类型的存在可能性。一些模型分布展示了本福德现象。描述的机制使用特定的相应数据源(例如文件扩展名,处理器统计信息等)检测勒索软件,比特币挖掘等安全攻击类型。该机制无需捕获健康的正常行为基线并且不依赖恶意软件代码即可检测安全攻击。签名。当项目发生分布与模型分布的偏离至少达到预定程度时,该技术会以电子方式发出安全攻击警报。然后可以断言针对计算系统上可能的X型安全攻击的对策。例如,对策可能包括更多的计算密集型测试,以确定攻击的确切范围或确切性质。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号