首页> 外国专利> LEARNING INDICATORS OF COMPROMISE WITH HIERARCHICAL MODELS

LEARNING INDICATORS OF COMPROMISE WITH HIERARCHICAL MODELS

机译:分层模型的妥协性学习指标

摘要

Presented herein are techniques for classifying devices as being infected with malware based on learned indicators of compromise. A method includes receiving at a security analysis device, traffic flows from a plurality of entities destined for a plurality of users, aggregating the traffic flows into discrete bags of traffic, wherein the bags of traffic comprise a plurality of flows of traffic for a given user over a predetermined period of time, extracting features from the bags of traffic and aggregating the features into per-flow feature vectors, aggregating the per-flow feature vectors into per-destination domain aggregated vectors, combining the per-destination-domain aggregated vectors into a per-user aggregated vector, and classifying a computing device used by a given user as infected with malware when indicators of compromise detected in the bags of traffic indicate that the per-user aggregated vector for the given user includes suspicious features among the extracted features.
机译:本文提出的是基于学习到的危害指标将设备归类为感染了恶意软件的技术。一种方法,包括在安全分析设备处接收来自多个实体的,面向多个用户的业务流,将业务流聚合成离散的业务流,其中业务流包括给定用户的多个业务流在预定的时间段内,从交通流量中提取特征并将特征聚合到每个流特征向量中,将每个流特征向量聚合到每个目标域聚合向量中,将每个目标域聚合向量合并到每个用户的聚合向量,并在流量袋中检测到的危害指标指示给定用户的每个用户的聚合向量包括提取的特征中的可疑特征时,将给定用户使用的计算设备分类为感染了恶意软件。

著录项

  • 公开/公告号US2018063163A1

    专利类型

  • 公开/公告日2018-03-01

    原文格式PDF

  • 申请/专利权人 CISCO TECHNOLOGY INC.;

    申请/专利号US201615248252

  • 发明设计人 PETR SOMOL;TOMAS PEVNY;

    申请日2016-08-26

  • 分类号H04L29/06;H04L29/08;

  • 国家 US

  • 入库时间 2022-08-21 13:00:14

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号