首页> 外国专利> FINGERPRINT MERGING AND RISK LEVEL EVALUATION FOR NETWORK ANOMALY DETECTION

FINGERPRINT MERGING AND RISK LEVEL EVALUATION FOR NETWORK ANOMALY DETECTION

机译:网络异常检测的指纹合并和风险等级评估

摘要

In one embodiment, a device in a network receives fingerprints of two or more network anomalies detected in the network by different anomaly detectors. Each fingerprint comprises a hash of tags that describe a detected anomaly. The device associates the fingerprints with network records captured within a timeframe in which the two or more network anomalies were detected. The device compares the fingerprints associated with the network records to determine that the two or more detected anomalies are part of a singular anomaly event. The device generates a notification regarding the singular anomaly event, wherein the notification includes those of the fingerprints that are associated with the singular anomaly event.
机译:在一个实施例中,网络中的设备接收由不同异常检测器在网络中检测到的两个或更多个网络异常的指纹。每个指纹都包含描述检测到的异常的标记的哈希。设备将指纹与在检测到两个或多个网络异常的时间范围内捕获的网络记录相关联。设备会比较与网络记录关联的指纹,以确定两个或多个检测到的异常是单个异常事件的一部分。该设备生成关于奇异异常事件的通知,其中该通知包括与奇异异常事件相关联的指纹的那些。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号