首页> 外国专利> System and method for correlating historical attacks with diverse indicators to generate indicator profiles for detecting and predicting future network attacks

System and method for correlating historical attacks with diverse indicators to generate indicator profiles for detecting and predicting future network attacks

机译:用于将历史攻击与各种指标相关联以生成指标配置文件以检测和预测未来网络攻击的系统和方法

摘要

An apparatus and method predict and detect network attacks by using a diverse set of indicators to measure aspects of the traffic and by encoding traffic characteristics using these indicators of potential attacks or anomalous behavior. The set of indicators is analyzed by supervised learning to automatically learn a decision rule which examines the temporal patterns in the coded values of the set of indicators to accurately detect and predict network attacks. The rules automatically evolve in response to new attacks as the system updates its rules periodically by analyzing new data and feedback signals about attacks associated with that data. To assist human operators, the system also provides human interpretable explanations of detection and prediction rules by pointing to indicators whose values contribute to a decision that there is an existing network attack or an imminent network attack. When such indictors are detected, an operator can take remediation actions.
机译:一种设备和方法,通过使用各种指示符来测量流量的各个方面并通过使用这些潜在攻击或异常行为的指示符对流量特征进行编码,来预测和检测网络攻击。通过监督学习来分析该组指标,以自动学习决策规则,该决策规则检查该组指标的编码值中的时间模式,以准确检测和预测网络攻击。随着系统通过分析新数据和有关与该数据相关联的攻击的反馈信号来定期更新其规则,这些规则会自动响应新的攻击而发展。为了帮助操作人员,该系统还通过指向指示其值有助于确定是否存在现有网络攻击或即将发生网络攻击的指示符,来对检测和预测规则提供人类可解释的解释。当检测到此类指示符时,操作员可以采取补救措施。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号