首页> 外国专利> Modeling and outlier detection in threat management system data

Modeling and outlier detection in threat management system data

机译:威胁管理系统数据中的建模和异常值检测

摘要

Methods, systems, and computer-readable media for identifying potential threats on a network based on anomalous behavior in communication between endpoints are provided. Traffic data for a network is accumulated over some period of time. The traffic data is grouped by one or more keys, such as source IP address, and sets of metric values are calculated for the keys. A mixture distribution, such as a negative binomial mixture distribution, is fitted to each set of metric values, and outlying metric values are determined based on the mixture distribution(s). A list of outliers is then generated comprising key values having outlying metric values in one or more of the sets of metric values.
机译:提供了用于基于端点之间的通信中的异常行为来识别网络上的潜在威胁的方法,系统和计算机可读介质。网络的流量数据是在一段时间内累积的。交通数据按一个或多个键(例如源IP地址)分组,并为这些键计算一组度量值。将混合分布(例如负二项式混合分布)拟合到每组度量值,并根据混合分布确定外围度量值。然后,生成离群值列表,其中包括在一组或多组度量值中具有离奇度量值的键值。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号