首页> 外国专利> Automated discovery, attribution, analysis, and risk assessment of security threats

Automated discovery, attribution, analysis, and risk assessment of security threats

机译:自动发现,归因,分析和评估安全威胁

摘要

A method for profiling network traffic of a network. The method includes obtaining a signature library comprising a plurality of signatures each representing first data characteristics associated with a corresponding application executing in the network, generating, based on a first pre-determined criterion, a group behavioral model associated with the signature library, wherein the group behavioral model represents a common behavior of a plurality of historical flows identified from the network traffic, wherein each of the plurality of signatures correlates to a subset of the plurality of historical flows, selecting a flow in the network traffic for including in a target flow set, wherein the flow matches the group behavioral model without being correlated to any corresponding application of the plurality of signatures, analyzing the target flow set to generate a new signature, and adding the new signature to the signature library.
机译:一种用于分析网络的网络流量的方法。该方法包括:获得包括多个签名的签名库,每个签名代表与在网络中执行的对应应用相关联的第一数据特征;基于第一预定标准,生成与签名库相关联的群组行为模型,其中,组行为模型表示从网络流量中识别出的多个历史流量的常见行为,其中多个签名中的每个与多个历史流量的子集相关,选择网络流量中的流量以包含在目标流量中集合,其中流与组行为模型匹配而不与多个签名的任何对应应用相关,分析目标流集以生成新签名,并将新签名添加到签名库。

著录项

  • 公开/公告号US9094288B1

    专利类型

  • 公开/公告日2015-07-28

    原文格式PDF

  • 申请/专利权人 ANTONIO NUCCI;SABYASACHI SAHA;

    申请/专利号US201113282010

  • 发明设计人 ANTONIO NUCCI;SABYASACHI SAHA;

    申请日2011-10-26

  • 分类号H04L29/06;H04L12/26;H04L12/24;

  • 国家 US

  • 入库时间 2022-08-21 15:18:39

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号