首页> 外国专利> Class discovery for automated discovery, attribution, analysis, and risk assessment of security threats

Class discovery for automated discovery, attribution, analysis, and risk assessment of security threats

机译:用于自动发现,归因,分析和评估安全威胁的风险的类发现

摘要

A method for profiling network traffic of a network. The method includes obtaining a signature library comprising a plurality of signatures corresponding to a plurality of behavioral models, generating, based on a first pre-determined criterion, a group behavioral model associated with the signature library, wherein the group behavioral model represents a common behavior of a plurality of historical flows identified from the network traffic, wherein each of the plurality of signatures correlates to a subset of the plurality of historical flows, selecting a flow in the network traffic for including in a target flow set, wherein the flow matches the group behavioral model without matching any of the plurality of behavioral models, analyzing the target flow set to generate a new signature, and adding the new signature to the signature library. Further, each behavioral model is generated from a kernel constructed using boosting of decision tree learning methods.
机译:一种用于分析网络的网络流量的方法。该方法包括:获得包括与多个行为模型相对应的多个签名的签名库;基于第一预定标准,生成与签名库相关联的群体行为模型,其中,群体行为模型表示共同的行为。从网络流量中识别出的多个历史流量中的一个,其中多个签名中的每个与多个历史流量的子集相关,在网络流量中选择一个流量以包含在目标流量集中,其中流量与在不匹配多个行为模型中的任何一个的情况下对行为模型进行分组,分析目标流程集以生成新签名,并将新签名添加到签名库。此外,每个行为模型都是从使用决策树学习方法增强构建的内核中生成的。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号