首页> 外国专利> Method and system for detecting intrusive anomalous use of a software system using multiple detection algorithms

Method and system for detecting intrusive anomalous use of a software system using multiple detection algorithms

机译:使用多种检测算法检测软件系统的侵入性异常使用的方法和系统

摘要

A target software system is instrumented to generate behavior data representing a current observation or observation aggregate. A method then determines whether the current observation or observation aggregate warrants a second level examination; preferably, this determination is made by processing the current observation or observation aggregate through a first level detection algorithm that provides a provisional indication of a possible intrusion. If executing the first level detection algorithm indicates that the current observation or observation aggregate warrants a second level examination, the method continues by processing the current observation or observation aggregate through at least one second level detection algorithms to provide a more definite, fine grain indication of a possible intrusion. Multiple algorithms may be executed together within a single examination level, with the individual results then analyzed to obtain a composite result or output indicative of intrusive or anomalous behavior.
机译:使用目标软件系统来生成代表当前观察值或观察值汇总的行为数据。然后,一种方法确定当前的观测值或观测值汇总是否值得进行第二级检查;优选地,该确定是通过第一水平检测算法处理当前观察或观察集合而做出的,该第一水平检测算法提供对可能入侵的临时指示。如果执行第一级检测算法指示当前观察值或观察值集合需要进行第二级检查,则该方法继续通过至少一个第二级检测算法来处理当前观察值或观察值集合,以提供更明确的细粒度指示。可能的入侵。可以在单个检查级别内一起执行多种算法,然后对单个结果进行分析以获得指示侵入性或异常行为的复合结果或输出。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号