首页> 外国专利> Method of classifying and active learning that ranks entries based on multiple scores, presents entries to human analysts, and detects and/or prevents malicious behavior

Method of classifying and active learning that ranks entries based on multiple scores, presents entries to human analysts, and detects and/or prevents malicious behavior

机译:一种分类和主动学习的方法,该方法基于多个分数对条目进行排名,将条目提供给分析人员,并检测和/或防止恶意行为

摘要

A malicious behavior detection/prevention system, such as an intrusion detection system, is provided that uses active learning to classify entries into multiple classes. A single entry can correspond to either the occurrence of one or more events or the non-occurrence of one or more events. During a training phase, entries are automatically classified into one of multiple classes. After classifying the entry, a generated model for the determined class is utilized to determine how well an entry corresponds to the model. Ambiguous classifications along with entries that do not fit the model well for the determined class are selected for labeling by a human analyst. The selected entries are presented to a human analyst for labeling. These labels are used to further train the classifier and the models. During an evaluation phase, entries are automatically classified using the trained classifier and a policy associated with determined class is applied.
机译:提供了一种恶意行为检测/预防系统,例如入侵检测系统,其使用主动学习将条目分类为多个类别。单个条目可以对应于一个或多个事件的发生或一个或多个事件的不发生。在培训阶段,条目将自动分类为多个类别之一。在对条目进行分类之后,将使用用于确定类别的生成模型来确定条目与模型的对应程度。选择歧义的分类以及与所确定的类别不太适合该模型的条目,以供人工分析人员进行标记。所选条目将提供给人工分析人员进行标记。这些标签用于进一步训练分类器和模型。在评估阶段,将使用训练有素的分类器对条目进行自动分类,并应用与确定的类别关联的策略。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号