首页> 外国专利> Anomaly detection apparatus based on outlier score in EDR

Anomaly detection apparatus based on outlier score in EDR

机译:基于EDR的异常值得分数的异常检测装置

摘要

The present invention relates to an apparatus and method for detecting anomalies in EDR based on an outlier score.In particular, a distance is calculated using a Euclidean distance, Minkowski distance, and a cosine distance calculation method for a network traffic log or event, and then the corresponding distance is calculated. The present invention relates to an apparatus and method for detecting anomalies in an EDR based on an outlier score that enables detection of an outlier in a network traffic log or an event by using it as an outlier score. In addition, according to the present invention, there is provided a feature extraction unit for extracting a feature of network traffic data; A distance calculator that calculates a distance of data using the extracted features; And an analysis unit that extracts statistics using the number of data within a specific range from the distance of the data, and then determines the analyzed data as an outlier of the top n%. An apparatus and method for detecting anomalies in an EDR based on an outlier score is provided. .
机译:本发明涉及一种用于基于异常值得分检测EDR中的异常的装置和方法。特别地,使用欧几里德距离,Minkowski距离和网络流量日志或事件的余弦距离计算方法计算距离,以及然后计算相应的距离。本发明涉及一种用于基于EDR中检测异常的装置和方法,其通过使用它作为异常值分数来检测网络流量日志或事件中的异常值。另外,根据本发明,提供了一种特征提取单元,用于提取网络流量数据的特征;使用提取的特征计算数据距离的距离计算器;和一个分析单元,用特定范围内的数据数从数据距离中提取统计信息,然后将分析的数据确定为顶部n%的异常值。提供了一种用于基于异常值得分检测EDR中的异常的装置和方法。 。

著录项

  • 公开/公告号KR102251467B1

    专利类型

  • 公开/公告日2021-05-13

    原文格式PDF

  • 申请/专利权人

    申请/专利号KR1020190090027

  • 发明设计人 이태진;김수정;

    申请日2019-07-25

  • 分类号H04L12/26;H04L12/24;

  • 国家 KR

  • 入库时间 2022-08-24 18:48:07

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号