首页> 外国专利> Identifying threat indicators by processing multiple anomalies

Identifying threat indicators by processing multiple anomalies

机译:通过处理多个异常来识别威胁指标

摘要

Techniques are described for processing anomalies detected using user-specified rules with anomalies detected using machine-learning based behavioral analysis models to identify threat indicators and security threats to a computer network. In an embodiment, anomalies are detected based on processing event data at a network security system that used rules-based anomaly detection. These rules-based detected anomalies are acquired by a network security system that uses machine-learning based anomaly detection. The rules-based detected anomalies are processed along with machine learning detected anomalies to detect threat indicators or security threats to the computer network. The threat indicators and security threats are output as alerts to the network security system that used rules-based anomaly detection.
机译:描述使用使用基于机器学习的行为分析模型检测到的异常检测到使用用户指定规则检测的异常的技术来识别对计算机网络的威胁指示符和安全威胁。在一个实施例中,基于在使用基于规则的异常检测的网络安全系统处的处理事件数据来检测异常。这些基于规则的检测到的异常是由使用基于机器学习的异常检测的网络安全系统获取。基于规则的检测到的异常随机处理,检测到的机器学习检测到的异常,以检测计算机网络的威胁指示符或安全威胁。威胁指示符和安全威胁将作为用于使用基于规则的异常检测的网络安全系统的警报。

著录项

  • 公开/公告号US11019088B2

    专利类型

  • 公开/公告日2021-05-25

    原文格式PDF

  • 申请/专利权人 SPLUNK INC.;

    申请/专利号US202016886542

  • 发明设计人 ROBERT WINSLOW PRATT;RAVI PRASAD BULUSU;

    申请日2020-05-28

  • 分类号G06F21/64;G06F12/08;H04L29/06;G06N20;

  • 国家 US

  • 入库时间 2022-08-24 18:52:35

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号