首页> 外国专利> User and entity behavioral analysis with network topology enhancements

User and entity behavioral analysis with network topology enhancements

机译:网络拓扑增强的用户和实体行为分析

摘要

A system and method for network cybersecurity analysis that uses user and entity behavioral analysis combined with network topology information to provide improved cybersecurity. The system and method involve gathering network entity information, establishing baseline behaviors for each entity, and monitoring each entity for behavioral anomalies that might indicate cybersecurity concerns. Further, the system and method involve incorporating network topology information into the analysis by generating a model of the network, annotating the model with risk and criticality information for each entity in the model and with a vulnerability level between entities, and using the model to evaluate cybersecurity risks to the network. Risks and vulnerabilities associated with user entities may be represented, in part or in whole, by the behavioral analyses and monitoring of those user entities.
机译:用于网络网络安全分析的系统和方法,使用用户和实体行为分析与网络拓扑信息相结合以提供改进的网络安全。 该系统和方法涉及收集网络实体信息,为每个实体建立基线行为,并监视可能表明网络安全问题的行为异常的每个实体。 此外,系统和方法涉及通过生成网络的模型将网络拓扑信息结合到分析中,为模型中的每个实体带来具有风险和临界信息的模型,并且在实体之间的漏洞级别以及使用模型来评估 网络安全对网络的风险。 与用户实体相关联的风险和漏洞可以部分地或全部地表示这些用户实体的行为分析和监视。

著录项

  • 公开/公告号US11089045B2

    专利类型

  • 公开/公告日2021-08-10

    原文格式PDF

  • 申请/专利权人 QOMPLX INC.;

    申请/专利号US202016807007

  • 发明设计人 JASON CRABTREE;ANDREW SELLERS;

    申请日2020-03-02

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-24 20:28:36

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号