白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Context informed abnormal endpoint behavior detection

專利號
US11888881B2
公開日期
2024-01-30
申請人
Palo Alto Networks, Inc.(US CA Santa Clara)
發(fā)明人
Shai Meir; Dany Cohen; Arkady Miasnikov; Ohad Ohayon
IPC分類
H04L9/40; G06N20/00
技術(shù)領(lǐng)域
causality,event,endpoint,adaptive,profile,malicious,security,file,normal,events
地域: CA CA Santa Clara

摘要

Adaptive normal profiles are generated at a hierarchical scope corresponding to a set of endpoints and a process. Abnormal endpoint activity is detected by verifying whether event data tracking activity on the set of endpoints conforms to the adaptive normal profiles. False positives are reduced by verifying alarms correspond to normal endpoint activity. Abnormal event data is forwarded to a causality chain identifier that identifies abnormal chains of processes for the abnormal endpoint activity. A trained threat detection model receives abnormal causality chains from the causality chain identifier and indicates a likelihood of corresponding to a malicious attack that indicates abnormal endpoint behavior.

說明書

At block 501, a profile generator receives a query to create an adaptive normal profile for a specific process and a set of hierarchical endpoint groups. The query includes scoping parameters that specify hierarchical endpoint levels from which to create the adaptive normal profile.

At block 503, the profile generator begins iterating over the hierarchical endpoint levels indicated in the query. The profile generator can iterate through hierarchical endpoint levels in an arbitrary order, although in some embodiments database access will be more efficient when iterating from the narrowest to the broadest hierarchical endpoint levels. The loop of operations includes example operations at blocks 505 and 507.

At block 505, the profile generator determines frequent events for the current hierarchical endpoint level and process. The profile generator aggregates event data across a current hierarchical endpoint level corresponding to the process. The profile generator accesses a bucketed event database and queries the database according to the current hierarchical endpoint level. The database sends the profile generator a batch of frequent events corresponding to the current hierarchical endpoint level, unless there are no frequent events for the current hierarchical endpoint level.

權(quán)利要求

1
微信群二維碼
意見反饋