白丝美女被狂躁免费视频网站,500av导航大全精品,yw.193.cnc爆乳尤物未满,97se亚洲综合色区,аⅴ天堂中文在线网官网

Context informed abnormal endpoint behavior detection

專利號
US11888881B2
公開日期
2024-01-30
申請人
Palo Alto Networks, Inc.(US CA Santa Clara)
發(fā)明人
Shai Meir; Dany Cohen; Arkady Miasnikov; Ohad Ohayon
IPC分類
H04L9/40; G06N20/00
技術(shù)領(lǐng)域
causality,event,endpoint,adaptive,profile,malicious,security,file,normal,events
地域: CA CA Santa Clara

摘要

Adaptive normal profiles are generated at a hierarchical scope corresponding to a set of endpoints and a process. Abnormal endpoint activity is detected by verifying whether event data tracking activity on the set of endpoints conforms to the adaptive normal profiles. False positives are reduced by verifying alarms correspond to normal endpoint activity. Abnormal event data is forwarded to a causality chain identifier that identifies abnormal chains of processes for the abnormal endpoint activity. A trained threat detection model receives abnormal causality chains from the causality chain identifier and indicates a likelihood of corresponding to a malicious attack that indicates abnormal endpoint behavior.

說明書

FIG. 1 is a conceptual diagram of a profile generator generating adaptive normal profiles. Agent 1 102, agent 2 104, and agent N 106 are embedded on endpoint 1 101, endpoint 2 103, and endpoint N 105 respectively. The embedded agents 102, 104, and 106 generate event data and send the event data to event processor 110. In this illustration, the agent N 106 on endpoint N 105 detects event data 108 and sends the event data 108 to the event processor 110. The event processor 110 sends the event data to event database 107 for future use. The event processor 110 also comprises an event importance filter 109 and an event normalizer 111 that process the event data into bucketed event data that the event processor 110 sends to a bucketed event database 113. In response to a query of scoping parameters such as scoping parameters 121, 123, and 125, a profile generator 119 accesses the bucketed event database 113 in order to generate adaptive normal profiles. The profile database 117 stores the generated adaptive normal profiles corresponding to the scoping parameters.

權(quán)利要求

1
微信群二維碼
意見反饋