CNIPA.AI
검색으로 돌아가기
기록

DETECTING SECURITY THREATS FROM LOGON DATA

발명심사 중
1조회수
20청구항 · 3 독립항
§ Ⅰ

개요

발명자

Saibala Lakkaraju; Srinivas Chava; Kristine Wetch; Naga lakshmi subha pavan kumar Ghantasala; Moshe Adam Van Berg; Elvis Dang; Vamsi Kadiyala; Satish Raj Katakam

IPC 분류

H4L 9/40G6N 3/88G6N 3/9

CPC 분류

H4L63/1408G6N3/88G6N3/9H4L63/1441

This disclosure describes techniques for analyzing network traffic to generate an actionable insight pertaining to a security threat to a network. In one example, this disclosure describes a method that includes obtaining, by a computing system, historical network activity data that includes information about authentication traffic within a network; determining, by the computing system and based on the historical network activity, a baseline of network activity; collecting, by the computing system, a set of network activity data; applying, by the computing system, an unsupervised algorithm to identify the set of network activity data as anomalous relative to the baseline of network activity; classifying, by the computing system, the network activity data into an identified threat category from among a plurality of threat categories; and taking action, by the computing system and based on the identified threat category, to mitigate a security threat posed by the network activity data.

원문 (중국어)

This disclosure describes techniques for analyzing network traffic to generate an actionable insight pertaining to a security threat to a network. In one example, this disclosure describes a method that includes obtaining, by a computing system, historical network activity data that includes information about authentication traffic within a network; determining, by the computing system and based on the historical network activity, a baseline of network activity; collecting, by the computing system, a set of network activity data; applying, by the computing system, an unsupervised algorithm to identify the set of network activity data as anomalous relative to the baseline of network activity; classifying, by the computing system, the network activity data into an identified threat category from among a plurality of threat categories; and taking action, by the computing system and based on the identified threat category, to mitigate a security threat posed by the network activity data.