CNIPA.AI
返回搜索
档案

DETECTING SECURITY THREATS FROM LOGON DATA

发明专利审中
20权利要求 · 3 独立
§ Ⅰ

卷宗概要

发明人

Saibala Lakkaraju; Srinivas Chava; Kristine Wetch; Naga lakshmi subha pavan kumar Ghantasala; Moshe Adam Van Berg; Elvis Dang; Vamsi Kadiyala; Satish Raj Katakam

IPC 分类

H4L 9/40G6N 3/88G6N 3/9

CPC 分类

H4L63/1408G6N3/88G6N3/9H4L63/1441

This disclosure describes techniques for analyzing network traffic to generate an actionable insight pertaining to a security threat to a network. In one example, this disclosure describes a method that includes obtaining, by a computing system, historical network activity data that includes information about authentication traffic within a network; determining, by the computing system and based on the historical network activity, a baseline of network activity; collecting, by the computing system, a set of network activity data; applying, by the computing system, an unsupervised algorithm to identify the set of network activity data as anomalous relative to the baseline of network activity; classifying, by the computing system, the network activity data into an identified threat category from among a plurality of threat categories; and taking action, by the computing system and based on the identified threat category, to mitigate a security threat posed by the network activity data.

原文(中文)

This disclosure describes techniques for analyzing network traffic to generate an actionable insight pertaining to a security threat to a network. In one example, this disclosure describes a method that includes obtaining, by a computing system, historical network activity data that includes information about authentication traffic within a network; determining, by the computing system and based on the historical network activity, a baseline of network activity; collecting, by the computing system, a set of network activity data; applying, by the computing system, an unsupervised algorithm to identify the set of network activity data as anomalous relative to the baseline of network activity; classifying, by the computing system, the network activity data into an identified threat category from among a plurality of threat categories; and taking action, by the computing system and based on the identified threat category, to mitigate a security threat posed by the network activity data.