×

Window-based rarity determination using probabilistic suffix trees for network security analysis

  • US 10,560,468 B2
  • Filed: 07/20/2018
  • Issued: 02/11/2020
  • Est. Priority Date: 08/31/2015
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • receiving a sequence of event feature sets corresponding to a sequence of events, wherein the event feature sets are derived from raw event machine data recorded in a computer network;

    measuring an anomaly count within a target event window by processing the sequence of event feature sets through an event sequence prediction model to increase the anomaly count when the event sequence prediction model identifies an event feature set within the target event window as corresponding to an anomalous event, wherein the event sequence prediction model includes a probabilistic suffix tree (PST) based machine learning model;

    comparing a rarity score for the target event window against an established baseline distribution to determine a probability of encountering the event window with the rarity score; and

    upon determining that the probability of encountering the event window is below a threshold, identifying the target event window as containing a suspicious series of events by determining whether the anomaly count deviates from a baseline by a specified criterion; and

    generating a computer security threat indicator or a computer security anomaly indicator based on the identification of the suspicious series of events.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×