×

Graph-based network anomaly detection across time and entities

  • US 10,609,059 B2
  • Filed: 12/13/2018
  • Issued: 03/31/2020
  • Est. Priority Date: 01/30/2017
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • accessing a relationship graph having entities as nodes, and relationships among the nodes as links, the relationship graph reflecting a batch of events that occurred during a time range;

    assigning the nodes in the relationship graph to groups based on event timestamps, each group including nodes associated with activities that occurred in a corresponding time unit;

    constructing links for nodes across different groups, wherein a link representing a relationship is established based on a respective activity recorded in the batch of events, each chain of linked nodes forming a component;

    computing a total interest score for the formed component, wherein the total interest score reflects a totality of interest generated from all nodes attached to a given link; and

    identifying a component for further security scrutiny based on the total interest score.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×