Please download the dossier by clicking on the dossier button x
×

Relating to the monitoring of network security

  • US 10,681,059 B2
  • Filed: 05/25/2016
  • Issued: 06/09/2020
  • Est. Priority Date: 05/25/2016
  • Status: Active Grant
First Claim
Patent Images

1. A method of monitoring a network and its nodes for security threats, the method comprising:

  • monitoring the activity of a plurality of network nodes by measuring parameters and/or actions associated with each network node;

    calculating a plurality of node scores for each of the network nodes based upon the measured parameters and/or actions;

    comparing the calculated one or more node scores against a reference activity, the reference activity including both ofa peer node score indicative of the monitored activity of a peer node having a similar type as the respective network node, anda network node score indicative of the monitored activity of a network node having a historically similar activity profile as the respective network node;

    calculating a node suspicion score representing the likelihood of suspicious activity for the one or more network nodes based upon the comparison, wherein the node suspicion score for a particular network node includes a weighted sum ofa) a peer anomaly score representing a difference between a cumulative peer node score for an individual network node over time and a mean of cumulative peer node scores for all of the network nodes, the difference then divided by a standard deviation of the cumulative peer node scores for all of the network nodes, andb) a discord anomaly score representing a difference between an average of the network node scores for the individual network node over time and a mean of the average network node scores for all of the network nodes, the difference then divided by a standard deviation of the average network node scores for all of the network nodes; and

    applying a Grubbs test to determine whether the node suspicion score is a statistical outlier.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×