×

Anomaly alert system for cyber threat detection

  • US 10,701,093 B2
  • Filed: 02/06/2017
  • Issued: 06/30/2020
  • Est. Priority Date: 02/09/2016
  • Status: Active Grant
First Claim
Patent Images

1. A method for an anomalous behavior detection system having a mathematical model of what is considered to be normal behavior for a device in a computer system that is used in a detection of anomalous behavior of the device of the computer system, the method arranged to be performed by a processing system, the method comprising:

  • deriving values, m1, . . . , mN, of a metric, M, representative of data associated with the device;

    modelling a distribution of the values of the metric;

    determining, in accordance with the distribution of the values of the metric, a probability of observing a more extreme value of the metric than a given value, m, of the metric, wherein the probability and the distribution of the values of the metric are used by the mathematical model of what is considered to be normal behavior for that device to determine whether the device is behaving anomalously;

    determining, in accordance with the probability of observing the more extreme value, and a probabilistic model of the device, a posterior probability of the given value, m, being a result of anomalous behavior of the device, wherein the posterior probability is used to determine whether the device is behaving anomalously;

    determining posterior probabilities for a plurality of given values, mi, of a plurality of metrics, Mi, wherein the metrics, Mi, are representative of data associated with the device, where levels of anomalousness of values of the plurality of metrics for the device are combined to produce a measure of an overall posterior probability of the device being in an anomalous state; and

    in accordance with the posterior probabilities for the given values, mi, determining an overall posterior probability of the device being in the anomalous state, wherein the overall posterior probability is used to determine whether the device is behaving anomalously;

    wherein a combined posterior probability that the device is in an anomalous state, Pd(A), is given by

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×