Systems and methods for anomaly detection in patterns of monitored communications
First Claim
Patent Images
1. A system for detecting an anomalous communication transmitted over a communications network, the system comprising:
- a) an interface coupling the system with the communications network;
b) a system data store capable of storing data associated with communications transmitted over the communications network and information associated with one or more responses to be initiated if an anomaly is detected;
c) a system processor in communication with the interface and the data store, wherein the system processor comprises one or more processing elements and wherein the system processor executes;
i) a collection engine that;
1) receives a communication via the interface; and
2) generates data associated with the received communication by applying one or more tests to the received communication;
ii) an analysis engine that detects whether an anomaly exists with respect to the received communication based upon the data generated by the collection engine and data associated with previously received communications from the system data store; and
iii) an action engine that initiates a predetermined response from the system data store if an anomaly was detected by the analysis engine.
14 Assignments
0 Petitions
Accused Products
Abstract
The present invention is directed to systems and methods for enhancing electronic communication security. A communication transmitted over a communications network is received and tested by a collection engine to generate data associated with the received communication. An analysis engine analyzes the data generated by the collection engine along with data associated with previously received communications to whether an anomaly exists. If an anomaly exists with respect to the received communication, an action engine initiates a predetermined response.
189 Citations
47 Claims
-
1. A system for detecting an anomalous communication transmitted over a communications network, the system comprising:
-
a) an interface coupling the system with the communications network;
b) a system data store capable of storing data associated with communications transmitted over the communications network and information associated with one or more responses to be initiated if an anomaly is detected;
c) a system processor in communication with the interface and the data store, wherein the system processor comprises one or more processing elements and wherein the system processor executes;
i) a collection engine that;
1) receives a communication via the interface; and
2) generates data associated with the received communication by applying one or more tests to the received communication;
ii) an analysis engine that detects whether an anomaly exists with respect to the received communication based upon the data generated by the collection engine and data associated with previously received communications from the system data store; and
iii) an action engine that initiates a predetermined response from the system data store if an anomaly was detected by the analysis engine. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27)
-
-
28. A method for detecting an anomalous communication transmitted over a communication network, the method comprising the steps of:
-
a) receiving a communication transmitted over a communication network;
b) applying one or more tests to the received communication to generate data associated with the received communication;
c) acquiring data associated with one or more previously received communications;
d) detecting whether an anomaly exists with respect to the received communication based upon the generated data and acquired data; and
e) initiating a predetermined response if an anomaly was detected. - View Dependent Claims (29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40)
-
-
41. Computer readable storage media storing instructions that upon execution by a system processor cause the system processor to detect an anomalous communication transmitted over a communication network, the media having stored instruction that cause the system processor to perform the steps comprising of:
-
a) receiving a communication transmitted over a communication network;
b) applying one or more tests to the received communication to generate data associated with the received communication;
c) acquiring data associated with one or more previously received communications;
d) detecting whether an anomaly exists with respect to the received communication based upon the generated data and acquired data; and
e) initiating a predetermined response if an anomaly was detected. - View Dependent Claims (42, 43, 44, 45, 46)
-
-
47. A system for detecting an anomalous communication transmitted over a communications network, the system comprising:
-
a) storing means for storing data associated with communications transmitted over the communications network and information associated with one or more responses to be initiated if an anomaly is detected;
b) collection means for receiving a communication transmitted over a communications network and for generating data associated with the received communication by applying one or more tests to the received communication;
c) analysis means for detecting whether an anomaly exists with respect to the received communication based upon the data generated by the collection means and data associated with previously received communications from the storing means; and
d) action means for initiating a predetermined response from the storing means if an anomaly was detected by the analysis means.
-
Specification