×

SYSTEMS AND METHODS FOR DETECTION OF ANOMALOUS NETWORK BEHAVIOR

  • US 20160142435A1
  • Filed: 11/13/2014
  • Published: 05/19/2016
  • Est. Priority Date: 11/13/2014
  • Status: Active Grant
First Claim
Patent Images

1. A computer implemented method for detecting anomalous behavior in a network, comprising:

  • receiving data representing at least one network activity, each network activity representing a certain data access event occurring between certain network entities;

    extracting from said data representing each respective network activity, the certain network entities involved in the respective network activity;

    retrieving at least one relevant diversity value from a network behavior model based on said extracted certain network entities, wherein said network behavior model includes at least one diversity value, wherein each respective diversity value represents a certain relationship between at least one network entity and at least one network entity type;

    calculating an abnormality score for said received at least one network activity based on said retrieved at least one relevant diversity value;

    classifying said at least one network activity as anomalous or normal based on said calculated abnormality score; and

    generating an alert when said at least one network activity is classified as anomalous.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×