×

Prioritizing Bayes network alerts

  • US 7,379,993 B2
  • Filed: 09/13/2001
  • Issued: 05/27/2008
  • Est. Priority Date: 09/13/2001
  • Status: Active Grant
First Claim
Patent Images

1. In a computer network having an information security device that generates alerts when attacks or anomalous incidents are detected, a method for prioritizing alerts comprising the steps of:

  • receiving alerts from the information security device;

    examining the received alerts for the presence of one or more relevant features;

    providing a summary or list of the features from at least a subset of the received alerts to a Bayes network for analysis; and

    assigning priority scores to at least a subset of the received alerts, the priority scores reflecting an importance of an associated alert relative to other alerts and being based at least in part on the analysis performed by the Bayes network,where the Bayes network uses conditional probability tables (CPTs) to model potential influence of alert features on the priority scores, the CPTs including one or more rows that correspond to priority score states and one or more columns that correspond to alert feature states such that an element at an intersection of a row and a column of a CPT represents a likelihood of a priority score state given an alert feature state, where the CPTs are adjusted in response to a dominant priority score by adapting a first row of the CPT, the first row of the CPT corresponding to the dominant priority score, to increase a measure of likelihood of the dominant priority score across alert feature states represented in the first row, the adapting comprising;

    converting each element in the first row of the CPT to an effective count to produce one or more effective counts, an effective count indicating a number of times that the dominant priority score has been observed for a corresponding alert feature state, wherein the dominant priority score is added as an additional effective count distributed over the alert feature states represented in the first row;

    normalizing the first row of the CPT; and

    recomputing the one or more effective counts for all priority score states.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×