×

Method and system for adaptive anomaly-based intrusion detection

  • US 8,800,036 B2
  • Filed: 01/22/2010
  • Issued: 08/05/2014
  • Est. Priority Date: 01/22/2010
  • Status: Expired due to Fees
First Claim
Patent Images

1. A computer implemented method of intrusion detection in an enterprise network, the method comprising:

  • a) developing a prediction model to predict expected values of future anomaly scores from real time anomaly scores based on an output of an anomaly detection system derived from an input of network traffic pattern data of the enterprise network in real time under benign conditions;

    b) setting an adaptive classification threshold based on the expected values predicted by the prediction model; and

    c) classifying unknown observations not within the adaptive classification threshold as possible intrusions;

    wherein the expected values of future anomaly scores ({circumflex over (r)}(n+1)) are calculated from the equation;

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×