×

Methods and apparatus to identify malicious activity in a network

  • US 9,503,465 B2
  • Filed: 11/14/2013
  • Issued: 11/22/2016
  • Est. Priority Date: 11/14/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • generating, with a processor, a set of statistical features based on communications between a plurality of network devices including a set of suspect devices classified as being associated with malicious activity and a set of unclassified devices;

    iteratively adjusting, with the processor and for a first number of iterations, a set of weights of a distance function representing differences between vectors of statistical features for different devices, the weights corresponding to the statistical features, the set of weights to be adjusted at each iteration based on a calculated gradient and step size to (1) reduce a first distance calculated between a first suspect device of the set of suspect devices and a second suspect device of the set of suspect devices and (2) increase a second distance calculated between the first suspect device and a first unclassified device of the set of unclassified devices; and

    in response to determining a first statistical feature of the set of statistical features is indicative of malicious activity based on a corresponding first weight, sending information identifying the first statistical feature of the set of statistical features to a network monitor that is to determine whether any of the unclassified devices are associated with malicious activity.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×