×

Methods, systems, and computer program products for detecting communication anomalies in a network based on overlap between sets of users communicating with entities in the network

  • US 9,641,545 B2
  • Filed: 10/26/2015
  • Issued: 05/02/2017
  • Est. Priority Date: 03/04/2013
  • Status: Active Grant
First Claim
Patent Images

1. A system, comprising:

  • a memory that stores instructions; and

    a processor that executes the instructions to perform operations, the operations comprising;

    determining an overlap between subsets of a set of users that entities of a plurality of entities communicated with, respectively, wherein the plurality of entities comprise domain names;

    identifying, based on the overlap and based on a similarity metric between pairs of the entities of the plurality of entities, a cluster of the entities of the plurality of entities; and

    determining whether communication between the cluster of the entities and the set of users is anomalous based on the overlap, wherein determining whether the communication between the cluster of the entities and the set of users is anomalous comprises;

    determining whether the communication associated with the cluster of the entities is anomalous based on a number of internet protocol addresses each of the domain names in the cluster of the entities resolves to over a time period; and

    determining whether the communication associated with the cluster of entities is anomalous based on a sequence in which users of the set of users communicate with the cluster of the entities.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×