×

Method and apparatus for computer intrusion detection

  • US 9,679,131 B2
  • Filed: 03/14/2013
  • Issued: 06/13/2017
  • Est. Priority Date: 01/25/2013
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method performed by a computerized device having a processor, the method comprising:

  • receiving a description of a computerized system, the description comprising indication of at least two entities, at least one attribute for each of the at least two entities and at least one statistical rule related to relationships between the at least two entities;

    receiving data to be automatically analyzed related to monitored activity of the computerized system, the data comprising events containing at least an event related to an attack attempt and an event not related to an attack attempt;

    grouping the events into at least two groups associated with the at least two entities;

    classifying each entity by determining a probability of each entity being associated with the events within the data, and classifying the events based on when they occurred;

    aggregating each group into at least two objects based on the classifications;

    comparing the at least two objects to predetermined values which are based on at least one statistical rule, to identify a group from which an object was aggregated as not complying with the at least one statistical rule, wherein the non-compliance is not binary and degrees of non-compliance exist, wherein the non-compliant group may be identified as containing the event related to the attack attempt;

    displaying or otherwise treating a plurality of events related to an attack attempt in order of their degree of non-compliance, identified via the steps of receiving the description, receiving the data, grouping, classifying, aggregating and comparing; and

    wherein said receiving the description, receiving the data, groupings of classifying, comparing, and displaying or otherwise treating is performed by the processor.

View all claims
  • 6 Assignments
Timeline View
Assignment View
    ×
    ×