×

System for identifying illegitimate communications between computers by comparing evolution of data flows

  • US 9,847,924 B2
  • Filed: 04/02/2015
  • Issued: 12/19/2017
  • Est. Priority Date: 10/10/2012
  • Status: Active Grant
First Claim
Patent Images

1. A real-time method of identifying similar and coordinated communications between a plurality of computers connected by a network, the method comprising:

  • monitoring communications between a plurality of pairs of computers over the network to obtain a first flow metric for a first pair of computers and a second flow metric for a second pair of computers, wherein the first flow metric represents at least one property of a first data flow between the first pair of computers and the second flow metric represents at least one property of a second data flow between the second pair of computers;

    updating a representation of the evolution of the first data flow between the first pair of computers using the first flow metric or updating a representation of the evolution of the second data flow between the second pair of computers using the second flow metric;

    comparing the representation of the evolution of the first data flow and the representation of the evolution of the second data flow to determine the similarity of the first data flow and the second data flow; and

    identifying the first pair of computers and the second pair of computers as exhibiting similar and coordinated communication if the first data flow and second data flow are determined to be similar.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×