会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 2. 发明申请
    • PREDICTING ATTACKS BASED ON PROBABILISTIC GAME-THEORY
    • 基于概率游戏理论预测攻击
    • US20130318616A1
    • 2013-11-28
    • US13487774
    • 2012-06-04
    • Mihai ChristodorescuDmytro KorzhykReiner SailerDouglas L SchalesMarc Ph StoecklinTing Wang
    • Mihai ChristodorescuDmytro KorzhykReiner SailerDouglas L SchalesMarc Ph StoecklinTing Wang
    • G06F21/00
    • G06F21/00G06F21/552G06Q10/06375H04L63/1408H04L63/20
    • Systems for determining cyber-attack target include a network monitor module configured to collect network event information from sensors in one or more network nodes; a processor configured to extract information regarding an attacker from the network event information, to form an attack scenario tree that encodes network topology and vulnerability information including a plurality of paths from known compromised nodes to a set of potential targets, to calculate a likelihood for each of the paths, to calculate a probability distribution for the set of potential targets to determine which potential targets are most likely pursued by the attacker, to calculate a probability distribution over a set of nodes and node vulnerability types already accessed by the attacker, and to determine a network graph edge to remove that minimizes a defender's expected uncertainty over the potential targets; and a network management module configured to remove the determined network graph edge.
    • 用于确定网络攻击目标的系统包括被配置为从一个或多个网络节点中的传感器收集网络事件信息的网络监视器模块; 处理器,其被配置为从网络事件信息中提取关于攻击者的信息,以形成将网络拓扑和脆弱性信息编码的攻击场景树,所述攻击场景树包括从已知的受损节点到一组潜在目标的多个路径,以计算每个 的路径,以计算潜在目标集合的概率分布,以确定攻击者最有可能追查哪些潜在目标,以计算攻击者已经访问的一组节点和节点漏洞类型的概率分布,以及 确定一个网络图边缘去除,使防守者对潜在目标的预期不确定性最小化; 以及被配置为去除所确定的网络图边缘的网络管理模块。
    • 5. 发明授权
    • Methods, systems and computer program products for detecting flow-level network traffic anomalies via abstraction levels
    • 用于通过抽象级别检测流量级网络流量异常的方法,系统和计算机程序产品
    • US07962611B2
    • 2011-06-14
    • US12056583
    • 2008-03-27
    • Paul T. HurleyAndreas KindMarc Ph. Stoecklin
    • Paul T. HurleyAndreas KindMarc Ph. Stoecklin
    • G06F15/173
    • H04L43/026H04L41/142
    • Methods, systems and computer program products for detecting flow-level network traffic anomalies via abstraction levels. An exemplary embodiment includes a method for detecting flow-level network traffic anomalies in a computer network, the method including obtaining current distributions of flow level traffic features within the computer network, computing distances of the current distributions' components from a distributions model, comparing the distances of the current distributions to distance baselines from the distributions model, determining if the distances are above a pre-determined thresholds and in response to one or more of the distances being above the pre-determined thresholds in one or more distributions, identifying the current condition to be abnormal and providing indications to its nature.
    • 用于通过抽象级别检测流量级网络流量异常的方法,系统和计算机程序产品。 示例性实施例包括一种用于检测计算机网络中的流量级网络流量异常的方法,所述方法包括获得计算机网络内的流量级别业务特征的当前分布,从分布模型计算当前分布组件的距离, 当前分布与分布模型的距离基线的距离,确定距离是否高于预定阈值,并且响应于一个或多个距离在一个或多个分布中高于预定阈值,识别当前 情况异常,并提供适应症。