会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明申请
    • SYSTEMS AND METHODS FOR DETECTING AND RESPONDING TO SECURITY THREATS USING APPLICATION EXECUTION AND CONNECTION LINEAGE TRACING
    • 使用应用执行和连接线追踪检测和应对安全威胁的系统和方法
    • WO2017100364A1
    • 2017-06-15
    • PCT/US2016/065450
    • 2016-12-07
    • PRISMO SYSTEMS INC.
    • VENKATRAMANI, AnjanCHAO, Chihwei
    • G06F3/048G06F12/14H04J1/16
    • H04L63/1416H04L63/0272H04L63/1425H04L63/20
    • Systems and methods for detecting and responding to security threats using application execution and connection lineage tracing in accordance with embodiments of the invention are disclosed-. In one embodiment, a process for detecting suspicious activity in a network and in a computer server system includes receiving at a collector server a first piece of activity data including a first set of attributes, each attribute having a particular value, combining a first set of context information with the first piece of activity data to generate a first activity record, comparing the first activity record to a set of baseline signatures, where each baseline signature includes a second set of attributes, each attribute having a particular value and each baseline signature being unique in the combination of values of its attributes, and incrementing a count of a first matching baseline signature from the set of baseline signatures.
    • 公开了使用根据本发明实施例的应用执行和连接沿袭跟踪来检测和响应安全威胁的系统和方法。 在一个实施例中,用于检测网络中和计算机服务器系统中的可疑活动的过程包括在收集器服务器处接收包括第一组属性的第一活动数据,每个属性具有特定值,组合第一组 上下文信息与第一活动数据一起生成第一活动记录,将第一活动记录与一组基准签名进行比较,其中每个基准签名包括第二组属性,每个属性具有特定值并且每个基准签名是 在其属性值的组合中是唯一的,并且增加来自该组基准签名的第一匹配基线签名的计数。