Invention Grant
- Patent Title: Using new edges for anomaly detection in computer networks
- Patent Title (中): 在计算机网络中使用新的边缘进行异常检测
-
Application No.: US13826995Application Date: 2013-03-14
-
Publication No.: US09038180B2Publication Date: 2015-05-19
- Inventor: Joshua Charles Neil
- Applicant: Los Alamos National Security, LLC
- Applicant Address: US NM Los Alamos
- Assignee: Los Alamos National Security, LLC
- Current Assignee: Los Alamos National Security, LLC
- Current Assignee Address: US NM Los Alamos
- Agency: LeonardPatel PC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/57

Abstract:
Creation of new edges in a network may be used as an indication of a potential attack on the network. Historical data of a frequency with which nodes in a network create and receive new edges may be analyzed. Baseline models of behavior among the edges in the network may be established based on the analysis of the historical data. A new edge that deviates from a respective baseline model by more than a predetermined threshold during a time window may be detected. The new edge may be flagged as potentially anomalous when the deviation from the respective baseline model is detected. Probabilities for both new and existing edges may be obtained for all edges in a path or other subgraph. The probabilities may then be combined to obtain a score for the path or other subgraph. A threshold may be obtained by calculating an empirical distribution of the scores under historical conditions.
Public/Granted literature
- US20140068769A1 USING NEW EDGES FOR ANOMALY DETECTION IN COMPUTER NETWORKS Public/Granted day:2014-03-06
Information query