Invention Grant
- Patent Title: Systems and methods for detection of anomalous network behavior
- Patent Title (中): 用于检测异常网络行为的系统和方法
-
Application No.: US14540289Application Date: 2014-11-13
-
Publication No.: US09565203B2Publication Date: 2017-02-07
- Inventor: Ruth Bernstein , Andrey Dulkin
- Applicant: Cyber-Ark Software Ltd.
- Applicant Address: IL Petach-Tikva
- Assignee: Cyber-Ark Software Ltd.
- Current Assignee: Cyber-Ark Software Ltd.
- Current Assignee Address: IL Petach-Tikva
- Main IPC: G06F21/56
- IPC: G06F21/56 ; H04L29/06

Abstract:
There is provided a computer implemented method for detecting anomalous behavior in a network, comprising: receiving data representing at least one network activity, each network activity representing a certain data access event involving certain network entities; extracting from the data the certain network entities involved in the respective network activity; retrieving at least one relevant diversity value from a network behavior model based on the extracted certain network entities, wherein the network behavior model includes at least one diversity value, wherein each respective diversity value represents a certain relationship between at least one network entity and at least one network entity type; calculating an abnormality score for the received network activity based on the retrieved relevant diversity values; and classifying the network activity as anomalous or normal based on the calculated abnormality score.
Public/Granted literature
- US20160142435A1 SYSTEMS AND METHODS FOR DETECTION OF ANOMALOUS NETWORK BEHAVIOR Public/Granted day:2016-05-19
Information query