- 专利标题: Detecting network anomalies by probabilistic modeling of argument strings with markov chains
-
申请号: US14982888申请日: 2015-12-29
-
公开(公告)号: US10063576B2公开(公告)日: 2018-08-28
- 发明人: Yingbo Song , Angelos D. Keromytis , Salvatore J. Stolfo
- 申请人: The Trustees of Columbia University in the City of New York
- 申请人地址: US NY New York
- 专利权人: The Trustees of Columbia University in the City of New York
- 当前专利权人: The Trustees of Columbia University in the City of New York
- 当前专利权人地址: US NY New York
- 代理机构: Byrne Poh LLP
- 主分类号: G06F21/00
- IPC分类号: G06F21/00 ; H04L29/06 ; H04L29/08
摘要:
Systems, methods, and media for detecting network anomalies are provided. In some embodiments, a training dataset of communication protocol messages having argument strings is received. The content and structure associated with each of the argument strings is determined and a probabilistic model is trained using the determined content and structure of each of the argument strings. A communication protocol message having an argument string that is transmitted from a first processor to a second processor across a computer network is received. The received communication protocol message is compared to the probabilistic model and then it is determined whether the communication protocol message is anomalous.
公开/授权文献
信息查询