- Patent Title: Graph-based attack chain discovery in enterprise security systems
-
Application No.: US15725974Application Date: 2017-10-05
-
Publication No.: US10289841B2Publication Date: 2019-05-14
- Inventor: LuAn Tang , Hengtong Zhang , Zhengzhang Chen , Bo Zong , Zhichun Li , Guofei Jiang , Kenji Yoshihira
- Applicant: NEC Laboratories America, Inc.
- Applicant Address: JP Tokyo
- Assignee: NEC Corporation
- Current Assignee: NEC Corporation
- Current Assignee Address: JP Tokyo
- Agent Joseph Kolodka
- Main IPC: G06F21/55
- IPC: G06F21/55 ; H04L12/24 ; H04L29/06 ; G06F21/57

Abstract:
Methods and systems for detecting anomalous events include detecting anomalous events in monitored system data. An event correlation graph is generated based on the monitored system data that characterizes the tendency of processes to access system targets. Kill chains are generated that connect malicious events over a span of time from the event correlation graph that characterize events in an attack path over time by sorting events according to a maliciousness value and determining at least one sub-graph within the event correlation graph with an above-threshold maliciousness rank. A security management action is performed based on the kill chains.
Public/Granted literature
- US20180032724A1 GRAPH-BASED ATTACK CHAIN DISCOVERY IN ENTERPRISE SECURITY SYSTEMS Public/Granted day:2018-02-01
Information query