Invention Grant
- Patent Title: Graph-based intrusion detection using process traces
-
Application No.: US15213896Application Date: 2016-07-19
-
Publication No.: US10305917B2Publication Date: 2019-05-28
- Inventor: Zhengzhang Chen , LuAn Tang , Boxiang Dong , Guofei Jiang , Haifeng Chen
- Applicant: NEC Laboratories America, Inc.
- Applicant Address: JP
- Assignee: NEC Corporation
- Current Assignee: NEC Corporation
- Current Assignee Address: JP
- Agent Joseph Kolodka
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/55 ; H04L12/24

Abstract:
Methods and systems for detecting malicious processes include modeling system data as a graph comprising vertices that represent system entities and edges that represent events between respective system entities. Each edge has one or more timestamps corresponding respective events between two system entities. A set of valid path patterns that relate to potential attacks is generated. One or more event sequences in the system are determined to be suspicious based on the graph and the valid path patterns using a random walk on the graph.
Public/Granted literature
- US20160330226A1 Graph-based Instrusion Detection Using Process Traces Public/Granted day:2016-11-10
Information query