Invention Grant
- Patent Title: Graph-based fusing of heterogeneous alerts
-
Application No.: US15477603Application Date: 2017-04-03
-
Publication No.: US10476749B2Publication Date: 2019-11-12
- Inventor: Kenji Yoshihira , Zhichun Li , Zhengzhang Chen , Haifeng Chen , Guofei Jiang , LuAn Tang
- Applicant: nec laboratories america, inc.
- Applicant Address: JP
- Assignee: NEC Corporation
- Current Assignee: NEC Corporation
- Current Assignee Address: JP
- Agent Joseph Kolodka
- Main IPC: H04L12/24
- IPC: H04L12/24 ; H04L29/06 ; G06F21/55

Abstract:
Methods and systems for reporting anomalous events include intra-host clustering a set of alerts based on a process graph that models states of process-level events in a network. Hidden relationship clustering is performed on the intra-host clustered alerts based on hidden relationships between alerts in respective clusters. Inter-host clustering is performed on the hidden relationship clustered alerts based on a topology graph that models source and destination relationships between connection events in the network. Inter-host clustered alerts that exceed a threshold level of trustworthiness are reported.
Public/Granted literature
- US20170288974A1 GRAPH-BASED FUSING OF HETEROGENEOUS ALERTS Public/Granted day:2017-10-05
Information query