Blue print graphs for fusing of heterogeneous alerts
Abstract:
Methods and systems for reporting anomalous events include building a process graph that models states of process-level events in a network. A topology graph is built that models source and destination relationships between connection events in the network. A set of alerts is clustered based on the process graph and the topology graph. Clustered alerts that exceed a threshold level of trustworthiness are reported.
Public/Granted literature
Information query
Patent Agency Ranking
0/0