- 专利标题: Detection and identification of targeted attacks on a computing system
-
申请号: US15874983申请日: 2018-01-19
-
公开(公告)号: US10715545B2公开(公告)日: 2020-07-14
- 发明人: Philip K. Newman , Puhazholi Vetrivel , Sudhakar Narayanamurthy , Ejike E. Ofuonye , Suresh C. Palani , Ashish Mishra
- 申请人: Microsoft Technology Licensing, LLC
- 申请人地址: US WA Redmond
- 专利权人: Microsoft Technology Licensing, LLC
- 当前专利权人: Microsoft Technology Licensing, LLC
- 当前专利权人地址: US WA Redmond
- 代理机构: Kelly, Holt & Christenson, PLLC
- 代理商 Christopher J. Volkmann
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06F21/57 ; G06F21/56 ; G06F21/55
摘要:
Malicious activity data is obtained, that is indicative of attempted attacks on a computing system. Clusters of targets are identified and it is determined whether the malicious activity preferentially targets one cluster of targets over other. Also, low prevalence attacks are identified and it is determined whether a low prevalence attack has a high concentration in one or more of the target clusters. If the malicious activity either preferentially targets a cluster, or a low prevalence attack has a high concentration in a cluster, then the attack is identified as a targeted attack, so that remediation steps can be taken.
公开/授权文献
信息查询