- 专利标题: System and methods for malware detection using log analytics for channels and super channels
-
申请号: US17661511申请日: 2022-04-29
-
公开(公告)号: US11785035B2公开(公告)日: 2023-10-10
- 发明人: Amnon Lotem , Doron Peri , Aviv Raff
- 申请人: RADWARE LTD.
- 申请人地址: IL Tel Aviv
- 专利权人: RADWARE LTD.
- 当前专利权人: RADWARE LTD.
- 当前专利权人地址: IL Tel Aviv
- 代理机构: M&B IP Analysts, LLC
- 主分类号: H04L9/40
- IPC分类号: H04L9/40 ; H04W12/67
摘要:
A method for operating at least one log-analytics detection platform for detecting security threats associated with a client network, comprising: obtaining, via a communication network, log files from a client network, each log file comprising a log record associated with a channel and including an outbound communications log; extracting a channel feature set for said channels from said log files, said channel feature set comprises data pertaining to an associated entity, at least one channel feature being behavior of communication over a channel; aggregating said channel associated features for each of the channels into a data repository; generating a risk factor characterized by an entity score for said least one entity associated with entities of said channels; and blocking of communication for said entity when said risk factory is indicative of said entity being a security threat.
公开/授权文献
信息查询