Invention Grant
- Patent Title: Modeling and outlier detection in threat management system data
- Patent Title (中): 威胁管理系统数据中的建模和异常值检测
-
Application No.: US13116613Application Date: 2011-05-26
-
Publication No.: US08528088B2Publication Date: 2013-09-03
- Inventor: Jeremy Wright , John Hogoboom , Chaim Spielman
- Applicant: Jeremy Wright , John Hogoboom , Chaim Spielman
- Applicant Address: US GA Atlanta
- Assignee: AT&T Intellectual Property I, L.P.
- Current Assignee: AT&T Intellectual Property I, L.P.
- Current Assignee Address: US GA Atlanta
- Agency: Hartman & Citrin LLC
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Methods, systems, and computer-readable media for identifying potential threats on a network based on anomalous behavior in communication between endpoints are provided. Traffic data for a network is accumulated over some period of time. The traffic data is grouped by one or more keys, such as source IP address, and sets of metric values are calculated for the keys. A mixture distribution, such as a negative binomial mixture distribution, is fitted to each set of metric values, and outlying metric values are determined based on the mixture distribution(s). A list of outliers is then generated comprising key values having outlying metric values in one or more of the sets of metric values.
Public/Granted literature
- US20120304288A1 Modeling and Outlier Detection in Threat Management System Data Public/Granted day:2012-11-29
Information query