发明授权
- 专利标题: Method of detecting anomalous behaviour in a computer network
- 专利标题(中): 检测计算机网络异常行为的方法
-
申请号: US11578866申请日: 2005-04-19
-
公开(公告)号: US08631464B2公开(公告)日: 2014-01-14
- 发明人: Omar Belakhdar , Pedro Bados , Boi Faltings
- 申请人: Omar Belakhdar , Pedro Bados , Boi Faltings
- 申请人地址: CH Lausanne
- 专利权人: Ecole Polytechnique Fédérale de Lausanne (EPFL)
- 当前专利权人: Ecole Polytechnique Fédérale de Lausanne (EPFL)
- 当前专利权人地址: CH Lausanne
- 代理机构: Faegre Baker Daniels LLP
- 优先权: EP04405242 20040420
- 国际申请: PCT/IB2005/001051 WO 20050419
- 国际公布: WO2005/104482 WO 20051103
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
Method of detecting anomalous behavior in a computer network comprising the steps of—monitoring network traffic flowing in a computer network system,—authenticating users to which network packets of the network traffic are associated,—extracting parameters associated to the network packets for each user, said parameters including at least the type (T) of network services,—forming symbols based on a combination of one or more of said parameters, and—modeling and analyzing individual user behavior based on sequences of occurrence of said symbols (S).
公开/授权文献
信息查询