Invention Grant
US09432393B2 Global clustering of incidents based on malware similarity and online trustfulness
有权
基于恶意软件相似性和在线信任度的事件全局聚类
- Patent Title: Global clustering of incidents based on malware similarity and online trustfulness
- Patent Title (中): 基于恶意软件相似性和在线信任度的事件全局聚类
-
Application No.: US14612623Application Date: 2015-02-03
-
Publication No.: US09432393B2Publication Date: 2016-08-30
- Inventor: Karel Bartos , Martin Rehak , Michal Sofka
- Applicant: Cisco Technology, Inc.
- Applicant Address: US CA San Jose
- Assignee: Cisco Technology, Inc.
- Current Assignee: Cisco Technology, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Hickman Palermo Becker Bingham LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; H04L29/06 ; G06F21/56

Abstract:
In an embodiment, a method, performed by processors of a computing device for creating and storing clusters of incident data records based on behavioral characteristic values in the records and origin characteristic values in the records, the method comprising: receiving a plurality of input incident data records comprising sets of attribute values; identifying two or more first incident data records that have a particular behavioral characteristic value; using a malicious incident behavioral data table that maps sets of behavioral characteristic values to identifiers of malicious acts in the network, and a plurality of comparison operations using the malicious incident behavioral data table and the two or more first incident data records, determining whether any of the two or more first incident data records are malicious; and if so, creating a similarity behavioral cluster record that includes the two or more first incident data records.
Public/Granted literature
- US20160226904A1 GLOBAL CLUSTERING OF INCIDENTS BASED ON MALWARE SIMILARITY AND ONLINE TRUSTFULNESS Public/Granted day:2016-08-04
Information query