Characterizing behavior anomaly analysis performance based on threat intelligence

    公开(公告)号:US10728264B2

    公开(公告)日:2020-07-28

    申请号:US15433136

    申请日:2017-02-15

    Abstract: A technique includes receiving data identifying behavior anomalies that are exhibited by entities that are associated with a computer system. The technique includes associating the behavior anomalies with contexts based at least in part on threat intelligence to provide modified anomalies. The threat intelligence associates the contexts with indicators of potential breach. The technique includes characterizing the behavior anomaly identification based at least in part on the threat intelligence. The characterization includes applying machine learning to features of the modified anomalies to classify the identified behavior anomalies.

Patent Agency Ranking