-
公开(公告)号:US10728264B2
公开(公告)日:2020-07-28
申请号:US15433136
申请日:2017-02-15
Applicant: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Inventor: Sandeep N. Bhatt , Pratyusa K. Manadhata , Tomas Sander
Abstract: A technique includes receiving data identifying behavior anomalies that are exhibited by entities that are associated with a computer system. The technique includes associating the behavior anomalies with contexts based at least in part on threat intelligence to provide modified anomalies. The threat intelligence associates the contexts with indicators of potential breach. The technique includes characterizing the behavior anomaly identification based at least in part on the threat intelligence. The characterization includes applying machine learning to features of the modified anomalies to classify the identified behavior anomalies.
-
公开(公告)号:US10686817B2
公开(公告)日:2020-06-16
申请号:US15754282
申请日:2015-09-21
Applicant: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Inventor: Prasad V. Rao , Sandeep N. Bhatt , William G. Horne , Pratyusa K. Manadhata , Miranda Jane Felicity Mowbray
Abstract: Examples determine a number of hosts, within an enterprise, which are resolving a particular domain. Based on the number of hosts within the enterprise resolving the particular domain, the examples identify whether the particular domain is benign.
-
公开(公告)号:US20180255083A1
公开(公告)日:2018-09-06
申请号:US15754282
申请日:2015-09-21
Applicant: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Inventor: Prasad V. Rao , Sandeep N. Bhatt , William G. Home , Pratyusa K. Manadhata , Miranda Jane Felicity Mowbray
CPC classification number: H04L63/1425 , H04L61/1511 , H04L61/3015 , H04L63/0236 , H04L63/1416 , H04L63/1441
Abstract: Examples determine a number of hosts, within an enterprise, which are resolving a particular domain. Based on the number of hosts within the enterprise resolving the particular domain, the examples identify whether the particular domain is benign.
-
公开(公告)号:US20180234445A1
公开(公告)日:2018-08-16
申请号:US15433136
申请日:2017-02-15
Applicant: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Inventor: Sandeep N. Bhatt , Pratyusa K. Manadhata , Tomas Sander
Abstract: A technique includes receiving data identifying behavior anomalies that are exhibited by entities that are associated with a computer system. The technique includes associating the behavior anomalies with contexts based at least in part on threat intelligence to provide modified anomalies. The threat intelligence associates the contexts with indicators of potential breach. The technique includes characterizing the behavior anomaly identification based at least in part on the threat intelligence. The characterization includes applying machine learning to features of the modified anomalies to classify the identified behavior anomalies.
-
-
-