-
公开(公告)号:US10904270B2
公开(公告)日:2021-01-26
申请号:US14929187
申请日:2015-10-30
Applicant: Splunk Inc.
Inventor: Sudhakar Muddu , Christos Tryfonas , Ravi Prasad Bulusu , Marios Iliofotou
IPC: H04L9/00 , H04L29/06 , G06N20/00 , G06F16/25 , G06F16/28 , G06F16/44 , G06F16/901 , G06F16/2457 , H04L12/26 , G06F40/134 , G06N7/00 , G06F3/0482 , G06K9/20 , G06F3/0484 , H04L12/24 , G06N5/04 , G06N5/02
Abstract: A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
-
公开(公告)号:US10798113B2
公开(公告)日:2020-10-06
申请号:US16568106
申请日:2019-09-11
Applicant: Splunk Inc.
Inventor: Sudhakar Muddu , Christos Tryfonas
IPC: H04L29/06 , G06N20/00 , G06F16/25 , G06F16/28 , G06F16/44 , G06F16/901 , G06F16/2457 , H04L12/26 , G06N7/00 , G06F3/0482 , G06K9/20 , G06F3/0484 , H04L12/24 , G06F17/22 , G06N5/04 , G06N5/02 , G06F40/134
Abstract: A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
-
公开(公告)号:US10778703B2
公开(公告)日:2020-09-15
申请号:US16215350
申请日:2018-12-10
Applicant: SPLUNK INC.
Inventor: Sudhakar Muddu , Christos Tryfonas
IPC: H04L29/06 , G06N20/00 , G06N5/04 , G06F16/901 , G06F16/44 , G06F16/28 , G06F16/25 , H04L12/26 , G06F16/2457 , H04L12/24 , G06F3/0484 , G06K9/20 , G06F3/0482 , G06N5/02 , G06F40/134 , G06N7/00
Abstract: A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
-
公开(公告)号:US10666668B2
公开(公告)日:2020-05-26
申请号:US16259999
申请日:2019-01-28
Applicant: SPLUNK INC.
Inventor: Sudhakar Muddu , Christos Tryfonas
IPC: H04L29/06 , G06N20/00 , G06F16/25 , G06F16/28 , G06F16/44 , G06F16/901 , G06F16/2457 , H04L12/26 , G06F40/134 , G06N7/00 , G06F3/0482 , G06K9/20 , G06F3/0484 , H04L12/24 , G06N5/04 , G06N5/02
Abstract: A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
-
公开(公告)号:US10581881B2
公开(公告)日:2020-03-03
申请号:US15800000
申请日:2017-10-31
Applicant: Splunk Inc.
Inventor: Sudhakar Muddu , Christos Tryfonas , Sathyanarayanan Kavacheri
IPC: H04L29/06 , G06N20/00 , G06F16/25 , G06F16/28 , G06F16/44 , G06F16/901 , G06F16/2457 , H04L12/26 , G06N7/00 , G06F3/0482 , G06K9/20 , G06F3/0484 , H04L12/24 , G06F17/22 , G06N5/04 , G06N5/02
Abstract: A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
-
公开(公告)号:US10469508B2
公开(公告)日:2019-11-05
申请号:US14928471
申请日:2015-10-30
Applicant: Splunk Inc.
Inventor: Sudhakar Muddu , Christos Tryfonas
IPC: H04L29/06 , G06F17/30 , G06F3/0484 , G06K9/20 , G06N20/00 , G06F16/25 , G06F16/28 , G06F16/44 , G06F16/901 , G06F16/2457 , G06N7/00 , G06F3/0482 , H04L12/24 , H04L12/26 , G06F17/22 , G06N5/04 , G06N5/02
Abstract: A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
-
公开(公告)号:US10389738B2
公开(公告)日:2019-08-20
申请号:US14929183
申请日:2015-10-30
Applicant: Splunk Inc.
Inventor: Sudhakar Muddu , Christos Tryfonas , Joseph Auguste Zadeh , Alexander Beebe Bond , Ashwin Athalye
IPC: H04L9/00 , H04L29/06 , G06N20/00 , G06F16/25 , G06F16/28 , G06F16/44 , G06F16/901 , G06F16/2457 , G06N7/00 , G06F3/0482 , G06K9/20 , G06F3/0484 , H04L12/24 , H04L12/26 , G06F17/22 , G06N5/04
Abstract: A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
-
58.
公开(公告)号:US20190158517A1
公开(公告)日:2019-05-23
申请号:US16259999
申请日:2019-01-28
Applicant: SPLUNK INC.
Inventor: Sudhakar Muddu , Christos Tryfonas
IPC: H04L29/06 , G06N20/00 , G06N5/04 , G06F16/901 , G06F16/44 , G06F16/28 , G06F16/25 , H04L12/26 , G06F16/2457 , H04L12/24 , G06F3/0484 , G06K9/20 , G06F3/0482 , G06F17/22 , G06N7/00
Abstract: A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
-
59.
公开(公告)号:US20190075126A1
公开(公告)日:2019-03-07
申请号:US16182469
申请日:2018-11-06
Applicant: Splunk Inc.
Inventor: Sudhakar Muddu , Christos Tryfonas , Ravi Prasad Bulusu
IPC: H04L29/06 , G06N99/00 , G06F17/30 , H04L12/26 , H04L12/24 , G06F3/0484 , G06K9/20 , G06F3/0482 , G06N7/00 , G06N5/04 , G06F17/22
CPC classification number: H04L63/1416 , G06F3/0482 , G06F3/0484 , G06F3/04842 , G06F3/04847 , G06F16/24578 , G06F16/254 , G06F16/285 , G06F16/444 , G06F16/9024 , G06F17/2235 , G06K9/2063 , G06N5/022 , G06N5/04 , G06N7/005 , G06N20/00 , H04L41/0893 , H04L41/145 , H04L41/22 , H04L43/00 , H04L43/045 , H04L43/062 , H04L43/08 , H04L63/06 , H04L63/1408 , H04L63/1425 , H04L63/1433 , H04L63/1441 , H04L63/20 , H04L2463/121 , H05K999/99
Abstract: A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.
-
公开(公告)号:US20180367551A1
公开(公告)日:2018-12-20
申请号:US16050368
申请日:2018-07-31
Applicant: Splunk Inc.
Inventor: Sudhakar Muddu , Christos Tryfonas , Marios Iliofotou
IPC: H04L29/06 , G06N99/00 , G06F17/22 , H04L12/26 , G06F3/0482 , G06K9/20 , G06N7/00 , G06F17/30 , G06F3/0484 , H04L12/24 , G06N5/04
Abstract: The disclosed embodiments include a method performed by a computer system. The method includes forming groups of traffic, where each group includes a subset of detected connection requests. The method further includes determining a periodicity of connection requests for each group, identifying a particular group based on whether the periodicity of connection requests of the particular group satisfies a periodicity criterion, determining a frequency of the particular group in the traffic, and identifying the particular group as an anomaly based on whether the frequency of the particular group satisfies a frequency criterion.
-
-
-
-
-
-
-
-
-