Method and system for detecting anomaly of user behavior in a network
    1.
    发明授权
    Method and system for detecting anomaly of user behavior in a network 有权
    用于检测网络中用户行为异常的方法和系统

    公开(公告)号:US09203857B2

    公开(公告)日:2015-12-01

    申请号:US14342150

    申请日:2012-08-10

    IPC分类号: G06F11/00 H04L29/06

    摘要: A method and system for detecting anomaly of user behavior in a network with a hierarchical topology, including a plurality of users, at least two bridges to each of which at least one user is connected to and wherein the bridges are configured to be operable to connect the corresponding users to the network, and at least one predetermined profiling network entity, the method includes the steps of: a) determining common behaviors of the users connected to the respective bridges; b) transmitting the determined common behaviors to the profiling network entity; c) determining an overall profile based on the transmitted common behaviors; d) transmitting back the determined overall profile to the bridges; and e) detecting anomaly of user behavior of the users connected to the corresponding bridges based on the overall profile.

    摘要翻译: 一种用于检测包括多个用户的分层拓扑的网络中的用户行为异常的方法和系统,至少两个桥,每个至少一个用户被连接到其上,并且其中所述网桥被配置为可操作以连接 相应的用户到网络,以及至少一个预定的分析网络实体,该方法包括以下步骤:a)确定连接到相应网桥的用户的共同行为; b)将确定的共同行为发送到分析网络实体; c)基于所发送的共同行为确定总体简档; d)将确定的总体轮廓传回桥梁; 以及e)基于总体简档检测连接到相应网桥的用户的用户行为异常。

    METHOD AND SYSTEM FOR DETECTING ANOMALY OF USER BEHAVIOR IN A NETWORK
    2.
    发明申请
    METHOD AND SYSTEM FOR DETECTING ANOMALY OF USER BEHAVIOR IN A NETWORK 有权
    用于检测网络中用户行为异常的方法和系统

    公开(公告)号:US20140215612A1

    公开(公告)日:2014-07-31

    申请号:US14342150

    申请日:2012-08-10

    IPC分类号: H04L29/06

    摘要: A method and system for detecting anomaly of user behavior in a network with a hierarchical topology, including a plurality of users, at least two bridges to each of which at least one user is connected to and wherein the bridges are configured to be operable to connect the corresponding users to the network, and at least one predetermined profiling network entity, the method includes the steps of: a) determining common behaviors of the users connected to the respective bridges; b) transmitting the determined common behaviors to the profiling network entity; c) determining an overall profile based on the transmitted common behaviors; d) transmitting back the determined overall profile to the bridges; and e) detecting anomaly of user behavior of the users connected to the corresponding bridges based on the overall profile.

    摘要翻译: 一种用于检测包括多个用户的分层拓扑的网络中的用户行为异常的方法和系统,至少两个桥,每个至少一个用户被连接到其上,并且其中所述网桥被配置为可操作以连接 相应的用户到网络,以及至少一个预定的分析网络实体,该方法包括以下步骤:a)确定连接到相应网桥的用户的共同行为; b)将确定的共同行为发送到分析网络实体; c)基于所发送的共同行为确定总体简档; d)将确定的总体轮廓传回桥梁; 以及e)基于总体简档检测连接到相应网桥的用户的用户行为异常。

    Method for determining if an encrypted flow of packets belongs to a predefined class of flows
    4.
    发明授权
    Method for determining if an encrypted flow of packets belongs to a predefined class of flows 有权
    用于确定加密的分组流是否属于预定类别的流的方法

    公开(公告)号:US07852775B2

    公开(公告)日:2010-12-14

    申请号:US12369248

    申请日:2009-02-11

    IPC分类号: H04L12/26

    摘要: A method to determine if an encrypted flow of packets (F) belongs to a predefined class of flows (ωt), comprises the steps of giving probability density functions (p(xi|ωt)) of the values of two measurable variables in a plurality of encrypted flows of packets (Fj) belonging to the predefined class of flows (ωt), measuring the values (si,Δt1) of the two measurable variables, apply the measured values (si,Δt1) to the probability density functions (p(xi|ωt)) to generate a sequence of values of probability density (p({right arrow over (x)}|ωt)), process the sequence of values of probability density (p({right arrow over (x)}|ωt)) to generate a reference value (S({right arrow over (x)}|ωt)), and compare such reference value (S({right arrow over (x)}|ωt)) to a threshold value (T) to determine whether the encrypted flow of packets (F) belongs to the predefined class of flows.

    摘要翻译: 一种确定分组(F)的加密流程是否属于预定类别的流(ωt)的方法包括以下步骤:给出多个可测量变量中的两个可测量变量的值的概率密度函数(p(xi |ωt)) 测量两个可测量变量的值(si,&Dgr; t1)的属于预定类别流(ωt)的加密数据包流(Fj),将测量值(si,&Dgr; t1)应用于概率密度 函数(p(xi |ωt)),以生成概率密度值(p({right arrow over(x)} |ωt))的序列序列),处理概率密度值序列(p({ x)} |ωt))以产生参考值(S({右箭头over(x)} |ωt)),并将这样的参考值(S({right} over(x)} |ωt) 阈值(T)以确定分组(F)的加密流程是否属于预定类别的流。

    Method for Determining if an Encrypted Flow of Packets Belongs to a Predefined Class of Flows
    6.
    发明申请
    Method for Determining if an Encrypted Flow of Packets Belongs to a Predefined Class of Flows 有权
    确定分组的加密流是否属于预定义流类别的方法

    公开(公告)号:US20090207740A1

    公开(公告)日:2009-08-20

    申请号:US12369248

    申请日:2009-02-11

    IPC分类号: H04L12/26

    摘要: A method to determine if an encrypted flow of packets (F) belongs to a predefined class of flows (ωt), comprises the steps of giving probability density functions (p(xi|ωt)) of the values of two measurable variables in a plurality of encrypted flows of packets (Fj) belonging to the predefined class of flows (ωt), measuring the values (si,Δt1) of the two measurable variables, apply the measured values (si,Δt1) to the probability density functions (p(xi|ωt)) to generate a sequence of values of probability density (p({right arrow over (x)}|ωt)), process the sequence of values of probability density (p({right arrow over (x)}|ωt)) to generate a reference value (S({right arrow over (x)}|ωt)), and compare such reference value (S({right arrow over (x)}|ωt)) to a threshold value (T) to determine whether the encrypted flow of packets (F) belongs to the predefined class of flows.

    摘要翻译: 一种确定分组(F)的加密流程是否属于预定类别流(omegat)的方法,包括以下步骤:给出多个可测量变量中的两个可测量变量的值的概率密度函数(p(xi | omegat)) 属于预定类别流(omegat)的加密数据包流(Fj),测量两个可测量变量的值(si,Deltat1),将测量值(si,Deltat1)应用于概率密度函数(p( 生成概率密度值(p({right} over(x)} | omegat)的序列),处理概率密度值序列(p({right arrow over(x)} | xi | omegat)) (S({right} over(x)} | omegat))与阈值(T(ω))相比较,生成参考值(S({right arrow over(x)} | omegat) )来确定分组(F)的加密流程是否属于预定类别的流。