-
公开(公告)号:US20220360596A1
公开(公告)日:2022-11-10
申请号:US17321847
申请日:2021-05-17
Applicant: Citrix Systems, Inc.
Inventor: Andreas Varnavas , Ananthaneni Sai Teja Chowdary , Nikolaos Tsapakis , Premkumar SJ , Manikam Muthiah
IPC: H04L29/06
Abstract: A system and method that detects malicious account creation in a web-based platform. A method includes detecting suspicious events associated with an account creation process using a username classifier that evaluates a username used to create a new account, an IP address classifier that evaluates an IP address used to create the new account, and a domain classifier that evaluates a domain from an email address used to create the new account; analyzing each detected suspicious event with a density analysis classifier to determine if each detected suspicious event comprises a malicious event based on a density of detected suspicious events from a collections of account creation processes; and determining an alert condition based on at least one malicious event detection.
-
公开(公告)号:US20210152571A1
公开(公告)日:2021-05-20
申请号:US16714240
申请日:2019-12-13
Applicant: Citrix Systems, Inc.
Inventor: Andreas Varnavas , Nikolaos Tsapakis
IPC: H04L29/06
Abstract: Systems and methods for identifying potential security incidents include an analytics engine that identifies a detection threshold for login failures according to a number of login successes to a system. The analytics engine may determine a number of login failures by a plurality of users to the system within a time window. The analytics engine may determine that the number of login failures to the system within the time window exceeds the detection threshold. The analytics engine may provide a notification to a device indicating a potential security incident responsive to the number of login failures exceeding the detection threshold.
-
公开(公告)号:US12225021B2
公开(公告)日:2025-02-11
申请号:US17321847
申请日:2021-05-17
Applicant: Citrix Systems, Inc.
Inventor: Andreas Varnavas , Ananthaneni Sai Teja Chowdary , Nikolaos Tsapakis , Premkumar S J , Manikam Muthiah
Abstract: A system and method that detects malicious account creation in a web-based platform. A method includes detecting suspicious events associated with an account creation process using a username classifier that evaluates a username used to create a new account, an IP address classifier that evaluates an IP address used to create the new account, and a domain classifier that evaluates a domain from an email address used to create the new account; analyzing each detected suspicious event with a density analysis classifier to determine if each detected suspicious event comprises a malicious event based on a density of detected suspicious events from a collections of account creation processes; and determining an alert condition based on at least one malicious event detection.
-
公开(公告)号:US20240005001A1
公开(公告)日:2024-01-04
申请号:US17868378
申请日:2022-07-19
Applicant: CITRIX SYSTEMS, INC.
Inventor: Andreas Varnavas , Georgios Papaloukopoulos , Asterios Stergioudis , Dimitrios Markonis , Nikolaos Tsapakis , Georgios Tsolis
CPC classification number: G06F21/566 , G06N7/005
Abstract: A computer system is provided. The computer system includes a memory and at least one processor coupled to the memory and configured to detect triggering of one or more threat detectors. The at least one processor is further configured to activate a subset of nodes from a plurality of nodes in a Bayesian network in response to the detection, the activated subset of nodes associated with the triggered threat detectors. The at least one processor is further configured to calculate a probability of malicious action using the Bayesian network to combine probabilities associated with the activated subset of nodes. The at least one processor is further configured to determine that the probability exceeds a threshold value. The at least one processor is further configured to perform a security action in response to the determination.
-
-
-