-
公开(公告)号:US11757917B2
公开(公告)日:2023-09-12
申请号:US17078203
申请日:2020-10-23
Applicant: VMWARE, INC.
Inventor: Santosh Pallagatti Kotrabasappa , Sairam Veeraswamy , Jayneeta Sinha , Suriyan S.
IPC: H04L9/40 , H04L41/0604 , H04L41/0213 , G06F18/243
CPC classification number: H04L63/1433 , G06F18/24323 , H04L41/0213 , H04L41/0627 , H04L63/1425 , H04L63/1466
Abstract: The disclosure provides an approach for detecting and preventing attacks in a network. Embodiments include receiving network traffic statistics of a system. Embodiments include determining a set of features of the system based on the network traffic statistics. Embodiments include inputting the set of features to a classification model that has been trained using historical features associated with labels indicating whether the historical features correspond to attacks. Embodiments include receiving, as output from the classification model, an indication of whether the system is a target of an attack. Embodiments include receiving additional statistics related to the system. Embodiments include analyzing, in response to the indication that the system is the target of the attack, the additional statistics to identify a source of the attack. Embodiments include performing an action to prevent the attack based on the source of the attack.