-
公开(公告)号:US11729207B2
公开(公告)日:2023-08-15
申请号:US16900240
申请日:2020-06-12
Applicant: VMware, Inc.
Inventor: Zhen Mo , Vijay Ganti , Debessay Fesehaye Kassa , Barak Raz , Honglei Li
IPC: H04L9/40
CPC classification number: H04L63/1441 , H04L63/0236 , H04L63/1416 , H04L63/1425 , H04L63/20
Abstract: The disclosure provides an approach for detecting and preventing attacks in a network. Embodiments include determining a plurality of network behaviors of a process by monitoring the process. Embodiments include generating a plurality of intended states for the process based on subsets of the plurality of network behaviors. Embodiments include determining a plurality of intended state clusters by applying a clustering technique to the plurality of intended states. Embodiments include determining a state of the process. Embodiments include identifying a given cluster of the plurality of intended state clusters that corresponds to the state of the process. Embodiments include selecting a novelty detection technique based on a size of the given cluster. Embodiments include using the novelty detection technique to determine, based on the given cluster and the state of the process, whether to generate a security alert for the process.