Patent · US Active

Rating network security posture and comparing network maliciousness

US10038703B2 · kind B2 · utility

18Cited by
1References
21Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 16, 2015
Grant dateJul 31, 2018
Priority date
Expiry dateApr 11, 2036

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L61/5007
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Embodiments are disclosed for profiling network-level malicious activity. Profiling embodiments include observing malicious activity, representing such activity in accordance with a set of representative features, capturing temporal evolution of this malicious behavior and its dynamics, and using this temporal evolution to reveal key risk related properties of these networks. Embodiments are further disclosed addressing the connectedness of various networks and similarity in network-level maliciousness. Embodiments directed to similarity analyses include focusing on the notion of similarity—a quantitative measure of the extent to which the dynamic evolutions of malicious activities from two networks are alike, and mapping this behavioral similarity to their similarity in certain spatial features, which includes their relative proximity to each other and may be used to help predict the future maliciousness of a particular network. The embodiments described may be applicable to various network aggregation levels.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.