Patent · US Active

Automatic selection of malicious activity detection rules using crowd-sourcing techniques

US10148673B1 · kind B1 · utility

1Cited by
16References
15Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 30, 2015
Grant dateDec 4, 2018
Priority date
Expiry dateAug 24, 2036

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1441
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Techniques of operating intrusion detection systems provide a recommendation of an intrusion detection rule to an administrator of an intrusion detection system based on the experience of another administrator that has used the rule in another intrusion detection system. For example, suppose that electronic circuitry receives a numerical rating from a first intrusion detection system that indicates whether an intrusion detection rule was effective in identifying malicious activity when used in the first intrusion detection system. Based on the received rating and attributes of the first intrusion detection system, the electronic circuitry generates a predicted numerical rating that indicates whether the intrusion detection rule is likely to be effective in identifying malicious communications when used in a second intrusion detection system. If the predicted numerical rating is sufficiently high, then the electronic circuitry transmits a message to the second intrusion detection system recommending the intrusion detection rule for use in the second intrusion detection system.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.