Patent · US Active

System for identifying anomalies in an information system

US10339309B1 · kind B1 · utility

77Cited by
39References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJun 9, 2017
Grant dateJul 2, 2019
Priority date
Expiry dateJan 10, 2038

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/2145
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

A system for identifying anomalies in an information system is typically configured for: collecting information regarding a hierarchy of capabilities, a hierarchy of resources, capability instances, and resource instances of the information system; storing, in a graph database, nodes corresponding to the hierarchy of capabilities, hierarchy of resources, capability instances, and resource instances; collecting information regarding relationships among the hierarchy of capabilities, hierarchy of resources, capability instances, and resource instances; defining, in the graph database, edges corresponding to the relationships among the hierarchy of capabilities, hierarchy of resources, capability instances, and resource instances; collecting event and/or state data for the information system; comparing the event and/or state data to the graph database and determining that an event and/or state is anomalous; and, in response to determining that the event and/or state is anomalous, taking an information security action.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.