Patent · US Active

Detection of anomalous computer behavior

US11321214B1 · kind B1 · utility

0Cited by
5References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateOct 12, 2020
Grant dateMay 3, 2022
Priority date
Expiry dateOct 12, 2040

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2463/121
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

A computer-implemented method for determining features of a dataset that are indicative of anomalous behavior of one or more computers in a large group of computers comprises (1) receiving log files including a plurality of entries of data regarding connections between a plurality of computers belonging to an organization and a plurality of websites outside the organization, each entry being associated with the actions of one computer, (2) executing a time series decomposition algorithm on a portion of the features of the data to generate a first list of features, (3) implementing a plurality of traffic dispersion graphs to generate a second list of features, and (4) implementing an autoencoder and a random forest regressor to generate a third list of features.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.