Patent · US Active

Anomaly detection using endpoint counters

US11632382B2 · kind B2 · utility

0Cited by
11References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateJul 8, 2020
Grant dateApr 18, 2023
Priority date
Expiry dateOct 12, 2040

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L67/535
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A system, method, and computer-readable medium are disclosed for performing a security operation. The security operation includes monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the monitoring comprising monitoring the plurality of electronically-observable actions via a protected endpoint; converting the plurality of electronically-observable actions of the entity to electronic information representing the plurality of actions of the entity; generating a representation of occurrences of a particular event from the plurality of events enacted by the entity; and performing an anomaly detection operation based upon the representation of occurrences of the particular event from the plurality of events enacted by the entity, the anomaly detection operation determining when the representation of occurrences of the particular event exceeds a predetermined threshold.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.