Anomaly detection using endpoint counters
US11632382B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Jul 8, 2020 |
| Grant date | Apr 18, 2023 |
| Priority date | — |
| Expiry date | Oct 12, 2040 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L67/535
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
A system, method, and computer-readable medium are disclosed for performing a security operation. The security operation includes monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the monitoring comprising monitoring the plurality of electronically-observable actions via a protected endpoint; converting the plurality of electronically-observable actions of the entity to electronic information representing the plurality of actions of the entity; generating a representation of occurrences of a particular event from the plurality of events enacted by the entity; and performing an anomaly detection operation based upon the representation of occurrences of the particular event from the plurality of events enacted by the entity, the anomaly detection operation determining when the representation of occurrences of the particular event exceeds a predetermined threshold.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.