Security threat detection based on network flow analysis
US11991187B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Apr 1, 2021 |
| Grant date | May 21, 2024 |
| Priority date | — |
| Expiry date | Oct 5, 2041 |
Classification
- Technology area (CPC H)Electricity
- CPC primaryH04L63/1425
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
Some embodiments provide a method for identifying security threats to a datacenter. From multiple host computers in the datacenter, the method receives attribute sets for multiple flows. Each respective attribute set for a respective flow includes at least (i) a source identifier for the respective flow and (ii) an indicator as to whether the respective flow is indicative of the source of the respective flow being a security threat. For each of multiple source identifiers, the method aggregates the received attribute sets to generate an aggregate attribute set for the source identifier that includes a combined measurement of security threat indicators. For a particular source identifier, the method adjusts a security threat likelihood score for the source corresponding to the particular source identifier based on the combined measurement of security threat indicators for the source identifier.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.