Patent · US Active

Intrusion detection using MDL clustering

US9106689B2 · kind B2 · utility

6Cited by
18References
24Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMay 6, 2011
Grant dateAug 11, 2015
Priority date
Expiry dateJun 11, 2032

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1408
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

An intrusion detection method, system and computer-readable media are disclosed. The system can include a processor programmed to perform computer network intrusion detection. The intrusion detection can include an identification module and a detection module. The identification module can be adapted to perform semi-supervised machine learning to identify key components of a network attack and develop MDL models representing those attack components. The detection module can cluster the MDL models and use the clustered MDL models to classify network activity and detect polymorphic or zero-day attacks.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.