Patent · US Active

Anomaly sensor framework for detecting advanced persistent threat attacks

US9378361B1 · kind B1 · utility

148Cited by
3References
27Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 31, 2012
Grant dateJun 28, 2016
Priority date
Expiry dateSep 2, 2033

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F21/562
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A threat detection system for detecting threat activity in a protected computer system includes anomaly sensors of distinct types including user-activity sensors, host-activity sensors and application-activity sensors. Each sensor builds a history of pertinent activity over a training period, and during a subsequent detection period the sensor compares current activity to the history to detect new activity. The new activity is identified in respective sensor output. A set of correlators of distinct types are used that correspond to different stages of threat activity according to modeled threat behavior. Each correlator receives output of one or more different-type sensors and applies logical and/or temporal testing to detect activity patterns of the different stages. The results of the logical and/or temporal testing are used to generate alert outputs for a human or machine user.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.