Patent · US Active

Identifying threats based on hierarchical classification

US9462008B2 · kind B2 · utility

6Cited by
2References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateOct 21, 2014
Grant dateOct 4, 2016
Priority date
Expiry dateNov 11, 2034

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L2463/142
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

A system and a method are disclosed for identifying network threats based on hierarchical classification. The system receives packet flows from a data network and determines flow features for the received packet flows based on data from the packet flows. The system also classifies each packet flow into a flow class based on flow features of the packet flow. Based on a criterion, the system selects packet flows from the received packet flows and places the selected packet flows into an event set that represents an event on the network. The system determines event set features for the event set based on the flow features of the selected packet flows. The system then classifies the event set into a set class based on the determined event set features. Based on the set class, the computer system may report a threat incident on an internetworking device that originated the selected packet flows.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.