The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 26, 2019

Filed:

Nov. 10, 2017
Applicant:

Triad National Security, Llc, Los Alamos, NM (US);

Inventors:

Joshua Charles Neil, Jemez Springs, NM (US);

Michael Edward Fisk, Los Alamos, NM (US);

Alexander William Brugh, Los Alamos, NM (US);

Curtis Lee Hash, Jr., Santa Fe, NM (US);

Curtis Byron Storlie, Jemez Springs, NM (US);

Benjamin Uphoff, Los Alamos, NM (US);

Alexander Kent, Los Alamos, NM (US);

Assignee:

Triad National Security, LLC, Los Alamos, NM (US);

Attorneys:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 29/00 (2006.01); H04L 29/06 (2006.01); H04L 1/00 (2006.01); G06N 5/02 (2006.01); G06N 7/00 (2006.01); G06F 21/57 (2013.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06N 5/02 (2013.01); G06N 7/005 (2013.01); H04L 1/002 (2013.01); H04L 63/1408 (2013.01); H04L 63/1416 (2013.01); H04L 63/1433 (2013.01); G06F 21/577 (2013.01); H04L 2463/144 (2013.01);
Abstract

A system, apparatus, computer-readable medium, and computer-implemented method are provided for detecting anomalous behavior in a network. Historical parameters of the network are determined in order to determine normal activity levels. A plurality of paths in the network are enumerated as part of a graph representing the network, where each computing system in the network may be a node in the graph and the sequence of connections between two computing systems may be a directed edge in the graph. A statistical model is applied to the plurality of paths in the graph on a sliding window basis to detect anomalous behavior. Data collected by a Unified Host Collection Agent ('UHCA') may also be used to detect anomalous behavior.


Find Patent Forward Citations

Loading…