The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 16, 2019

Filed:

Jul. 01, 2016
Applicant:

Hewlett Packard Enterprise Development Lp, Houston, TX (US);

Inventors:

Philipp Reinecke, Bristol, GB;

Marco Casassa Mont, Bristol, GB;

Yolanta Beresna, Bristol, GB;

Assignee:

ENTIT SOFTWARE LLC, Sunnyvale, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 11/00 (2006.01); G06F 21/55 (2013.01); G06F 16/903 (2019.01); G06F 21/56 (2013.01); H04L 29/06 (2006.01); G06F 17/30 (2006.01); G06F 21/57 (2013.01); G06N 5/02 (2006.01); G06F 12/14 (2006.01);
U.S. Cl.
CPC ...
G06F 21/55 (2013.01); G06F 16/90335 (2019.01); G06F 17/30979 (2013.01); G06F 21/56 (2013.01); G06F 21/566 (2013.01); G06F 21/577 (2013.01); G06N 5/02 (2013.01); H04L 63/1408 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01); G06F 2221/034 (2013.01);
Abstract

Examples relate to model-based computer attack analytics orchestration. In one example, a computing device may: generate, using an attack model that specifies behavior of a particular attack on a computing system, a hypothesis for the particular attack, the hypothesis specifying, for a particular state of the particular attack, at least one attack action; identify, using the hypothesis, at least one analytics function for determining whether the at least one attack action specified by the hypothesis occurred on the computing system; provide an analytics device with instructions to execute the at least one analytics function on the computing system; receive analytics results from the analytics device; and update a state of the attack model based on the analytics results.


Find Patent Forward Citations

Loading…