The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Sep. 10, 2019

Filed:

Dec. 30, 2016
Applicants:

Dustin Lundring Rigg Hillard, Seattle, WA (US);

Art Munson, Seattle, WA (US);

Lawrence Cayton, Seattle, WA (US);

Scott Golder, Seattle, WA (US);

Inventors:

Dustin Lundring Rigg Hillard, Seattle, WA (US);

Art Munson, Seattle, WA (US);

Lawrence Cayton, Seattle, WA (US);

Scott Golder, Seattle, WA (US);

Assignee:

eSentire, Inc., Cambridge, Ontario, unknown;

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06N 20/00 (2019.01); G06F 21/55 (2013.01);
U.S. Cl.
CPC ...
H04L 63/1433 (2013.01); G06F 21/55 (2013.01); G06F 21/552 (2013.01); G06F 21/554 (2013.01); G06N 20/00 (2019.01); H04L 63/1408 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01);
Abstract

System and methods for determining network threats are disclosed. For each entity operating in a network being monitored for network security, an example method obtains an observed metric value for each metric that characterizes actions performed by the entity. Each observed metric value may be input into a machine learning model that is specific to the metric in order to determine an anomaly score for the observed metric value that represents how anomalous the observed metric value is relative to an expected metric value for the metric. A threat score may then be determined for each entity from the anomaly scores for each metric. A security threat presentation that identifies one or more high-scoring entities according to the threat scores may be generated and provided for display on a user device.


Find Patent Forward Citations

Loading…