The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 20, 2021

Filed:

Apr. 23, 2019
Applicant:

Darktrace Limited, Cambridge, GB;

Inventors:

Jack Stockdale, Cambridge, GB;

Stephen Casey, Cambridge, GB;

Anthony Preston, Berkshire, GB;

Assignee:

Darktrace Limited, Cambridge, GB;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06N 20/00 (2019.01); H04L 12/26 (2006.01); H04L 12/24 (2006.01);
U.S. Cl.
CPC ...
H04L 63/145 (2013.01); G06N 20/00 (2019.01); H04L 43/12 (2013.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01); H04L 63/1433 (2013.01); H04L 63/1491 (2013.01); H04L 63/20 (2013.01); H04L 41/22 (2013.01);
Abstract

A multivariate anomaly detector can detect a cyber-attack using incremental malicious actions distributed across multiple devices in a network. A multivariate anomaly detector can collect input data describing communication connections between devices in the network. The multivariate anomaly detector can group the input data into a graph data batch based on a fixed batch increment of time to identify incremental actions. The multivariate anomaly detector can calculate a multivariate centrality score for two or more devices based on the graph data batch describing device centrality to the network. The multivariate anomaly detector can identify whether the two or more devices are in an anomalous state from normal device network interactions based on the multivariate centrality score to identify malicious activity distributed across multiple devices in the network. The multivariate anomaly detector can identify a cyber-attack upon identifying the incremental malicious actions distributed across multiple devices in the network.


Find Patent Forward Citations

Loading…