The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
May. 18, 2021

Filed:

Apr. 03, 2017
Applicant:

Splunk Inc., San Francisco, CA (US);

Inventors:

Stanislav Miskovic, San Francisco, CA (US);

Satheesh Kumar Joseph Durairaj, San Francisco, CA (US);

George Apostolopulous, San Francisco, CA (US);

Dimitrios Terzis, San Francisco, CA (US);

Assignee:

Splunk Inc., San Francisco, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 16/17 (2019.01); G06N 5/04 (2006.01); H04L 29/08 (2006.01); G06N 20/00 (2019.01); G06N 5/02 (2006.01);
U.S. Cl.
CPC ...
G06F 16/1734 (2019.01); G06N 5/025 (2013.01); G06N 5/047 (2013.01); G06N 20/00 (2019.01); H04L 67/22 (2013.01);
Abstract

A system and method of obtaining and utilizing an activity signature that is representative of a specific category of network activities based on directory service (DS) log data. The activity signature may be determining by a learning process, including segmenting and pruning a training dataset into a plurality of event segments and matching them with activities based on DS log data of known activities. Once obtained, the activity signature can advantageously be utilized to analyze any DS log data and activities in actual deployment. Using activity signatures to analyze DS event log can reveal roles of event-collection machines, aggregate information dispersed across their component events to reveal actors involved in particular AD activities, augment visibility of DS by enabling various vantage points to better infer activities at other domain machines, and reveal macro activities so that logged information becomes easily interpretable to human analysts.


Find Patent Forward Citations

Loading…