The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 07, 2016

Filed:

Dec. 11, 2013
Applicant:

Ut-battelle, Llc, Oak Ridge, TN (US);

Inventors:

Erik M. Ferragut, Oak Ridge, TN (US);

Jason A. Laska, Oak Ridge, TN (US);

Robert A. Bridges, Knoxville, TN (US);

Assignee:

UT-Batelle, LLC, Oak Ridge, TN (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/57 (2013.01); G06F 21/55 (2013.01); H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
G06F 21/577 (2013.01); G06F 21/552 (2013.01); H04L 63/1425 (2013.01);
Abstract

A system is described for receiving a stream of events and scoring the events based on anomalousness and maliciousness (or other classification). The system can include a plurality of anomaly detectors that together implement an algorithm to identify low-probability events and detect atypical traffic patterns. The anomaly detector provides for comparability of disparate sources of data (e.g., network flow data and firewall logs.) Additionally, the anomaly detector allows for regulatability, meaning that the algorithm can be user configurable to adjust a number of false alerts. The anomaly detector can be used for a variety of probability density functions, including normal Gaussian distributions, irregular distributions, as well as functions associated with continuous or discrete variables.


Find Patent Forward Citations

Loading…