Search International and National Patent Collections

1. (WO2016057994) DIFFERENTIAL DEPENDENCY TRACKING FOR ATTACK FORENSICS

Pub. No.:    WO/2016/057994    International Application No.:    PCT/US2015/055137
Publication Date: Fri Apr 15 01:59:59 CEST 2016 International Filing Date: Tue Oct 13 01:59:59 CEST 2015
IPC: H04L 29/06
H04L 12/26
Applicants: NEC LABORATORIES AMERICA, INC.
Inventors: LI, Zhichun
WU, Zhenyu
QIAN, Zhiyun
JIANG, Guofei
AKHOONDI, Masoud
KUSANO, Markus
Title: DIFFERENTIAL DEPENDENCY TRACKING FOR ATTACK FORENSICS
Abstract:
Methods and systems for intrusion attack recovery include monitoring (502) two or more hosts in a network to generate audit logs of system events. One or more dependency graphs (DGraphs) is generated (504) based on the audit logs. A relevancy score for each edge of the DGraphs is determined (510). Irrelevant events from the DGraphs are pruned (510) to generate a condensed backtracking graph. An origin is located by backtracking (512) from an attack detection point in the condensed backtracking graph.