Search International and National Patent Collections

1. (WO2018126226) MONITORING NETWORK SECURITY USING MACHINE LEARNING

Pub. No.:    WO/2018/126226    International Application No.:    PCT/US2017/069126
Publication Date: Fri Jul 06 01:59:59 CEST 2018 International Filing Date: Sat Dec 30 00:59:59 CET 2017
IPC: H04L 29/06
G06F 21/55
Applicants: HILLARD, Dustin Lundring Rigg
MUNSON, Art
CAYTON, Lawrence
GOLDER, Scott
Inventors: HILLARD, Dustin Lundring Rigg
MUNSON, Art
CAYTON, Lawrence
GOLDER, Scott
Title: MONITORING NETWORK SECURITY USING MACHINE LEARNING
Abstract:
System and methods for determining network threats are disclosed. For each entity operating in a network being monitored for network security, an example method obtains an observed metric value for each metric that characterizes actions performed by the entity. Each observed metric value may be input into a machine learning model that is specific to the metric in order to determine an anomaly score for the observed metric value that represents how anomalous the observed metric value is relative to an expected metric value for the metric. A threat score may then be determined for each entity from the anomaly scores for each metric. A security threat presentation that identifies one or more high-scoring entities according to the threat scores may be generated and provided for display on a user device.