US2013111588A1PendingUtilityA1

Method and system for detecting intrusive anomalous use of a software system using multiple detection algorithms

Individually held — no corporate assignee on recordPriority: Oct 19, 2004Filed: Jan 30, 2012Published: May 2, 2013
Est. expiryOct 19, 2024(expired)· nominal 20-yr term from priority
G06F 21/552G06F 21/55H04L 63/1408
44
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method of detecting an intrusion into (or an anomaly in a behavior of) a target software system begins by instrumenting the target software system to generate behavior data representing a current observation or observation aggregate. The method then determines whether the current observation or observation aggregate warrants a second level examination. If a result of executing the first level detection algorithm indicates that the current observation or observation aggregate warrants a second level examination, the method continues by processing the current observation or observation aggregate through at least one or more second level detection algorithms to provide a second, more definite, fine grain indication of a possible intrusion.

Claims

exact text as granted — not AI-modified
Having thus described our invention, what is claimed is as follows: 
     
         1 . Apparatus, comprising:
 a processor; and   computer memory holding computer program instructions to carry out a method to process one or more event data streams to thereby detect a possible intrusion associated with a target system, the event data stream representing a current observation or observation aggregate associated with the target system that has been instrumented to generate the one or more event data streams, the method comprising:
 processing the current observation or observation aggregate through a first level detection algorithm that provides a first, provisional indication of a possible intrusion; 
 determining whether the current observation or observation aggregate warrants a second level examination, wherein the determining step is performed as the one or more event streams are being generated and by the first level detection algorithm computing an approximation of a given function; and 
 if a result of executing the first level detection algorithm indicates that the current observation or observation aggregate warrants a second level examination, processing the current observation or observation aggregate through at least one or more second level detection algorithms to provide a second, more definite indication of a possible intrusion; 
 wherein the first level detection algorithm has a computational-efficiency that is greater than a computational-efficiency of the second level detection algorithm, wherein computational efficiency is measured as a function of memory and processing requirements. 
   
     
     
         2 . The apparatus as described in  claim 1  wherein the one or more second level detection algorithms use floating point arithmetic operations. 
     
     
         3 . The apparatus as described in  claim 1  wherein the step of processing the current observation or observation aggregate through at least one or more second level detection algorithms processes the current observation or observation aggregate through at least a pair of second level detection algorithms whose outputs are analyzed according to a function to provide the second, more definite indication of the possible intrusion. 
     
     
         4 . The apparatus as described in  claim 3  wherein the function is selected from a set of functions, namely, linear functions, non-linear functions, rules-based functions, and logical combinations thereof. 
     
     
         5 . The apparatus as described in  claim 4  wherein the outputs are combined according to the function concurrently. 
     
     
         6 . The apparatus as in  claim 1  wherein the first level detection algorithm computes a metric from the current observation or observation aggregate and compares the metric against a given threshold value to determine whether the current observation or observation aggregate warrants the second level examination. 
     
     
         7 . The apparatus as described in  claim 1  wherein the first level detection algorithm uses non-floating point computations to determine whether the current observation or observation aggregate warrants the second level examination. 
     
     
         8 . The apparatus as described in  claim 1  wherein the first level detection algorithm is a Markov model process or an ellipsoidal model process. 
     
     
         9 . The apparatus as described in  claim 1  wherein the one or more second level detection algorithms are selected from a set of mathematical models that are executed using floating-point computations and that include: ellipsoidal models, k-means models, decision tree models, support vector machine (SVM) models, Markov process models, and combinations thereof. 
     
     
         10 . The apparatus as described in  claim 1  wherein the method further includes the step of taking a given action if the result of the second level examination indicates a possible intrusion.

Join the waitlist — get patent alerts

Track US2013111588A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.