ANOMALY DETECTION BASED ON INFORMATION TECHNOLOGY ENVIRONMENT TOPOLOGY

Patent №

US 10,693,900

Granted

2020-06-23

Filed 2019

Owner

SPLUNK INC.

Lab

AI components

2

kr · planning

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

16250989

Techniques are described for analyzing data regarding activity in an IT environment to determine information regarding the entities associated with the activity and using the information to detect anomalous activity that may be indicative of malicious activity. In an embodiment, a plurality of events reflecting activity by a plurality of entities in an IT environment are processed to resolve the identities of the entities, discover how the entities fit within a topology of the IT environment, and determine what the entities are. This information is then used to generate an entity relationship graph that includes nodes representing the entities in the IT environment and edges connecting the nodes representing interaction relationships between the entities. In some embodiments, baselines are established by monitoring the activity between entities. This baseline information can be represented in the entity relationship graph in the form of directionality applied to the edges. The entity relationship graph can then be monitored to detect anomalous activity.

Knowledge representationPlanningH04L 63/1425H04L 43/045H04L 43/08H04L 61/103H04L 61/45H04L 67/30H04L 41/12H04L 43/106+4 more

AI classification

Planning0.95
Knowledge representation0.94
Machine learning0.12
AI hardware0.02
Natural language0.00
Speech0.00
Vision0.00
Evolutionary computation0.00

Ownership

SPLUNK INC.

assignment · 487270248

Assignors

ZADEH, JOSEPH AUGUSTE, SOTO, RODOLFO, APOSTOLOPOULOS, GEORGE, PIERCE, JOHN CLIFTON

On an employer assignment, the assignors are typically the inventors.

From the same owner

© 2026 NYSGPT2525 LLC