SYSTEMS AND METHODS FOR REDUCING FALSE POSITIVES WHEN USING EVENT-CORRELATION GRAPHS TO DETECT ATTACKS ON COMPUTING SYSTEMS

Patent №

US 9,166,997

Granted

2015-10-20

Filed 2013

Owner

SYMANTEC CORPORATION

Lab

AI components

4

ml · kr · planning · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

14031044

A computer-implemented method for reducing false positives when using event-correlation graphs to detect attacks on computing systems may include (1) detecting a suspicious event involving a first actor within a computing system, (2) constructing an event-correlation graph that includes a first node that represents the first actor, a second node that represents a second actor, and an edge that represents an additional suspicious event involving the first actor and the second actor, (3) comparing the event-correlation graph with at least one additional event-correlation graph that represents events on at least one additional computing system, (4) determining that a similarity of the event-correlation graph and the additional event-correlation graph exceeds a predetermined threshold, and (5) classifying the suspicious event as benign based on determining that the similarity of the event-correlation graph and the additional event-correlation graph exceeds the predetermined threshold. Various other methods, systems, and computer-readable media are also disclosed.

AI classification

Planning1.00
Knowledge representation0.99
AI hardware0.89
Machine learning0.76
Vision0.01
Natural language0.00
Evolutionary computation0.00
Speech0.00

Ownership

SYMANTEC CORPORATION

assignment · 312360278

Assignors

GUO, FANGLU, BHATKAR, SANDEEP, ROUNDY, KEVIN

On an employer assignment, the assignors are typically the inventors.

© 2026 NYSGPT2525 LLC