PATH SCANNING FOR THE DETECTION OF ANOMALOUS SUBGRAPHS AND USE OF DNS REQUESTS AND HOST AGENTS FOR ANOMALY/CHANGE DETECTION AND NETWORK SITUATIONAL AWARENESS

Patent №

US 9,825,979

Granted

2017-11-21

Filed 2017

Owner

Lab

AI components

2

ml · hardware

Assignment

None on record

Dataset

AIPD

2023_r1 edition

Application

15419673

A system, apparatus, computer-readable medium, and computer-implemented method are provided for detecting anomalous behavior in a network. Historical parameters of the network are determined in order to determine normal activity levels. A plurality of paths in the network are enumerated as part of a graph representing the network, where each computing system in the network may be a node in the graph and the sequence of connections between two computing systems may be a directed edge in the graph. A statistical model is applied to the plurality of paths in the graph on a sliding window basis to detect anomalous behavior. Data collected by a Unified Host Collection Agent (“UHCA”) may also be used to detect anomalous behavior.

Machine learningAI hardwareH04L 63/1425G06N 5/02G06N 5/022G06N 5/045G06N 7/01H04L 1/002H04L 63/1408H04L 63/1416+3 more

AI classification

AI hardware1.00
Machine learning0.60
Vision0.26
Planning0.05
Knowledge representation0.02
Evolutionary computation0.00
Speech0.00
Natural language0.00
© 2026 NYSGPT2525 LLC