Method and system for detecting attack path connections in a computer network using state-space correlation

A method of determining correlated flows in a network may include obtaining times of arrival and corresponding flows for data units in the network and assigning weights to a set of data units based on respective times between the set of data units and one data unit. A probability matrix representing...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Strayer, William Timothy, Jones, Christine Elaine, Krishnan, Rajesh, Castineyra, Isidro Marcos, Hain, Regina Rosales
Format: Patent
Sprache:eng
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:A method of determining correlated flows in a network may include obtaining times of arrival and corresponding flows for data units in the network and assigning weights to a set of data units based on respective times between the set of data units and one data unit. A probability matrix representing interflow connections in the network may be updated based on the assigned weights.