Aggregating alerts of malicious events for computer security

A method by a computing device implementing an attack analyzer for processing malicious events. The method includes determining a first set of features describing a malicious event detected by a firewall, determining a set of distances using a non-Euclidean distance function and the first set of fea...

Full description

Saved in:
Bibliographic Details
Main Authors Hershkovitz, Shelly, Yehudai, Gilad, Mantin, Itsik, Fisch, Lior, Ambar, Moran Rachel, Shulman, Amichai
Format Patent
LanguageEnglish
Published 07.03.2023
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:A method by a computing device implementing an attack analyzer for processing malicious events. The method includes determining a first set of features describing a malicious event detected by a firewall, determining a set of distances using a non-Euclidean distance function and the first set of features, wherein the non-Euclidean distance function is used to determine geographic origin similarity between different Internet Protocol addresses included in the first and second set of features, generating a statistical distribution object using the set of distances, wherein the statistical distribution object includes information describing a cluster that includes at least the malicious event and one or more other malicious events that are determined to be similar to the malicious event in terms of geographic origin, and transmitting information describing the cluster to a management console for presentation to an administrator on a graphical user interface.
Bibliography:Application Number: US202117456362