skip to main content
OSTI.GOV title logo U.S. Department of Energy
Office of Scientific and Technical Information

Title: Detection of anomalous events

Patent ·
OSTI ID:1255959

A system is described for receiving a stream of events and scoring the events based on anomalousness and maliciousness (or other classification). The system can include a plurality of anomaly detectors that together implement an algorithm to identify low-probability events and detect atypical traffic patterns. The anomaly detector provides for comparability of disparate sources of data (e.g., network flow data and firewall logs.) Additionally, the anomaly detector allows for regulatability, meaning that the algorithm can be user configurable to adjust a number of false alerts. The anomaly detector can be used for a variety of probability density functions, including normal Gaussian distributions, irregular distributions, as well as functions associated with continuous or discrete variables.

Research Organization:
Oak Ridge National Laboratory (ORNL), Oak Ridge, TN (United States)
Sponsoring Organization:
USDOE
DOE Contract Number:
AC05-00OR22725
Assignee:
UT-Batelle, LLC (Oak Ridge, TN)
Patent Number(s):
9,361,463
Application Number:
14/103,703
OSTI ID:
1255959
Resource Relation:
Patent File Date: 2013 Dec 11
Country of Publication:
United States
Language:
English

References (8)

Integration of Self-Organizing Map (SOM) and Kernel Density Estimation (KDE) for network intrusion detection conference September 2009
Anomaly detection: A survey journal July 2009
VAST Challenge 2012: Visual analytics for big data conference October 2012
An Intrusion-Detection Model journal February 1987
Tracking User Mobility to Detect Suspicious Behavior conference December 2013
Method and apparatus for detecting malicious code in an information handling system patent June 2010
Computer-implemented modeling systems and methods for analyzing and predicting computer network intrusions patent September 2011
Statistical method and system for network anomaly detection patent December 2013

Similar Records

Real-time detection and classification of anomalous events in streaming data
Patent · Tue Apr 19 00:00:00 EDT 2016 · OSTI ID:1255959

Compression Analytics for Classification and Anomaly Detection within Network Communication
Journal Article · Fri Oct 26 00:00:00 EDT 2018 · IEEE Transactions on Information Forensics and Security · OSTI ID:1255959

Profile-based adaptive anomaly detection for network security.
Technical Report · Tue Nov 01 00:00:00 EST 2005 · OSTI ID:1255959