US Patent:
20120072983, Mar 22, 2012
Inventors:
Owen McCUSKER - East Lyme CT, US
Scott BRUNZA - Old Lyme CT, US
Assignee:
Sonalysts, Inc. - Waterford CT
International Classification:
G06F 11/00
Abstract:
A method of determining, within a deployed environment over a data communication network, network threats and their associated behaviors. The method includes the steps of acquiring sensor data that identifies a specific contact, normalizing the acquired sensor data to generate transformed sensor data, deriving, for the specific contact from the transformed sensor data, a contact behavior feature vector for each of a plurality of time periods, determining, for the specific contact, scores associated with each of a plurality of classification modules to form a contact score vector, the contact score vector being independent of an identity of the specific contact, identifying a type of the specific contact based on the contact score vector, and determining a threat type, based on the contact behavioral profile and the contact score vector, when the specific contact is determined to be a threat in the identifying step.