CA2868076C

Anomaly detection to identify coordinated group attacks in computer networks

Abstract

Systems, apparatuses, methods, and computer programs for detecting anomalies to identify coordinated group attacks on computer networks are provided. An anomaly graph of a network including nodes, edges, and an indegree of the nodes in the anomaly graph may be determined. Nodes with an indegree of at least two may be designated as potential targets. Nodes with no incoming connections may be designated as potentially compromised nodes. The designated potentially compromised nodes may be outputted as potentially associated with a coordinated attack on the network when the potentially compromised nodes connect to one or more of the same potential target nodes.

Term

Projected expiry 14 March 2033.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Projected expiry

20 claims: 3 independent, 17 dependent

  1. 1
    CLAIMS 1. A computer-implemented method, comprising:determining, by a computing system, an anomaly graph of a network comprising nodes, edges, and an indegree of the nodes in the anomaly graph;designating, by the computing system, nodes with an indegree of at least two as potential targets;designating, by the computing system, nodes with no incoming connections as potentially compromised nodes;and outputting, by the computing system, the designated potentially compromised nodes as potentially associated with a coordinated attack on the network when the potentially compromised nodes connect to at least one of the same potential target nodes.
  2. 8
    An apparatus, comprising:at least one processor;and memory storing computer program instructions, wherein the instructions, when executed by the at least one processor, are configured to cause the at least one processor to: monitor a network over time periods to determine anomalous behavior signifying potential activity from a group of attackers during at least one time period, wherein the determination of the anomalous behavior is based on a determination of whether multiple nodes with no indegree and common node connections exist during the time period, and provide an indication that a potential group attack is occurring in the network when anomalous behavior is determined during at least one time period.
  3. 15
    A system, comprising:memory storing computer program instructions configured to detect anomalies in a network;and a plurality of processing cores configured to execute the stored computer program instructions, wherein plurality of processing cores is configured to: generate an anomaly graph for a network during a time period;determine whether multiple nodes with no indegree and common node connections exist during the time period;and generate an indication of a potential group attack on the network when the system determines that multiple nodes with no indegree and common node connections exist in one or more subgraphs of the anomaly graph.