作者: Chen Zhengzhang , Tang Luan , Jiang Guofei , Chen Haifeng , Li Zhichun
DOI:
关键词:
摘要: Methods and systems for reporting anomalous events include intra-host clustering a set of alerts based on process graph that models states process-level in network. Hidden relationship is performed the clustered hidden relationships between respective clusters. Inter-host topology source destination connection exceed threshold level trustworthiness are reported.