FIELD: information security.
SUBSTANCE: invention relates to apparatus and methods for ensuring computer security. The technical result is achieved due to the fact that in the proposed method, the hardware processor of a computer system executes the following stages: assigning a training set of event categories to events; assigning client systems to multiple client clusters in accordance with the event categories; and transmitting the attribution indicator of the client cluster to the anomaly detector configured to determine whether the event corresponds to computer security or a threat; wherein assigning categories to events includes: selecting multiple events occurring in client systems from the training set, forming a sequence of events, and assigning a category to the selected event from the sequence of events in accordance with the preceding event and additionally, in accordance with the subsequent event; wherein attribution of client systems to client clusters includes assigning the client system to the selected client cluster in accordance with the event profile; wherein the anomaly detector is configured to determine whether the event indicates a computer security threat in accordance with the behaviour model trained on a subset of events specific to the client cluster.
EFFECT: increase in the reliability of the system for detecting computer threats.
17 cl, 20 dwg
| Title | Year | Author | Number | 
|---|---|---|---|
| SYSTEMS AND METHODS FOR DETECTING BEHAVIOURAL THREATS | 2019 | 
 | RU2803399C2 | 
| SYSTEMS AND METHODS FOR DETECTING BEHAVIOURAL THREATS | 2019 | 
 | RU2778630C1 | 
| COMPUTER SYSTEM AND METHOD FOR DETECTING MALWARE USING MACHINE LEARNING | 2021 | 
 | RU2802860C1 | 
| CONFIDENTIALITY-PRESERVING DOMAIN NAME SERVICE (DNS) | 2021 | 
 | RU2837326C2 | 
| SYSTEMS AND METHODS FOR REPORTING COMPUTER SECURITY INCIDENTS | 2019 | 
 | RU2757597C1 | 
| SYSTEMS AND METHODS FOR USING DNS MESSAGES FOR SELECTIVE COLLECTION OF COMPUTER FORENSIC DATA | 2020 | 
 | RU2776349C1 | 
| SYSTEMS AND METHODS OF DEVICES AUTOMATIC DETECTION | 2017 | 
 | RU2742824C2 | 
| USER INTERFACE FOR PROVIDING SECURITY AND REMOTE CONTROL OF NETWORK ENDPOINTS | 2015 | 
 | RU2697935C2 | 
| SYSTEMS AND METHODS FOR TRANSLATING NATURAL LANGUAGE SENTENCES INTO DATABASE QUERIES | 2019 | 
 | RU2792579C2 | 
| SYSTEMS AND METHODS FOR AUTOMATIC DEVICE DETECTION, DEVICE CONTROL AND REMOTE ASSISTANCE | 2015 | 
 | RU2694022C2 | 
Authors
Dates
2022-05-23—Published
2019-12-10—Filed