Palantir Technologies Inc.
Network anomaly detection
Last updated:
Abstract:
A security system detects anomalous activity in a network. The system logs user activity, which can include ports used, compares users to find similar users, sorts similar users into cohorts, and compares new user activity to logged behavior of the cohort. The comparison can include a divergence calculation. Origins of user activity can also be used to determine anomalous network activity. The hostname, username, IP address, and timestamp can be used to calculate aggregate scores and convoluted scores.
Status:
Grant
Type:
Utility
Filling date:
22 Aug 2018
Issue date:
4 Aug 2020