VMware, Inc.
CREATING A CLUSTERING MODEL FOR EVALUATING A COMMAND LINE INTERFACE (CLI) OF A PROCESS

Last updated:

Abstract:

Certain aspects of the present disclosure relate to methods and systems for evaluating a first command line interface (CLI) input of a process. The method comprises examining the first CLI input and selecting a first clustering model corresponding to the process, wherein the first clustering model is created based on a first clustering configuration and a first feature type combination. The method further comprises creating a first feature combination for the first CLI input based on the first feature type combination, evaluating the first CLI input using the first clustering model and the first feature combination, wherein the evaluating further comprises determining a similarity score corresponding to a similarity between the first feature combination and the one or more clusters, and determining whether or not the first CLI input corresponds to normal behavior based on the similarity score.

Status:
Application
Type:

Utility

Filling date:

3 Jul 2019

Issue date:

7 Jan 2021