IP Library Granted Patent US 10,440,040
Granted Patent B2
US 10,440,040 · App. 15/380,450 · Granted Oct 8, 2019

Using frequency analysis in enterprise threat detection to detect intrusions in a computer system

Inventors: Kathrin Nos (Nussloch, DE); Volker Guzman (Heidelberg, DE); Marvin Klose (Mannheim, DE)
Assignee: SAP SE
H04L63/1425H04L63/02H04L63/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,440,040
App. No.
15/380,450
Granted
Oct 8, 2019
Kind
B2
Abstract

The present disclosure describes methods, systems, and computer program products for performing a frequency domain analysis of activity data for a computer system. One computer-implemented method receiving time domain activity data for a computer system, wherein the time domain activity data comprise activity records associated with the computer system in a time domain; computing, by a hardware processor, frequency domain activity data based on the time domain activity data; and displaying the frequency domain activity data.

Claims (43)

1. A computer-implemented method, comprising:

receiving time domain activity data for a computer system, wherein the time domain activity data comprise activity records associated with the computer system in a time domain;

filtering the time domain activity data based on activities associated with a monitored job or a monitored user;

computing, by a hardware processor at an intrusion detection system, frequency domain activity data based on the filtered time domain activity data, wherein computing, by the hardware processor, the frequency domain activity data based on the filtered time domain activity data comprise:

grouping the filtered time domain activity data into a plurality of groups, each of the plurality of groups comprises filtered time domain activity data in a different time period; and

for each of the groups, computing frequency domain activity data based on the filtered time domain activity data in the respective group;

identifying, by the hardware processor at the intrusion detection system, a presence of a malicious attack among the activity records by comparing the frequency domain activity data; and

displaying, at the intrusion detection system, the frequency domain activity data for each group consecutively.

2. The computer-implemented method of claim 1 , wherein the frequency domain activity data are computed using Fourier Transform.

3. The computer-implemented method of claim 1 , wherein the frequency domain activity data for each group are displayed using an animated format.

4. The computer-implemented method of claim 1 , further comprising:

determining a maximum amplitudes of the frequency domain activity data; and

displaying a user interface object indicating the maximum amplitude.

5. The computer-implemented method of claim 1 , wherein the activity records indicate time at which jobs are executed on the computer system.

6. A computer-implemented system, comprising:

a computer memory; and

a hardware processor interoperably coupled with the computer memory and configured to perform operations comprising:

receiving time domain activity data for a computer system, wherein the time domain activity data comprise activity records for the different computer system in a time domain;

filtering the time domain activity data on activities associated with a monitored job or a monitored user;

computing frequency domain activity data based on the filtered time domain activity data, wherein computing the frequency domain activity data based on the filtered time domain activity data comprise:

grouping the filtered time domain activity data into a plurality of groups, each of the plurality of groups comprises filtered time domain activity data in a different time period; and

for each of the groups, computing frequency domain activity data based on the filtered time domain activity data in the respective group;

identifying a presence of a malicious attack among the activity records by comparing the frequency domain activity data computed; and

displaying the frequency domain activity data for each group consecutively.

7. The computer-implemented system of claim 6 , wherein the frequency domain activity data are computed using Fourier Transform.

8. The computer-implemented system of claim 6 , wherein the frequency domain activity data for each group are displayed using an animated format.

9. The computer-implemented system of claim 6 , the operations further comprising:

determining a maximum amplitudes of the frequency domain activity data; and

displaying a user interface object indicating the maximum amplitude.

10. The computer-implemented system of claim 6 , wherein the activity records indicate time at which jobs are executed on the computer system.

11. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising:

receiving time domain activity data for a computer system, wherein the time domain activity data comprise activity records for the different computer system in a time domain;

filtering the time domain activity data based on activities associated with a monitored job or a monitored user;

computing, by a hardware processor at the computer system, frequency domain activity data based on the filtered time domain activity data, wherein computing, by the hardware processor at the computer system, the frequency domain activity data based on the filtered time domain activity data comprise:

grouping the filtered time domain activity data into a plurality of groups, each of the plurality of groups comprises filtered time domain activity data in a different time period; and

for each of the groups, computing frequency domain activity data based on the filtered time domain activity data in the respective group;

identifying, by the hardware processor at the computer system, a presence of a malicious attack among the activity records by comparing the frequency domain activity data; and

displaying, at the computer system, the frequency domain activity data for each group consecutively.

12. The non-transitory, computer-readable medium of claim 11 , wherein the frequency domain activity data are computed using Fourier Transform.

13. The non-transitory, computer-readable medium of claim 11 , wherein the frequency domain activity data for each group are displayed using an animated format.

14. The non-transitory, computer-readable medium of claim 11 , the operations further comprising:

determining a maximum amplitudes of the frequency domain activity data; and

displaying a user interface object indicating the maximum amplitude.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 24, 2017
From: NOS, KATHRIN; GUZMAN, VOLKER; KLOSE, MARVIN
To: SAP SE
Reel/Frame 041066/0279 →
Continuity (1)
Related Publication 20180176238A1 · Jun 21, 2018