WO2025224683 - ANOMALY DETECTION IN NETWORK TRAFFIC DATA
National phase entry is expected:
Publication Number
WO/2025/224683
Publication Date
30.10.2025
International Application No.
PCT/IB2025/054307
International Filing Date
24.04.2025
Title **
[English]
ANOMALY DETECTION IN NETWORK TRAFFIC DATA
[French]
DÉTECTION D'ANOMALIE DANS DES DONNÉES DE TRAFIC DE RÉSEAU
Applicants **
ARMIS SECURITY LTD.
Inventors
KEISAR, Bar
BURABIA, Gabi
BEN AKOUNE, Elad
TZUR-HILLELI, Michal
Priority Data
63/638,390
24.04.2024
US
Application details
| Total Number of Claims/PCT | * |
| Number of Independent Claims | * |
| Number of Priorities | * |
| Number of Multi-Dependent Claims | * |
| Number of Drawings | * |
| Pages for Publication | * |
| Number of Pages with Drawings | * |
| Pages of Specification | * |
| * | |
| Number of Office Actions | * |
| * | |
International Searching Authority |
EPO
* |
| Recordal of a Change of the Applicant's Name/Address |
Change of Applicant's Name and Address
* |
| Type of Assignment |
The Standard Agent's Assignment
* |
| Applicant's Legal Status |
Legal Entity
* |
| * | |
| * | |
| * | |
| * | |
| * | |
| Entry into National Phase under |
Chapter I
* |
| Patent Delivery |
Send the Letters Patent by Courier
* |
| 译文 |
|
* The data is based on automatic recognition. Please verify and amend if necessary.
** IP-Coster compiles data from publicly available sources. If this data includes your personal information, you can contact us to request its removal.
Quotation for National Phase entry
| Country | Stages | Total | |
|---|---|---|---|
| China | Filing, Examination, Granting | 2489 | |
| EPO | Filing, Examination, Granting | 11939 | |
| Japan | Filing, Examination, Granting | 2309 | |
| South Korea | Filing, Examination, Granting | 2385 | |
| USA | Filing, Examination, Granting | 4740 |

Total:
23,862
Contact Us
Abstract[English]
This disclosure relates to systems, methods, and devices for identifying anomalous network activity. In some embodiments, a baseline model is used for identifying anomalous network activity. In some embodiments, anomalous network activity is detected based on a z-score, modified z-score, or both being above respective thresholds when compared to the baseline. In some embodiments, multiple baseline models are used, and anomalous network activity is detected when multiple baseline models identify a network activity session as anomalous. In some embodiments, two baseline models are used.[French]
La présente divulgation concerne des systèmes, des procédés et des dispositifs pour identifier une activité de réseau anormale. Dans certains modes de réalisation, un modèle de base de référence est utilisé pour identifier une activité de réseau anormale. Dans certains modes de réalisation, une activité de réseau anormale est détectée selon qu'un score z, qu'un score z modifié, ou que les deux soient supérieurs à des seuils respectifs par comparaison avec la base de référence. Dans certains modes de réalisation, de multiples modèles de base de référence sont utilisés, et une activité de réseau anormale est détectée lorsque de multiples modèles de base de référence identifient une session d'activité de réseau comme anormale. Dans certains modes de réalisation, deux modèles de base de référence sont utilisés.