CPC H04L 63/1458 (2013.01) [G06F 17/18 (2013.01); H04L 63/1425 (2013.01); H04L 63/1433 (2013.01)] | 19 Claims |
1. A method for detecting cyber-attacks, comprising:
identifying at least one hit quantile out of a plurality of quantiles, wherein the at least one identified hit quantile falls within quantile edges of a sample of traffic directed at a protected entity, wherein each of the plurality of quantiles is characterized by a probability distribution of at least one feature of a data stream, each of the plurality of quantiles having a respective probability estimate;
updating the probability estimates of the plurality of quantiles when the at least one hit quantile has been identified; and
when the probability estimate of the at least one hit quantile is above a threshold, taking an action to mitigate existence of a cyber-attack.
|