CPC H04L 41/0631 (2013.01) [H04L 41/0627 (2013.01); H04L 41/12 (2013.01)] | 20 Claims |
1. A method for determining a correlation of one or more events occurring in a plurality of nodes of a network, comprising:
accessing, by a computing device, address information associated with each of the plurality of nodes on the network;
accessing, by the computing device, one or more event IDs associated with one or more events occurring on the plurality of nodes;
creating an association, by the computing device, between the one or more events occurring on the plurality of nodes with related events occurring on others of the plurality of nodes, the association including the address information;
computing a topology homogeneity score on the one or more event IDs, based on a topological relationship between the plurality of nodes;
identifying rules of a node of the plurality of nodes to be transferrable to another node of the plurality of nodes based on the topology homogeneity score; and
reducing a number of false positives in an alert based on the rules.
|