| CPC H04L 63/1416 (2013.01) [G06N 20/00 (2019.01); H04L 63/1425 (2013.01); H04L 63/1441 (2013.01)] | 17 Claims |

|
1. A system, comprising:
a plurality of compute nodes of a network comprising two or more compute nodes that host respective virtual computing resource instances, each compute node comprising at least one processor and a memory; and
a security threat detection and mitigation platform, for classifying behavior of the virtual computing resource instances within the network, implemented on the network and configured to:
train a machine model to distinguish malicious behavior in network traffic based on patterns, in known-malicious network traffic, of one or more features of interest including packet size, packet frequency, or ratio of inbound packets to outbound packets;
receive one or more indications of patterns of network traffic received by, or sent from, one of the virtual computing resource instances within the network;
classify, based on application of the trained machine model to the one or more indicated patterns of network traffic for the virtual computing resource instance within the network, behavior of the virtual computing resource instance with respect to a security threat of a particular type; and
take action, in response to classification of the behavior of the virtual computing resource instance within the network as malicious with respect to the security threat, to mitigate the security threat.
|