首页>
外国专利>
SYSTEM, METHOD, AND COMPUTER PROGRAM FOR DETECTION OF ANOMALOUS USER NETWORK ACTIVITY BASED ON MULTIPLE DATA SOURCES
SYSTEM, METHOD, AND COMPUTER PROGRAM FOR DETECTION OF ANOMALOUS USER NETWORK ACTIVITY BASED ON MULTIPLE DATA SOURCES
展开▼
机译:基于多个数据源的异常用户网络活动检测的系统,方法和计算机程序
展开▼
页面导航
摘要
著录项
相似文献
摘要
The present disclosure relates a system, method, and computer program for detecting anomalous user network activity based on multiple data sources. The system extracts user event data for n days from multiple data sources to create a baseline behavior model that reflects the user's daily volume and type of IT events. In creating the model, the system addresses data heterogeneity in multi-source logs by categorizing raw events into meta events. Thus, baseline behavior model captures the user's daily meta-event pattern and volume of IT meta events over n days. The model is created using a dimension reduction technique. The system detects any anomalous pattern and volume changes in a user's IT behavior on day n by comparing user meta-event activity on day n to the baseline behavior model. A score normalization scheme allows identification of a global threshold to flag current anomalous activity in the user population.
展开▼