首页> 外国专利> USER BEHAVIOR ANALYTICS FOR INSIDER THREAT DETECTION

USER BEHAVIOR ANALYTICS FOR INSIDER THREAT DETECTION

机译:内威胁检测的用户行为分析

摘要

Disclosed in some examples are systems, methods, and machine readable mediums for identifying insider threats by determining file system element activity models that correlate to undesirable behavior and then utilizing the determined model to detect insider threats. Events involving file system elements of a client computing device (e.g., a network endpoint) may be monitored by a file system element monitoring application on the client computing device. The values of these signals are aggregated across all events of the same type that have occurred within a predetermined time window (e.g., an hour) for a particular client computing device. Each time an aggregated signal has a value over the threshold, an anomaly is recorded. Anomaly counts for each signal are then calculated as the aggregate number of anomalies for a particular signal over a second time period, the span of which is determined by the generation of first anomaly to the close of an alert by the network monitor. The anomaly counts for the signals are then weighted and summed to produce a risk score.
机译:在一些示例中公开了用于通过确定与不良行为相关联的文件系统元素活动模型,然后利用确定的模型来检测内部威胁来识别内部威胁的系统,方法和机器可读介质。涉及客户端计算设备(例如,网络端点)的文件系统元素的事件可以由客户端计算设备上的文件系统元素监视应用程序监视。这些信号的值在针对特定客户端计算设备的预定时间窗口(例如一个小时)内发生的所有相同类型的事件中进行汇总。每次聚合信号的值超过阈值时,都会记录一个异常。然后,将每个信号的异常计数计算为第二时间段内特定信号的异常总数,该间隔的范围由网络监视器生成的第一异常到警报结束来确定。然后对信号的异常计数进行加权和求和以产生风险评分。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号