首页> 外国专利> Automatically detecting insider threats using user collaboration patterns

Automatically detecting insider threats using user collaboration patterns

机译:使用用户协作模式自动检测内部威胁

摘要

Automatically detecting insider threats using user collaboration patterns. In one embodiment, a method may include identifying collaborative access of one or more network resources in a network between a target user using a target network device and other users using other network devices in the network during multiple prior time periods and during a current time period, generating prior collaboration graphs for the prior time periods, generating an average collaboration graph by combining the prior collaboration graphs, generating a current collaboration graph for the current time period, generating an anomaly score by comparing the current collaboration graph to the average collaboration graph, determining that the collaborative access of the one or more network resources during the current time period is anomalous by determining that the anomaly score exceeds a threshold, and, in response to the anomaly score exceeding the threshold, performing a security action on the target network device.
机译:使用用户协作模式自动检测内部威胁。在一个实施例中,一种方法可以包括:在多个先前时间段期间和当前时间段期间,识别使用目标网络设备的目标用户与使用网络中其他网络设备的其他用户之间网络中一个或多个网络资源的协作访问。 ,生成先前时间段的先前协作图,通过组合先前协作图生成平均协作图,生成当前时间段的当前协作图,通过将当前协作图与平均协作图进行比较来生成异常评分,通过确定异常分数超过阈值来确定当前时间段内一个或多个网络资源的协作访问是异常的,并且响应于异常分数超过阈值,对目标网络设备执行安全动作。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号