首页> 外国专利> Clustering for detection of anomalous behavior and insider threat

Clustering for detection of anomalous behavior and insider threat

机译:聚类以检测异常行为和内部威胁

摘要

Detecting anomalous user behavior is provided. User activity is logged for a set of users. The user activity is divided into distinct time intervals. For each distinct time interval, logged user activity is converted to a numerical representation of each user's activities for that distinct time interval. A clustering process is used on the numerical representations of user activities to determine which users have similar activity patterns in each distinct time interval. A plurality of peer groups of users is generated based on determining the similar activity patterns in each distinct time interval. Anomalous user behavior is detected based on a user activity change in a respective peer group of users within a distinct time interval.
机译:提供了检测异常用户行为的功能。记录了一组用户的用户活动。用户活动分为不同的时间间隔。对于每个不同的时间间隔,已记录的用户活动将转换为该不同时间间隔内每个用户活动的数字表示。在用户活动的数字表示上使用聚类过程来确定哪些用户在每个不同的时间间隔内具有相似的活动模式。基于确定每个不同时间间隔中的相似活动模式来生成多个对等用户组。基于不同时间间隔内相应对等用户组中用户活动的变化来检测异常用户行为。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号