首页> 外国专利> Identifying insider-threat security incidents via recursive anomaly detection of user behavior

Identifying insider-threat security incidents via recursive anomaly detection of user behavior

机译:通过递归异常检测用户行为来识别内部威胁安全事件

摘要

A computerized system for recursively detecting anomalies in monitored behavior of entities. The system comprises a storage unit to store monitored events, event deviations and parameters related to each event and to each event deviation. The system comprises a processing unit configured to receive a plurality of input events, construct a plurality of baseline models, receive an input event that occurred during an analyzed timeframe, compare parameters of the received input event to a corresponding baseline model in order to detect an event deviation, and associate an event deviation score to the detected event deviation. Using the detected event deviation as an input event, said operations are repeated until a predetermined condition is satisfied, and an alert is generated, indicating suspicious activity has been detected. A viewer application configured to receive and display alerts relating to the detected event deviation is provided.
机译:一种用于递归检测受监视实体行为异常的计算机化系统。该系统包括存储单元,用于存储监视的事件,事件偏差以及与每个事件和每个事件偏差有关的参数。该系统包括配置成接收多个输入事件,构造多个基线模型,接收在分析的时间帧期间发生的输入事件,将接收到的输入事件的参数与对应的基线模型进行比较以便检测出一个输入信号的处理单元。事件偏差,并将事件偏差评分与检测到的事件偏差相关联。使用检测到的事件偏差作为输入事件,重复所述操作直到满足预定条件,并生成警报,指示已检测到可疑活动。提供了一种查看器应用程序,该应用程序配置为接收和显示与检测到的事件偏差有关的警报。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号