首页> 外国专利> INTEGRATED MONITORING SYSTEM FOR PERSONAL INFORMATION SECURITY PRODUCT

INTEGRATED MONITORING SYSTEM FOR PERSONAL INFORMATION SECURITY PRODUCT

机译:个人信息安全产品集成监控系统

摘要

The present invention relates to an integrated management system for personal information security products comprising: a profiling cluster storage module; and an abnormal pattern analysis module. The profiling cluster storage module comprises: a task-based data converting unit which converts data using personal information for a task of a user into a task behavior list data; a task-based data extracting unit which extracts the task behavior list acquired by the data converting unit for each user; a task-based vector converting unit which vectorizes the extracted task behavior list for each user; a task-based clustering processing unit which uses a K-average algorithm to cluster the vectorized task behavior list and forms a task-based cluster; a task-based critical value calculating unit which uses t-digest algorithm to calculate a threshold value of a distance value between a center of the task-based cluster and factors; and a clustering storage unit which stores the task-based cluster and the threshold value of the distance value as a column-type data format. The abnormal pattern analysis module comprises an abnormal pattern determining unit which compares an analyzed distance value of a cluster acquired by a following personal information access behavior of the user with a threshold value of the task-based distance value acquired by the storage module, and determines whether abnormality occurs or not. The system analyzes task behavior of a user for logs generated and collected with no preset abnormal patterns, such that false positive rates or false negative rates can be reduced.
机译:本发明涉及一种用于个人信息安全产品的集成管理系统,包括:配置文件群集存储模块;以及以及异常模式分析模块。所述配置集群存储模块包括:基于任务的数据转换单元,其使用针对用户的任务的个人信息将数据转换为任务行为列表数据;以及基于任务的数据提取单元,为每个用户提取由数据转换单元获取的任务行为列表;基于任务的向量转换单元,其为每个用户对提取的任务行为列表进行向量化;基于任务的聚类处理单元,其使用K均值算法对向量化的任务行为列表进行聚类,形成基于任务的聚类;基于任务的临界值计算单元,其使用t-摘要算法来计算基于任务的聚类的中心与因子之间的距离值的阈值;聚类存储单元将基于任务的聚类和距离值的阈值存储为列型数据格式。异常模式分析模块包括异常模式确定单元,该异常模式确定单元将通过用户的以下个人信息访问行为获取的聚类的分析距离值与由存储模块获取的基于任务的距离值的阈值进行比较,并确定是否发生异常。该系统针对没有预设的异常模式而生成和收集的日志分析用户的任务行为,从而可以减少误报率或误报率。

著录项

  • 公开/公告号KR101810860B1

    专利类型

  • 公开/公告日2017-12-20

    原文格式PDF

  • 申请/专利权人 SAMO CNS CO. LTD.;

    申请/专利号KR20170091386

  • 发明设计人 KIM HYUN CHEOL;

    申请日2017-07-19

  • 分类号G06F21/62;G06F21/50;

  • 国家 KR

  • 入库时间 2022-08-21 12:41:24

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号