首页> 外国专利> Automated detection of session-based access anomalies in a computer network through processing of session data

Automated detection of session-based access anomalies in a computer network through processing of session data

机译:通过处理会话数据自动检测计算机网络中基于会话的访问异常

摘要

A processing device in one embodiment comprises a processor coupled to a memory and is configured to obtain data characterizing a plurality of network sessions for each of a plurality of user identifiers. The network sessions are initiated from a plurality of user devices over at least one network and may comprise respective virtual private network (VPN) sessions. The processing device is further configured to process the data characterizing the network sessions for a given one of the plurality of user identifiers to generate a network session profile for the given user identifier, the network session profile comprising a plurality of histograms for respective ones of a plurality of features extracted from the data characterizing the plurality of network sessions for the given user identifier. A risk score is generated for a current network session utilizing features extracted from the data characterizing that session and the network session profile.
机译:一个实施例中的处理设备包括耦合到存储器的处理器,并且被配置为针对多个用户标识符中的每一个获取表征表征多个网络会话的数据。网络会话是通过至少一个网络上的多个用户设备发起的,并且可以包括相应的虚拟专用网(VPN)会话。处理设备还被配置为针对多个用户标识符中的给定用户标识符来处理表征网络会话的数据,以生成用于该给定用户标识符的网络会话简档,该网络会话简档包括针对每个用户标识符的多个直方图。从数据中提取的多个特征表征了给定用户标识符的多个网络会话。利用从表征该会话和网络会话配置文件的数据中提取的特征为当前网络会话生成风险评分。

著录项

  • 公开/公告号US10003607B1

    专利类型

  • 公开/公告日2018-06-19

    原文格式PDF

  • 申请/专利权人 EMC CORPORATION;

    申请/专利号US201615079219

  • 发明设计人 EYAL KOLMAN;KINERET RAVIV;

    申请日2016-03-24

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 13:05:57

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号