首页> 外国专利> Detection of anomalous administrative actions

Detection of anomalous administrative actions

机译:检测异常的行政行为

摘要

A method for monitoring includes defining a plurality of different types of administrative activities in a computer system. Each administrative activity in the plurality includes an action performed by one of the computers in the system that can be invoked only by a user having an elevated level of privileges in the system. The administrative activities performed by at least a group of the computers in the system are tracked automatically. Upon detecting that a given computer in the system has performed an anomalous combination of at least two of the different types of administrative activities, an action is initiated to inhibit malicious exploitation of the given computer.
机译:一种监视方法,包括在计算机系统中定义多种不同类型的管理活动。多个管理活动中的每个管理活动都包括由系统中的计算机之一执行的操作,该操作只能由系统中具有较高特权级别的用户调用。自动跟踪系统中至少由一组计算机执行的管理活动。在检测到系统中的给定计算机已执行了至少两种不同类型的管理活动的异常组合后,将启动操作来禁止对该给定计算机的恶意利用。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号