首页> 外国专利> DETECTING SUSPICIOUS FILE PROSPECTING ACTIVITY FROM PATTERNS OF USER ACTIVITY

DETECTING SUSPICIOUS FILE PROSPECTING ACTIVITY FROM PATTERNS OF USER ACTIVITY

机译:从用户活动模式中检测可疑文件的活动

摘要

Suspicious file prospecting activity is detected based on patterns of file system access. A user's file system access is monitored over a specific time period. A sequence of the file accesses (e.g., represented as path names) made by the user during the time period is recorded. Distances between the recorded file accesses are determined, for example as edit distances. A distance sequence is recorded, comprising a record of the determined distances. The distance sequence is reduced to one or more baseline statistics describing the pattern of the user's access of the file system during the given period of time. At least one subsequent anomaly in the user' s access of the file system is detected, by comparing at least one subsequently calculated statistic representing at least one subsequent pattern of the user's file system access to the at least one baseline statistic.
机译:根据文件系统访问的模式检测可疑文件探查活动。在特定时间段内监视用户的文件系统访问。记录用户在该时间段内进行的一系列文件访问(例如,表示为路径名)。确定记录的文件访问之间的距离,例如作为编辑距离。记录距离序列,包括确定距离的记录。距离序列减少为一个或多个基线统计数据,这些统计数据描述了给定时间段内用户对文件系统的访问模式。通过将代表用户文件系统访问的至少一种后续模式的至少一项随后计算的统计与至少一种基线统计进行比较,来检测用户对文件系统的访问中的至少一种后续异常。

著录项

  • 公开/公告号WO2017034668A1

    专利类型

  • 公开/公告日2017-03-02

    原文格式PDF

  • 申请/专利权人 SYMANTEC CORPORATION;

    申请/专利号WO2016US39910

  • 发明设计人 PARKER-WOOD ALEATHA;GARDNER ANDREW;

    申请日2016-06-28

  • 分类号G06F21/55;

  • 国家 WO

  • 入库时间 2022-08-21 13:31:55

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号