首页> 外国专利> SYSTEM FOR DETECTING ABNOMAL BEHAVIORS USING PERSONALIZED EARLY USE BEHAVIOR PATTERN ANALSIS

SYSTEM FOR DETECTING ABNOMAL BEHAVIORS USING PERSONALIZED EARLY USE BEHAVIOR PATTERN ANALSIS

机译:个性化的早期使用行为模式分析检测异常行为的系统

摘要

The present invention relates to a system for detecting an abnormal behavior, which detects an abnormal use behavior of a user in a bring your own device (BYOD) environment and a smart work environment. The system includes: a contextual information receiving unit which receives various kinds of contextual information from a contextual information collecting system; a contextual information processing unit which generates, when the contextual information about web service use is received, a detection requesting message according to the contextual information and transmits the detection requesting message to an abnormality detecting unit; the abnormality detecting unit which detects, when the detection requesting message is received, the abnormal use behavior by comparing the order of pages used immediately after user access and use speed with a pattern at the time of past access by using an early use behavior pattern analysis; a profile managing unit which profiles, stores and manages pieces of the contextual information according to the various use behaviors of the user; and an information analyzing unit which analyzes information on use of a website or a DB based on the received pieces of the contextual information. Unlike an existing network based security device by using a network traffic analysis, the present invention has realized a measure to detect the abnormal behavior by patterning behaviors based on various behavioral elements such as time, positions, access networks, used devices, etc. of a target object. The system for detecting the abnormal behavior according to the present invention is for promoting system security in the BYOD environment and the smart work environment and detects the behaviors including abnormal access and use, etc. of a terminal device by using the personalized early use behavior pattern analysis after processing the contextual information into access, use and agent contextual information and profile information.
机译:本发明涉及一种用于检测异常行为的系统,该系统在自带设备(BYOD)环境和智能工作环境中检测用户的异常使用行为。该系统包括:上下文信息接收单元,其从上下文信息收集系统接收各种上下文信息;以及上下文信息处理单元,其在接收到关于网络服务使用的上下文信息时,根据所述上下文信息生成检测请求消息,并将所述检测请求消息发送给异常检测单元;异常检测单元,当接收到检测请求消息时,通过使用早期使用行为模式分析,通过将用户访问后立即使用的页面的顺序和使用速度与过去访问时的模式进行比较,来检测异常使用行为;简档管理单元,其根据用户的各种使用行为来简档,存储和管理多条上下文信息;信息分析单元,基于接收到的上下文信息来分析有关使用网站或数据库的信息。与通过使用网络流量分析的现有的基于网络的安全设备不同,本发明已经实现了一种通过基于各种行为元素(例如时间,位置,接入网络,使用的设备等)来对行为进行模式化来检测异常行为的措施。目标对象。根据本发明的异常行为检测系统用于提高BYOD环境和智能工作环境中的系统安全性,并通过使用个性化的早期使用行为模式来检测终端设备的异常访问和使用等行为。在将上下文信息处理为访问,使用和代理上下文信息和配置文件信息之后进行分析。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号