首页> 外国专利> Anomaly detection based on profile history and peer history

Anomaly detection based on profile history and peer history

机译:基于配置文件历史记录和对等体历史记录的异常检测

摘要

A method and apparatus for automatic anomaly detection based on profile history and peer history are described. An anomaly detection system collects file-activity data pertaining to file accesses activities in a network share. The system computes file access patterns for the individual users and compares the individual user's file access pattern against a profile history to find a first deviation. The system also identifies a cluster of users from the group based on at least one of user collaborations of individual users of the group or a reporting structure of the group of users. When the first deviation is found, the system compares the user's file access pattern against a peer history of the other individual users in the cluster to find a second deviation. The system reports an anomaly in the file access patterns by the individual user when the first deviation and the second deviation are found.
机译:描述了用于基于简档历史和对等历史的自动异常检测的方法和设备。异常检测系统收集与网络共享中的文件访问活动有关的文件活动数据。该系统计算单个用户的文件访问模式,并将单个用户的文件访问模式与配置文件历史进行比较以找到第一偏差。该系统还基于该组的单个用户的用户协作或该用户组的报告结构中的至少一个来识别来自该组的用户群。当找到第一个偏差时,系统会将用户的文件访问模式与集群中其他单个用户的对等历史记录进行比较,以找到第二个偏差。当发现第一偏差和第二偏差时,系统报告单个用户的文件访问模式中的异常。

著录项

  • 公开/公告号US9166993B1

    专利类型

  • 公开/公告日2015-10-20

    原文格式PDF

  • 申请/专利权人 SYMANTEC CORPORATION;

    申请/专利号US201313950744

  • 发明设计人 YIN LIU;

    申请日2013-07-25

  • 分类号H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 15:22:04

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号