首页> 外国专利> Methods for user profiling for detecting insider threats based on internet search patterns and forensics of search keywords

Methods for user profiling for detecting insider threats based on internet search patterns and forensics of search keywords

机译:基于互联网搜索模式和搜索关键词取证的用户配置文件检测内部威胁的方法

摘要

Disclosed are methods for user profiling for detecting insider threats including the steps of: upon a client application sending a request for a link, extracting at least one search keyword from a search session associated with the request; classifying the link into at least one classification; determining whether at least one classification is a monitored classification; capturing search elements of search sessions associated with the monitored classification; acquiring usage data from the search elements to create a user profile associated with a user's search behavior; and performing a statistical analysis, on a search frequency for the monitored classification, on user profiles associated with many users. Preferably, the method includes: designating a profile as suspicious based on the statistical analysis exceeding a pre-determined threshold value, wherein the pre-determined threshold value is based on an expected search frequency for the profile and each respective grade for at least one risk-assessment dimension.
机译:公开了用于用户分析以检测内部威胁的方法,包括以下步骤:在客户端应用发送对链接的请求之后,从与该请求相关联的搜索会话中提取至少一个搜索关键字;将链接分类为至少一种分类;确定至少一个分类是否是受监视的分类;捕获与监视的分类关联的搜索会话的搜索元素;从搜索元素中获取使用数据,以创建与用户的搜索行为相关的用户资料;并针对与许多用户相关联的用户个人资料,针对监视的分类的搜索频率执行统计分析。优选地,所述方法包括:基于超过预定阈值的统计分析将简档指定为可疑的,其中,所述预定阈值基于针对所述简档的期望搜索频率以及针对至少一个风险的每个相应等级。评估维度。

著录项

  • 公开/公告号US8375452B2

    专利类型

  • 公开/公告日2013-02-12

    原文格式PDF

  • 申请/专利权人 GIL RAVIV;

    申请/专利号US20080344229

  • 发明设计人 GIL RAVIV;

    申请日2008-12-25

  • 分类号G06F11/00;

  • 国家 US

  • 入库时间 2022-08-21 16:45:16

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号