首页> 外国专利> DETECTION OF SLOW BRUTE FORCE ATTACKS BASED ON USER-LEVEL TIME SERIES ANALYSIS

DETECTION OF SLOW BRUTE FORCE ATTACKS BASED ON USER-LEVEL TIME SERIES ANALYSIS

机译:基于用户级时间序列分析的慢蛮力攻击检测

摘要

Methods, systems and computer program products are provided for detection of slow brute force attacks based on user-level time series analysis. A slow brute force attack may be detected based on one or more anomalous failed login events associated with a user, alone or in combination with one or more post-login anomalous activities associated with the user, security alerts associated with the user, investigation priority determined for the user and/or successful logon events associated with the user. An alert may indicate a user is the target of a successful or unsuccessful slow brute force attack. Time-series data (e.g., accounted for in configurable time intervals) may be analyzed on a user-by-user basis to identify localized anomalies and global anomalies, which may be scored and evaluated (e.g., alone or combined with other information) to determine an investigation priority and whether and what alert to issue for a user.
机译:提供了基于用户级时间序列分析的慢蛮力攻击的方法,系统和计算机程序产品。 可以基于与用户关联的一个或多个异常失败的登录事件来检测慢的蛮力攻击,单独或与与用户相关联的一个或多个登录后异常活动,与用户相关联的安全警报,确定的调查优先级 对于与用户关联的用户和/或成功登录事件。 警报可以指示用户是成功或不成功慢蛮力攻击的目标。 可以在用户的基础上分析时间序列数据(例如,以可配置的时间间隔计算)以识别本地化异常和全局异常,可以被评估和评估(例如,单独或与其他信息组合) 确定调查优先级以及是否为用户发出警报。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号