Patent · US Active

System, method, and computer program for detection of anomalous user network activity based on multiple data sources

US10645109B1 · kind B1 · utility

21Cited by
24References
28Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMar 29, 2018
Grant dateMay 5, 2020
Priority date
Expiry dateDec 13, 2038

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06N5/04
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

The present disclosure relates a system, method, and computer program for detecting anomalous user network activity based on multiple data sources. The system extracts user event data for n days from multiple data sources to create a baseline behavior model that reflects the user's daily volume and type of IT events. In creating the model, the system addresses data heterogeneity in multi-source logs by categorizing raw events into meta events. Thus, baseline behavior model captures the user's daily meta-event pattern and volume of IT meta events over n days. The model is created using a dimension reduction technique. The system detects any anomalous pattern and volume changes in a user's IT behavior on day n by comparing user meta-event activity on day n to the baseline behavior model. A score normalization scheme allows identification of a global threshold to flag current anomalous activity in the user population.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.