User behavior analytics for insider threat detection
US11611574B2 · kind B2 · utility
Assignee
Inventors
Key dates
| Filing date | Aug 2, 2017 |
| Grant date | Mar 21, 2023 |
| Priority date | — |
| Expiry date | Oct 26, 2038 |
Classification
- Technology area (CPC G)Physics
- CPC primaryG06F17/18
- WIPO fieldDigital communication
- WIPO sectorElectrical engineering
Abstract
Disclosed in some examples are systems, methods, and machine readable mediums for identifying insider threats by determining file system element activity models that correlate to undesirable behavior and then utilizing the determined model to detect insider threats. Events involving file system elements of a client computing device (e.g., a network endpoint) may be monitored by a file system element monitoring application on the client computing device. The values of these signals are aggregated across all events of the same type that have occurred within a predetermined time window (e.g., an hour) for a particular client computing device. Each time an aggregated signal has a value over the threshold, an anomaly is recorded. Anomaly counts for each signal are then calculated as the aggregate number of anomalies for a particular signal over a second time period, the span of which is determined by the generation of first anomaly to the close of an alert by the network monitor. The anomaly counts for the signals are then weighted and summed to produce a risk score.
Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.