Patent · US Active

User session-based generation of logical graphs and detection of anomalies

US11689553B1 · kind B1 · utility

3Cited by
134References
18Claims
0Family size

Assignee

Inventors

Key dates

Filing dateMar 9, 2021
Grant dateJun 27, 2023
Priority date
Expiry dateAug 14, 2041

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F16/2456
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Log data associated with at least one user session in a network environment associated with an original user is received. A logical graph is generated using at least a portion of the received log data. One example of such a logical graph is a privilege change graph that models privilege changes between processes. Another example of such a logical graph is a user login graph that models machines with which the original user interacts. Another example of such a logical graph is a machine-server graph that clusters machines into nodes based on resources executing on the machine. The generated logical graph is used to detect an anomaly.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.