Patent · US Active

Real-time mitigation of data access insider intrusions

US7673147B2 · kind B2 · utility

25Cited by
4References
12Claims
0Family size

Assignee

Inventors

Key dates

Filing dateSep 24, 2004
Grant dateMar 2, 2010
Priority date
Expiry dateSep 2, 2028

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/1416
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

The present invention provides a policy specification framework to enable an enterprise to specify a given insider attack using a holistic view of a given data access, as well as the means to specify and implement one or more intrusion mitigation methods in response to the detection of such an attack. The policy specification provides for the use of “anomaly” and “signature” attributes that capture sophisticated behavioral characteristics of illegitimate data access. When the attack occurs, a previously-defined administrator (or system-defined) mitigation response (e.g., verification, disconnect, de-provision, network re-routing, or the like) is then implemented.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.