Invention Grant
- Patent Title: Automatically detecting insider threats using user collaboration patterns
-
Application No.: US15629421Application Date: 2017-06-21
-
Publication No.: US10341373B2Publication Date: 2019-07-02
- Inventor: Sandeep Bhatkar , Saurabh Shintre , Ashwin Kayyoor
- Applicant: SYMANTEC CORPORATION
- Applicant Address: US CA Mountain View
- Assignee: SYMANTEC CORPORATION
- Current Assignee: SYMANTEC CORPORATION
- Current Assignee Address: US CA Mountain View
- Agency: Maschoff Brennan
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Automatically detecting insider threats using user collaboration patterns. In one embodiment, a method may include identifying collaborative access of one or more network resources in a network between a target user using a target network device and other users using other network devices in the network during multiple prior time periods and during a current time period, generating prior collaboration graphs for the prior time periods, generating an average collaboration graph by combining the prior collaboration graphs, generating a current collaboration graph for the current time period, generating an anomaly score by comparing the current collaboration graph to the average collaboration graph, determining that the collaborative access of the one or more network resources during the current time period is anomalous by determining that the anomaly score exceeds a threshold, and, in response to the anomaly score exceeding the threshold, performing a security action on the target network device.
Public/Granted literature
- US20180375883A1 AUTOMATICALLY DETECTING INSIDER THREATS USING USER COLLABORATION PATTERNS Public/Granted day:2018-12-27
Information query