Invention Grant
- Patent Title: Network session based user behavior pattern analysis and associated anomaly detection and verification
-
Application No.: US15155475Application Date: 2016-05-16
-
Publication No.: US10341391B1Publication Date: 2019-07-02
- Inventor: Shikhar Pandey , Kartikeya Putturaya , Chandra Sekar Rao Munaganuri Venkata , Gupta Abhishek
- Applicant: EMC Corporation
- Applicant Address: US MA Hopkinton
- Assignee: EMC IP Holding Company LLC
- Current Assignee: EMC IP Holding Company LLC
- Current Assignee Address: US MA Hopkinton
- Agency: Ryan, Mason & Lewis, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L29/08 ; G06F21/57

Abstract:
A processing device in one embodiment comprises a processor coupled to a memory and is configured to obtain data characterizing a plurality of network sessions for a given user identifier. The network sessions are initiated from one or more user devices over at least one network and may comprise respective virtual private network (VPN) sessions. The processing device is further configured to extract features from the obtained data, to detect at least one potentially anomalous network session among the plurality of network sessions for the given user identifier by applying the extracted features to a support vector machine model, and to apply a rules-based verification process to the detected potentially anomalous network session in order to verify that the detected potentially anomalous network session is an anomalous network session. An alert is generated based on a result of the rules-based verification process and transmitted to a security agent.
Information query