Invention Grant
- Patent Title: Insider threat detection utilizing user group data object access analysis
-
Application No.: US15673932Application Date: 2017-08-10
-
Publication No.: US10771496B2Publication Date: 2020-09-08
- Inventor: Guy Shtar , Shiri Margel
- Applicant: Imperva, Inc.
- Applicant Address: US CA Redwood City
- Assignee: Imperva, Inc.
- Current Assignee: Imperva, Inc.
- Current Assignee Address: US CA Redwood City
- Agency: Nicholson De Vos Webster & Elliott LLP
- Main IPC: G06F21/50
- IPC: G06F21/50 ; G06F21/55 ; H04L29/06 ; H04L29/08 ; H04W4/08

Abstract:
Techniques for detecting suspicious file access requests indicative of potential insider threats are described. A suspicious access detection module (SADM) determines, based on access data describing a access requests issued on behalf of multiple users, groups of the users having similar patterns of accesses to folders, a set of the folders accessed by each of the user groups, and ones of the user groups that are to be considered nearby others of the user groups based on having a threshold amount of folder access similarities. The SADM causes an alert to be generated responsive to a determination that a subsequent access request is suspicious because it accesses a file of a folder that is not within the set of accessed folders of the issuing user's user group, and because the folder is not within the sets of accessed folders of any nearby user groups.
Public/Granted literature
- US20190028504A1 INSIDER THREAT DETECTION UTILIZING USER GROUP DATA OBJECT ACCESS ANALYSIS Public/Granted day:2019-01-24
Information query