发明名称 USER ACTIVITY MONITORING
摘要 Systems and methods are disclosed for associating an entity with a risk score that may indicate a security threat associated with the entity's activity. An exemplary method may involve monitoring the activity of a subset of the set of entities (e.g., entities included in a watch list) by executing a search query against events indicating the activity of the subset of entities. The events may be associated with timestamps and may include machine data. Executing the search query may produce search results that pertain to activity of a particular entity from the subset. The search results may be evaluated based on a triggering condition corresponding to the statistical baseline. When the triggering condition is met, a risk score for the particular entity may be updated. The updated risk score may be displayed to a user via a graphical user interface (GUI).
申请公布号 US2016306965(A1) 申请公布日期 2016.10.20
申请号 US201514691535 申请日期 2015.04.20
申请人 Splunk Inc. 发明人 Iyer Ravi;Badhani Devendra;Chauhan Vijay
分类号 G06F21/55;G06F17/30 主分类号 G06F21/55
代理机构 代理人
主权项 1. A method comprising: identifying, from a set of entities to be monitored, a subset of the set of entities for additional monitoring; performing the additional monitoring by accessing a scoring rule that defines a search query and a risk modifier, the risk modifier indicative of an amount by which to adjust a risk score of a particular entity when a triggering condition is satisfied;after said accessing the scoring rule, executing the search query against a plurality of events associated with the activity of the subset of set of entities, wherein the search query produces a search result pertaining to activity of the particular entity, wherein each event of the plurality of events is associated with a timestamp and includes machine data;determining whether the search result meets the triggering condition; andresponsive to determining that the search result meets the triggering condition, updating the risk score for the particular entity based on the risk modifier in the scoring rule, the risk score indicating a security threat associated with activity of the particular entity; and causing at least one of: display of an indication of the updated risk score, transmission of an indication of the updated risk score, or remedial action based on the updated risk score.
地址 San Francisco CA US
您可能感兴趣的专利