发明名称 Enterprise data access anomaly detection and flow tracking
摘要 Anomalous access activity is detected and managed. Access of enterprise data on multiple client computers is monitored and logged. The resulting log information identifies accessed units of enterprise data and corresponding access context. Log information concerning access of specific units of data on multiple client computers is received over a period of time and amalgamated. Statistical analysis is performed on amalgamated log information, thereby determining access baselines for data over the time period. Received log information concerning access of a specific unit of data on a specific client computer is compared to corresponding access baseline(s). Responsive to the comparison indicating that the access deviates from a baseline in excess of a threshold, the access is classified as being anomalous. Alerts are automatically output in response to detecting anomalous data access. Reports documenting data access activity on multiple client computers over time are generated, based on amalgamated log information.
申请公布号 US9298914(B1) 申请公布日期 2016.03.29
申请号 US201314095015 申请日期 2013.12.03
申请人 Symantec Corporation 发明人 McCorkendale Bruce
分类号 G06F21/55 主分类号 G06F21/55
代理机构 Patent Law Works LLP 代理人 Patent Law Works LLP
主权项 1. A computer implemented method for automatically monitoring access of enterprise data on a plurality of client computers, thereby detecting anomalous access activity and protecting against leakage of enterprise data, the method comprising the steps of: receiving log information from multiple ones of the plurality of client computers, log information received from a specific client computer identifying specific units of enterprise data accessed on the specific client computer and information concerning context in which the specific units were accessed; amalgamating received log information concerning access of specific units of enterprise data on multiple client computers over a period of time; performing statistical analysis on amalgamated log information received from multiple client computers and concerning access of specific units of enterprise data on multiple computers over time, thereby determining at least one access baseline concerning access of specific units of enterprise data on multiple computers over time for enterprise data over the period of time, by the computer, wherein the at least one baseline concerns geographic locations from which a specific unit of enterprise data is accessed over the period of time, based on amalgamated log information concerning access of the specific unit of enterprise data on multiple client computers; detecting an anomalous access of enterprise data as measured against at least one determined access baseline; and automatically outputting an alert documenting the detected anomalous access in response to detecting the anomalous access of enterprise data.
地址 Mountain View CA US
您可能感兴趣的专利