发明名称 SYSTEM AND METHOD FOR REAL-TIME DETECTION OF ANOMALIES IN DATABASE USAGE
摘要 A system and method for real-time detection of anomalies in database or application usage is disclosed. Embodiments provide a mechanism to detect anomalies in database or application usage, such as data exfiltration attempts, first by identifying correlations (e.g., patterns of normalcy) in events across different heterogeneous data streams (such as those associated with ordinary, authorized and benign database usage, workstation usage, user behavior or application usage) and second by identifying deviations/anomalies from these patterns of normalcy across data streams in real-time as data is being accessed. An alert is issued upon detection of an anomaly, wherein a type of alert is determined based on a characteristic of the detected anomaly.
申请公布号 WO2015191394(A1) 申请公布日期 2015.12.17
申请号 WO2015US34468 申请日期 2015.06.05
申请人 NORTHROP GRUMMAN SYSTEMS CORPORATION 发明人 STEINER, DONALD;DAY, JOHN
分类号 G06F21/50;G06F21/60 主分类号 G06F21/50
代理机构 代理人
主权项
地址
您可能感兴趣的专利