发明名称 System and method of fraud and misuse detection using event logs
摘要 A system and method are provided for detecting fraud and/or misuse of data in a computer environment through generating a rule for monitoring at least one of transactions and activities that are associated with the data. The rule can be generated based on one or more criteria related to the at least one of the transactions and the activities that is indicative of fraud or misuse of the data. The rule can be applied to the at least one of the transactions and the activities to determine if an event has occurred, where the event occurs if the at least one criteria has been met. A hit is stored in the event has occurred and a notification can be provided if the event has occurred. A compilation of hits related to the rule can be provided.
申请公布号 US9202189(B2) 申请公布日期 2015.12.01
申请号 US201314102017 申请日期 2013.12.10
申请人 FAIRWARNING IP, LLC 发明人 Long Kurt James
分类号 G06F21/44;G06Q10/06;G06F21/55;G06F21/50;G06F21/60;G06F21/31 主分类号 G06F21/44
代理机构 Hauptman Ham, LLP 代理人 Hauptman Ham, LLP
主权项 1. A method of detecting improper access of business information in a customer relationship management (CRM) computer environment, the method comprising: analyzing audit log data representing at least one of transactions or activities of an authorized user having access to the business information in the CRM computer environment, the business information including at least one of a customer record or a prospective customer record, to determine at least one of a number of accesses by the authorized user to the CRM computer environment or a time interval of access by the authorized user to the CRM computer environment; generating a rule for monitoring the analyzed audit log data, the rule comprising at least one criterion specifying at least one of a specific volume threshold of access by the authorized user to the CRM computer environment, or a predetermined time interval of access by the authorized user to the CRM computer environment; applying the rule to the analyzed audit log data to determine if an event has occurred, the event occurring if at least one of the number of accesses by the authorized user to the CRM computer environment exceeds an allowed access count corresponding to the specific volume threshold or the time interval of access by the authorized user to the CRM computer environment overlaps the predetermined time interval; storing, in a memory, a hit if the event has occurred; and providing notification if the event has occurred.
地址 Clearwater FL US