发明名称 SYSTEMS AND METHODS FOR DETECTING MALICIOUS INSIDERS USING EVENT MODELS
摘要 Systems and methods are disclosed for determining whether a mission has occurred. The disclosed systems and methods utilize event models that represent a sequence of tasks that an entity could or must take in order to successfully complete the mission. As a specific example, an event model may represent the sequence of tasks a malicious insider may complete in order to exfiltrate sensitive information. Most event models include certain tasks that must be accomplished in order for the insider to successfully exfiltrate an organization's sensitive information. Many of the observable tasks in the attack models can be monitored using relatively little information, such as the source, time, and type of the communication. The monitored information is utilized in a traceback search through the event model for occurrences of the tasks of the event model to determine whether the mission that the event model represents occurred.
申请公布号 US2013019309(A1) 申请公布日期 2013.01.17
申请号 US201113181204 申请日期 2011.07.12
申请人 RAYTHEON BBN TECHNOLOGIES CORP.;STRAYER WILLIAM TIMOTHY;PARTRIDGE CRAIG;JACKSON ALDEN WARREN;POLIT STEPHEN HENRY 发明人 STRAYER WILLIAM TIMOTHY;PARTRIDGE CRAIG;JACKSON ALDEN WARREN;POLIT STEPHEN HENRY
分类号 G06F21/00;G06N5/02 主分类号 G06F21/00
代理机构 代理人
主权项
地址