发明名称 INSIDER THREAT DETECTION
摘要 Methods, systems, and computer program products for insider threat detection are provided. Embodiments detect insiders who act on documents and/or files to which they have access but whose activity is inappropriate or uncharacteristic of them based on their identity, past activity, and/or organizational context. Embodiments work by monitoring the network to detect network activity associated with a set of network protocols; processing the detected activity to generate information-use events; generating contextual information associated with users of the network; and processing the information-use events based on the generated contextual information to generate alerts and threat scores for users of the network. Embodiments provide several information-misuse detectors that are used to examine generated information-use events in view of collected contextual information to detect volumetric anomalies, suspicious and/or evasive behavior. Embodiments provide a user threat ranking system and a user interface to examine user threat scores and analyze user activity.
申请公布号 EP2137620(A4) 申请公布日期 2011.03.30
申请号 EP20080724891 申请日期 2008.01.29
申请人 THE MITRE CORPORATION 发明人 STEPHENS, GREGORY, D.;MALOOF, MARCUS, A.
分类号 G06F11/00 主分类号 G06F11/00
代理机构 代理人
主权项
地址