发明名称 METHODS FOR USER PROFILING FOR DETECTING INSIDER THREATS BASED ON INTERNET SEARCH PATTERNS AND FORENSICS OF SEARCH KEYWORDS
摘要 Disclosed are methods for user profiling for detecting insider threats including the steps of: upon a client application sending a request for a link, extracting at least one search keyword from a search session associated with the request; classifying the link into at least one classification; determining whether at least one classification is a monitored classification; capturing search elements of search sessions associated with the monitored classification; acquiring usage data from the search elements to create a user profile associated with a user's search behavior; and performing a statistical analysis, on a search frequency for the monitored classification, on user profiles associated with many users. Preferably, the method includes: designating a profile as suspicious based on the statistical analysis exceeding a pre-determined threshold value, wherein the pre-determined threshold value is based on an expected search frequency for the profile and each respective grade for at least one risk-assessment dimension.
申请公布号 US2010169971(A1) 申请公布日期 2010.07.01
申请号 US20080344229 申请日期 2008.12.25
申请人 CHECK POINT SOFTWARE TECHNOLOGIES, LTD. 发明人 RAVIV GIL
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址