Invention Grant
- Patent Title: Insider threat detection
- Patent Title (中): 内部威胁检测
-
Application No.: US11790225Application Date: 2007-04-24
-
Publication No.: US08707431B2Publication Date: 2014-04-22
- Inventor: Gregory D. Stephens , Marcus A. Maloof
- Applicant: Gregory D. Stephens , Marcus A. Maloof
- Applicant Address: US VA McLean
- Assignee: The MITRE Corporation
- Current Assignee: The MITRE Corporation
- Current Assignee Address: US VA McLean
- Agency: Sterne, Kessler, Goldstein & Fox P.L.L.C.
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G08B21/00 ; H04L29/06

Abstract:
Methods, systems, and computer program products for insider threat detection are provided. Embodiments detect insiders who act on documents and/or files to which they have access but whose activity is inappropriate or uncharacteristic of them based on their identity, past activity, and/or organizational context. Embodiments work by monitoring the network to detect network activity associated with a set of network protocols; processing the detected activity to generate information-use events; generating contextual information associated with users of the network; and processing the information-use events based on the generated contextual information to generate alerts and threat scores for users of the network. Embodiments provide several information-misuse detectors that are used to examine generated information-use events in view of collected contextual information to detect volumetric anomalies, suspicious and/or evasive behavior. Embodiments provide a user threat ranking system and a user interface to examine user threat scores and analyze user activity.
Public/Granted literature
- US20080271143A1 Insider threat detection Public/Granted day:2008-10-30
Information query