- Patent Title: Clustering for detection of anomalous behavior and insider threat
-
Application No.: US15619598Application Date: 2017-06-12
-
Publication No.: US10341372B2Publication Date: 2019-07-02
- Inventor: Suresh Chari , Benjamin Edwards , Taesung Lee , Ian M. Molloy
- Applicant: International Business Machines Corporation
- Applicant Address: US NY Armonk
- Assignee: International Business Machines Corporation
- Current Assignee: International Business Machines Corporation
- Current Assignee Address: US NY Armonk
- Agency: Yee & Associates, P.C.
- Agent Jeffrey LaBaw
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
Detecting anomalous user behavior is provided. User activity is logged for a set of users. The user activity is divided into distinct time intervals. For each distinct time interval, logged user activity is converted to a numerical representation of each user's activities for that distinct time interval. A clustering process is used on the numerical representations of user activities to determine which users have similar activity patterns in each distinct time interval. A plurality of peer groups of users is generated based on determining the similar activity patterns in each distinct time interval. Anomalous user behavior is detected based on a user activity change in a respective peer group of users within a distinct time interval.
Public/Granted literature
- US20180359270A1 Clustering for Detection of Anomalous Behavior and Insider Threat Public/Granted day:2018-12-13
Information query