Invention Grant
- Patent Title: Computer-implemented method for determining computer system security threats, security operations center system and computer program product
-
Application No.: US15571934Application Date: 2015-09-23
-
Publication No.: US10681060B2Publication Date: 2020-06-09
- Inventor: Balazs Scheidler , Marton Illes
- Applicant: BALABIT S.A.
- Applicant Address: LU Senningerberg
- Assignee: BALABIT S.A.
- Current Assignee: BALABIT S.A.
- Current Assignee Address: LU Senningerberg
- Agency: Maschoff Brennan
- International Application: PCT/EP2015/071866 WO 20150923
- International Announcement: WO2016/177437 WO 20161110
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06N20/00 ; G06F21/56 ; G06F21/57 ; G06F21/55 ; G06Q10/06

Abstract:
A computer-implemented method for determining computer system security threats, the computer system including user accounts established on the computer system, the method including the steps of: (i) for a plurality of user accounts, assigning a risk level to each account; (ii) in a time interval, for a plurality of events, wherein each event is linked to a respective user account, assigning an event score relating to deviation from normal behavior of each event with respect to the respective user account; (iii) in the time interval, for the plurality of events, calculating an event importance which is a function of the respective event score and the respective user account risk level; (iv) prioritizing the plurality of events by event importance, and (v) providing a record of the plurality of events, prioritized by event importance.
Public/Granted literature
Information query