Invention Grant
- Patent Title: Identifying changes in use of user credentials
-
Application No.: US15694891Application Date: 2017-09-04
-
Publication No.: US10686829B2Publication Date: 2020-06-16
- Inventor: Idan Amit , Eyal Firstenberg , Jonathan Allon , Yaron Neuman
- Applicant: Palo Alto Networks (Israel Analytics) Ltd
- Applicant Address: IL Tel Aviv
- Assignee: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
- Current Assignee: PALO ALTO NETWORKS (ISRAEL ANALYTICS) LTD.
- Current Assignee Address: IL Tel Aviv
- Agency: Kligler & Associates Patent Attorneys Ltd
- Main IPC: G06F11/00
- IPC: G06F11/00 ; H04L29/06 ; G06N5/04 ; G06N20/00 ; G06F21/55 ; G06F12/14

Abstract:
A method including extracting, from initial data transmitted on a network, multiple events, each of the events including a user accessing a resource. First and second sets of records are created, each first set record including a sub-group of the events of a user, each second set record including a sub-group of the events of a multiple users during respective sub-periods of a training period. Safe labels are assigned to the first set records and suspicious labels are assigned to the second set records. An analysis fits, to the first and the second set records and their respective labels, a model for predicting the label for a given record. The model filters subsequent network data to identify, in the subsequent data, sequences of events predicted to be labeled suspicious by the model, and upon detecting a given sequence of events predicted as suspicious by the model, an alert is generated.
Public/Granted literature
- US20180069893A1 Identifying Changes in Use of User Credentials Public/Granted day:2018-03-08
Information query