Invention Grant
- Patent Title: Detecting unauthorized cloud access by detecting malicious velocity incidents
-
Application No.: US15962592Application Date: 2018-04-25
-
Publication No.: US10764303B2Publication Date: 2020-09-01
- Inventor: Yonatan Most , Shai Kaplan , Ido Bar Av
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Newport IP, LLC
- Agent David W. Foster
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F17/18 ; H04W12/08

Abstract:
Embodiments detect unauthorized access to cloud-based resources. One technique analyzes cloud-based events to distinguish potentially malicious velocity incidents from benign velocity incidents. A velocity incident occurs when the same user causes events from two geographically remote locations in a short time. Benign velocity incidents are distinguished from malicious velocity incidents by comparing an event with past events that have the same features. Embodiments probabilistically determine if a velocity incident is malicious or benign based on a weighted multi-feature analysis. For each feature of an event, a probability is calculated based on past events that have the same feature. Then, each feature is associated with a weight based on a relative frequency of past events having that feature. A weighted average of probabilities is calculated, and the resulting probability is compared to a defined threshold to determine if the velocity incident is likely malicious or benign.
Public/Granted literature
- US20190334923A1 DETECTING UNAUTHORIZED CLOUD ACCESS BY DETECTING MALICIOUS VELOCITY INCIDENTS Public/Granted day:2019-10-31
Information query