Invention Grant
- Patent Title: Intrusion detection based on anomalies in access patterns
-
Application No.: US16119339Application Date: 2018-08-31
-
Publication No.: US10885167B1Publication Date: 2021-01-05
- Inventor: Shir Meir Lador , Gleb Keselman , Noa Haas , Liron Hayman , Yaron Sheffer , Tzvika Barenholz , Noah Eyal Altman , Shimon Shahar , Asaf Brill
- Applicant: Shir Meir Lador , Gleb Keselman , Noa Haas , Liron Hayman , Yaron Sheffer , Tzvika Barenholz , Noah Eyal Altman , Shimon Shahar , Asaf Brill
- Applicant Address: IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon
- Assignee: Shir Meir Lador,Gleb Keselman,Noa Haas,Liron Hayman,Yaron Sheffer,Tzvika Barenholz,Noah Eyal Altman,Shimon Shahar,Asaf Brill
- Current Assignee: Shir Meir Lador,Gleb Keselman,Noa Haas,Liron Hayman,Yaron Sheffer,Tzvika Barenholz,Noah Eyal Altman,Shimon Shahar,Asaf Brill
- Current Assignee Address: IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon; IL Hod HaSharon
- Agency: Ferguson Braswell Fraser Kubasta PC
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/31 ; G06N5/04 ; G06F21/55 ; G06N20/00

Abstract:
A method for detecting an unauthorized activity on a computer system involves obtaining current time stamps for a first type of access event related to the computer system, determining a current count of the first type of access event using the current time stamps, and predicting an expected count of the first type of access event using a current count of time stamps and a predictive model. The method further involves obtaining an actual count of the first type of access event, executing a first comparison of the actual count with the expected count, determining, based on a test comprising the first comparison, that the unauthorized access to the computer system occurred, and issuing an alert indicating the unauthorized activity occurred.
Information query