Invention Grant
- Patent Title: Detection of slow brute force attacks based on user-level time series analysis
-
Application No.: US16869351Application Date: 2020-05-07
-
Publication No.: US11269978B2Publication Date: 2022-03-08
- Inventor: Dror Cohen , Jonatan Zukerman , Noa Esther Aviv Hamamy , Yossef Basha
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: Fiala & Weaver P.L.L.C.
- Main IPC: G06F21/00
- IPC: G06F21/00 ; G06F21/31 ; G06F21/55

Abstract:
Methods, systems and computer program products are provided for detection of slow brute force attacks based on user-level time series analysis. A slow brute force attack may be detected based on one or more anomalous failed login events associated with a user, alone or in combination with one or more post-login anomalous activities associated with the user, security alerts associated with the user, investigation priority determined for the user and/or successful logon events associated with the user. An alert may indicate a user is the target of a successful or unsuccessful slow brute force attack. Time-series data (e.g., accounted for in configurable time intervals) may be analyzed on a user-by-user basis to identify localized anomalies and global anomalies, which may be scored and evaluated (e.g., alone or combined with other information) to determine an investigation priority and whether and what alert to issue for a user.
Public/Granted literature
- US20210349979A1 DETECTION OF SLOW BRUTE FORCE ATTACKS BASED ON USER-LEVEL TIME SERIES ANALYSIS Public/Granted day:2021-11-11
Information query