Invention Grant
- Patent Title: Threat detection using machine learning query analysis
-
Application No.: US16451170Application Date: 2019-06-25
-
Publication No.: US12001548B2Publication Date: 2024-06-04
- Inventor: Liron Ben Kimon , Yuri Shafet
- Applicant: PAYPAL, INC.
- Applicant Address: US CA San Jose
- Assignee: PAYPAL, INC.
- Current Assignee: PAYPAL, INC.
- Current Assignee Address: US CA San Jose
- Agency: Haynes and Boone, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F16/245 ; G06F21/55 ; G06N20/00

Abstract:
Within an organization, numerous different persons can access data. But a user account with database access may be compromised, leading to data theft and data destruction. Database queries used to access data may vary in length, content, and formatting. Features of these queries can be extracted to train a machine learning classifier. Queries for users can be mapped to a vector space and when a new sample query is received, it can be assessed using the classifier to determine its level of similarity with previous queries by that user and other users. By analyzing the results of this assessment on the new query, it can be determined if this new query represents a data access anomaly—e.g. a particularly unusual query for a user, given his or her past, that may indicate user credentials have been compromised. When a data access anomaly exists, a remedial action may be take.
Information query