Invention Grant
- Patent Title: Method for recognizing information flow and detecting information leakage by analyzing user's behaviors
- Patent Title (中): 通过分析用户行为识别信息流和检测信息泄漏的方法
-
Application No.: US12039930Application Date: 2008-02-29
-
Publication No.: US08181224B2Publication Date: 2012-05-15
- Inventor: Cheolho Lee , Kiwook Sohn
- Applicant: Cheolho Lee , Kiwook Sohn
- Applicant Address: KR Daejeon
- Assignee: Electronics and Telecommunications Research Institute
- Current Assignee: Electronics and Telecommunications Research Institute
- Current Assignee Address: KR Daejeon
- Agency: Ladas & Parry LLP
- Priority: KR10-2007-0059904 20070619
- Main IPC: G06F7/04
- IPC: G06F7/04

Abstract:
A method for analyzing user's behaviors is provided. API function call patterns occurring when operations on various objects are performed on a computer system are configured with contexts. User's behaviors are recognized as associations between the contexts and systematically expressed. Information flow occurring in the user's behaviors (i.e., associations between the contexts) is tracked. The information flow chain is divided into a source and a destination. When the information flow a confidential object to a leakage point occurs, the information leakage is rapidly detected and blocked. By exactly recognizing behaviors belonging to the corresponding information flow chain, user's behaviors related to the information leakage can be detected. Furthermore, the behavior expression based on the contexts configured with the API function call patterns with respect to the system object can be achieved by naturally connecting the API function call occurring on the system as an abstract behavior.
Public/Granted literature
- US20080320556A1 METHOD FOR RECOGNIZING INFORMATION FLOW AND DETECTING INFORMATION LEAKAGE BY ANALYZING USER'S BEHAVIORS Public/Granted day:2008-12-25
Information query