Invention Grant
- Patent Title: System and method for insider threat detection
- Patent Title (中): 内部威胁检测系统和方法
-
Application No.: US14044793Application Date: 2013-10-02
-
Publication No.: US09043905B1Publication Date: 2015-05-26
- Inventor: David L. Allen , Tsai-Ching Lu , Eric P. Tressler , Hankyu Moon
- Applicant: HRL Laboratories, LLC
- Applicant Address: US CA Malibu
- Assignee: HRL Laboratories, LLC
- Current Assignee: HRL Laboratories, LLC
- Current Assignee Address: US CA Malibu
- Agency: Tope-McKay & Associates
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/57 ; G06F12/14 ; G06F12/16

Abstract:
Described is a system for detecting insider threats in a network. In detecting the insider threat, the system receives data from the network relevant to network activity and extracts observable actions from the data relevant to a mission. The observable actions are combined to provide contextual cues and reasoning results. Based on the observable actions and reasoning results, proposed security policy updates are proposed to force insiders into using more observable actions. Finally, the system detects potential insider threats through analyzing the observable actions and reasoning results.
Information query