Invention Grant
US09043905B1 System and method for insider threat detection 有权
内部威胁检测系统和方法

System and method for insider threat detection
Abstract:
Described is a system for detecting insider threats in a network. In detecting the insider threat, the system receives data from the network relevant to network activity and extracts observable actions from the data relevant to a mission. The observable actions are combined to provide contextual cues and reasoning results. Based on the observable actions and reasoning results, proposed security policy updates are proposed to force insiders into using more observable actions. Finally, the system detects potential insider threats through analyzing the observable actions and reasoning results.
Information query
Patent Agency Ranking
0/0