Invention Grant
- Patent Title: Detecting anomalous accounts using event logs
-
Application No.: US15672025Application Date: 2017-08-08
-
Publication No.: US09910727B2Publication Date: 2018-03-06
- Inventor: Jennifer Lemond , Haoyang Duan , Xiaoming Wang
- Applicant: Microsoft Technology Licensing, LLC
- Applicant Address: US WA Redmond
- Assignee: Microsoft Technology Licensing, LLC
- Current Assignee: Microsoft Technology Licensing, LLC
- Current Assignee Address: US WA Redmond
- Agency: International IP Law Group, PLLC
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F11/07 ; G06F21/55 ; G06F21/31 ; G06F21/41

Abstract:
The claimed subject matter includes techniques for detecting anomalous accounts. An example method includes receiving, via a processor, a list of monitored machines and event logs including logons for the list of monitored machines for a predetermined window of time. The example method also includes generating, via the processor, a baseline based on the event logs for the predetermined window of time. The example method also includes collecting, via the processor, daily logon events after the predetermined time and comparing the daily logon events to the baseline. The method further includes detecting, via the processor, an anomalous account based on a difference of logon events of the anomalous account from the baseline. The method also includes displaying, via the processor, the detected anomalous account.
Public/Granted literature
- US20170344415A1 DETECTING ANOMALOUS ACCOUNTS USING EVENT LOGS Public/Granted day:2017-11-30
Information query