Invention Grant
- Patent Title: Network activity monitoring method and apparatus
-
Application No.: US14963851Application Date: 2015-12-09
-
Publication No.: US10270790B1Publication Date: 2019-04-23
- Inventor: Gary M Jackson
- Applicant: Anbeco, LLC
- Applicant Address: US MD Pasadena
- Assignee: Anbeco, LLC
- Current Assignee: Anbeco, LLC
- Current Assignee Address: US MD Pasadena
- Agency: Edwards Neils LLC
- Agent Jean C. Edwards, Esq.
- Main IPC: G06N5/02
- IPC: G06N5/02 ; H04L29/06

Abstract:
The present invention relates to an insider threat detection system which includes at least two stages: a front end sensor stage with activity detection from detectors, and a behavior reasoning component (BRC) with following automated reporting. As opposed to typical monitoring systems that seek to identify network activities as endpoint activities, work on a small number of static triggered rules or anomalous deviations from established norms, the present invention includes a behavior reasoning component (BRC) that uses network activity as precursor indicators to subsequent malicious or non-malicious behaviors, using BRC pattern classifiers, to predict likely malicious insider behaviors and alert security personnel to insider threat from high probability sabotage, fraud, or theft of sensitive, proprietary, classified data/information.
Information query