Method for intrusion detection to detect malicious insider threat activities and system for intrusion detection

    公开(公告)号:US12058158B2

    公开(公告)日:2024-08-06

    申请号:US17869730

    申请日:2022-07-20

    申请人: BULL SAS

    IPC分类号: H04L9/40 H04L67/306 H04L67/50

    摘要: A method and system for intrusion detection to detect malicious insider threat activities within a network of user profiles. The method includes training a Neural Network on multiple sets of user profile data for multiple user profiles and on multiple sets of activity data of the multiple user profiles of the network, such that the Neural Network is capable of predicting for future dates activities for multiple user profiles. The method includes applying the trained Neural Network on the set of further user profile data of the further user profile, predicting an activity of the further user profile based on the multiple sets of activity data by the trained Neural Network, observing activity of the further user profile, applying the trained Neural Network on the observed activity, and detecting malicious activity for the further user profile by the trained Neural Network, if the observed activity deviates from the predicted activity.