System, method, and computer program product for detecting and assessing security risks in a network

    公开(公告)号:US10803183B2

    公开(公告)日:2020-10-13

    申请号:US16657010

    申请日:2019-10-18

    申请人: Exabeam, Inc.

    IPC分类号: G06F21/57 H04L29/06

    摘要: The present disclosure is directed to a system, method, and computer program for detecting and assessing security risks in an enterprise's computer network. A behavior model is built for a user in the network based on the user's interactions with the network, wherein a behavior model for a user indicates client device(s), server(s), and resources used by the user. The user's behavior during a period of time is compared to the user's behavior model. A risk assessment is calculated for the period of time based at least in part on the comparison between the user's behavior and the user's behavior model, wherein any one of certain anomalies between the user's behavior and the user's behavior model increase the risk assessment.

    SYSTEM, METHOD, AND COMPUTER PROGRAM PRODUCT FOR DETECTING AND ASSESSING SECURITY RISKS IN A NETWORK

    公开(公告)号:US20190034641A1

    公开(公告)日:2019-01-31

    申请号:US16150604

    申请日:2018-10-03

    申请人: Exabeam, Inc.

    IPC分类号: G06F21/57 H04L29/06

    摘要: The present disclosure is directed to a system, method, and computer program for detecting and assessing security risks in an enterprise's computer network. A behavior model is built for a user in the network based on the user's interactions with the network, wherein a behavior model for a user indicates client device(s), server(s), and resources used by the user. The user's behavior during a period of time is compared to the user's behavior model. A risk assessment is calculated for the period of time based at least in part on the comparison between the user's behavior and the user's behavior model, wherein any one of certain anomalies between the user's behavior and the user's behavior model increase the risk assessment.

    System, method, and computer program product for detecting and assessing security risks in a network

    公开(公告)号:US10474828B2

    公开(公告)日:2019-11-12

    申请号:US16150604

    申请日:2018-10-03

    申请人: Exabeam, Inc.

    IPC分类号: G06F21/57 H04L29/06

    摘要: The present disclosure is directed to a system, method, and computer program for detecting and assessing security risks in an enterprise's computer network. A behavior model is built for a user in the network based on the user's interactions with the network, wherein a behavior model for a user indicates client device(s), server(s), and resources used by the user. The user's behavior during a period of time is compared to the user's behavior model. A risk assessment is calculated for the period of time based at least in part on the comparison between the user's behavior and the user's behavior model, wherein any one of certain anomalies between the user's behavior and the user's behavior model increase the risk assessment.