Detecting presence of a subject string in a target string and security event qualification based on prior behavior by an end user of a computer system
    1.
    发明授权
    Detecting presence of a subject string in a target string and security event qualification based on prior behavior by an end user of a computer system 有权
    基于计算机系统的最终用户的先前行为来检测目标字符串中的主题字符串的存在和安全事件限定

    公开(公告)号:US08321958B1

    公开(公告)日:2012-11-27

    申请号:US12511307

    申请日:2009-07-29

    CPC classification number: G06F21/51 G06F17/30867

    Abstract: A software-based security agent that hooks into the operating system of a computer device in order to continuously audit the behavior and conduct of the end user of the computer device. The detected actions of the end user can be stored in a queue or log file that can be continuously monitored to detect patterns of behavior that may constitute a policy violation and/or security risk. When a pattern of behavior that may constitute a policy violation and/or security risk is detected, an event may be triggered. A frequency vector string matching algorithm also is disclosed. The frequency vector string matching algorithm may be used to detect the presence or partial presence of subject strings within a target string of alphanumeric characters. The frequency vector string matching algorithm could be used to detect typos in stored computer records or to search for records based on partial information. In addition, the frequency vector string matching algorithm could be used to search communications for sensitive information that has been manipulated, obscured, or partially elided. In addition, an anomaly analysis is disclosed for comparing behavior patterns of one user against the behavior patterns of other users to detect anomalous behaviors.

    Abstract translation: 一种基于软件的安全代理,其挂接到计算机设备的操作系统中,以便不断地审核计算机设备的最终用户的行为和行为。 检测到的最终用户的动作可以存储在可以被连续监视的队列或日志文件中,以检测可能构成策略冲突和/或安全风险的行为模式。 当检测到可能构成违反政策和/或安全风险的行为模式时,可能触发事件。 还公开了一种频率矢量串匹配算法。 频率矢量串匹配算法可用于检测目标字符串中字母数字字符的存在或部分存在。 频率矢量字符串匹配算法可用于检测存储的计算机记录中的拼写错误或基于部分信息搜索记录。 此外,频率矢量串匹配算法可以用于搜索已经被操纵,模糊或部分消除的敏感信息的通信。 另外,公开了一种用于比较一个用户的行为模式与其他用户的行为模式以检测异常行为的异常分析。

Patent Agency Ranking