CLOUD SERVICE USAGE RISK ANALYSIS BASED ON USER LOCATION

    公开(公告)号:US20180191760A1

    公开(公告)日:2018-07-05

    申请号:US15820052

    申请日:2017-11-21

    IPC分类号: H04L29/06 H04L29/08

    摘要: A system and method for filtering detected anomalies in cloud service usage activities associated with an enterprise uses a trusted location analysis to filter detected anomalies. The locations from which the cloud usage activities are made are analyzed and designated as trusted or non-trusted. The trusted location determination is used to filter the detected anomalies that are associated with trusted locations and therefore may be of low risk. In this manner, actions can be taken only on detected anomalies that are associated with non-trusted locations and therefore may be high risk. The system and method of the present invention enable security incidents, anomalies and threats from cloud activity to be detected, filtered and annotated based on the location heuristics. The trusted location analysis identifies trusted locations automatically using cloud activity usage data and does not rely on potentially unreliable location data from user input.

    Cloud service usage risk analysis based on user location

    公开(公告)号:US09853992B1

    公开(公告)日:2017-12-26

    申请号:US15144335

    申请日:2016-05-02

    IPC分类号: H04L29/06 H04L29/08

    摘要: A system and method for filtering detected anomalies in cloud service usage activities associated with an enterprise uses a trusted location analysis to filter detected anomalies. The locations from which the cloud usage activities are made are analyzed and designated as trusted or non-trusted. The trusted location determination is used to filter the detected anomalies that are associated with trusted locations and therefore may be of low risk. In this manner, actions can be taken only on detected anomalies that are associated with non-trusted locations and therefore may be high risk. The system and method of the present invention enable security incidents, anomalies and threats from cloud activity to be detected, filtered and annotated based on the location heuristics. The trusted location analysis identifies trusted locations automatically using cloud activity usage data and does not rely on potentially unreliable location data from user input.

    Cloud security system implementing service action categorization

    公开(公告)号:US10999325B1

    公开(公告)日:2021-05-04

    申请号:US15789658

    申请日:2017-10-20

    IPC分类号: H04L29/06

    摘要: A service action category based cloud security system and method implement cloud security by categorizing service actions of cloud service providers into a set of service action categories. The service action categorization is performed agnostic to the applications or functions provided by the cloud service providers and also agnostic to the cloud service providers. With the service actions of cloud service providers thus categorized, cloud security monitoring and threat detection can be performed based on service action categories. Thus, cloud security can be implemented without requiring knowledge of the applications supported by the cloud service providers and without knowing all of the individual service actions supported by the cloud service providers.

    Cloud based data loss prevention system using graphical processing units for index filtering

    公开(公告)号:US10412102B1

    公开(公告)日:2019-09-10

    申请号:US15372643

    申请日:2016-12-08

    摘要: A system for providing data loss prevention services includes an indexer system configured to generate a search index based on structured data to be protected and a detection system configured to receive the search index and network data content and to detect in the network data content for matching data based on the search index. The detection system includes a first processor and multiple graphical processing units. The first processor provides words from the network data content in parallel to each of the graphical processing units, each graphical processing unit receiving a different word from the network data content. The graphical processing units perform detection of the words in parallel to detect for matched data content in at least a portion of the search index.

    Cloud activity threat detection for sparse and limited user behavior data

    公开(公告)号:US10291638B1

    公开(公告)日:2019-05-14

    申请号:US15260189

    申请日:2016-09-08

    IPC分类号: H04L29/06 G06F7/24 G06N20/00

    摘要: A cloud security system and method implements cloud activity threat detection using analysis of cloud usage user behavior. In particular, the cloud security system and method implements threat detection for users, cloud service providers, or tenants (enterprises) of the cloud security system who are new or unknown to the cloud security system and therefore lacking sufficient cloud activity data to generate an accurate behavior model for effective threat detection. In accordance with embodiments of the present invention, the cloud security system and method performs user behavior analysis to generate generalized user behavior models for user groups, where each user group includes users with similar cloud usage behavior. The user behavior models of the user groups are assigned to users with sparse cloud activity data. In this manner, the cloud security system and method of the present invention ensures effective threat detection by using accurate and reliable user behavior models.