会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 1. 发明申请
    • Detecting Suspicious File Prospecting Activity from Patterns of User Activity
    • 从用户活动模式中检测可疑文件查找活动
    • US20170061123A1
    • 2017-03-02
    • US14836804
    • 2015-08-26
    • Symantec Corporation
    • Aleatha Parker-WoodAndrew Gardner
    • G06F21/55G06F17/30
    • G06F21/552G06F21/556G06F2221/033
    • Suspicious file prospecting activity is detected based on patterns of file system access. A user's file system access is monitored over a specific time period. A sequence of the file accesses (e.g., represented as path names) made by the user during the time period is recorded. Distances between the recorded file accesses are determined, for example as edit distances. A distance sequence is recorded, comprising a record of the determined distances. The distance sequence is reduced to one or more baseline statistics describing the pattern of the user's access of the file system during the given period of time. At least one subsequent anomaly in the user's access of the file system is detected, by comparing at least one subsequently calculated statistic representing at least one subsequent pattern of the user's file system access to the at least one baseline statistic.
    • 基于文件系统访问模式检测到可疑文件检索活动。 在特定时间段内监视用户的文件系统访问。 记录用户在该时间段期间进行的文件访问(例如,表示为路径名)的顺序。 确定记录的文件访问之间的距离,例如作为编辑距离。 记录距离序列,包括确定的距离的记录。 距离序列减少到描述用户在给定时间段内文件系统的访问模式的一个或多个基线统计信息。 通过将表示用户文件系统访问的至少一个后续模式的至少一个随后计算的统计量与至少一个基线统计量进行比较来检测文件系统的用户访问中的至少一个后续异常。