The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Mar. 09, 2021

Filed:

Mar. 24, 2020
Applicant:

Exabeam, Inc., Foster City, CA (US);

Inventors:

Derek Lin, San Mateo, CA (US);

Qiaona Hu, Emerald Hills, CA (US);

Domingo Mihovilovic, Menlo Park, CA (US);

Sylvain Gil, San Francisco, CA (US);

Barry Steiman, San Ramon, CA (US);

Assignee:

Exabeam, Inc., Foster City, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06N 5/04 (2006.01); G06F 16/28 (2019.01); G06F 21/55 (2013.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06F 16/285 (2019.01); G06F 21/554 (2013.01); G06N 5/047 (2013.01);
Abstract

The present disclosure relates a system, method, and computer program for detecting anomalous user network activity based on multiple data sources. The system extracts user event data for n days from multiple data sources to create a baseline behavior model that reflects the user's daily volume and type of IT events. In creating the model, the system addresses data heterogeneity in multi-source logs by categorizing raw events into meta events. Thus, baseline behavior model captures the user's daily meta-event pattern and volume of IT meta events over n days. The model is created using a dimension reduction technique. The system detects any anomalous pattern and volume changes in a user's IT behavior on day n by comparing user meta-event activity on day n to the baseline behavior model. A score normalization scheme allows identification of a global threshold to flag current anomalous activity in the user population.


Find Patent Forward Citations

Loading…