System, method, and computer program product for detecting and assessing security risks in a network

The present disclosure is directed to a system, method, and computer program for detecting and assessing security risks in an enterprise's computer network. A behavior model is built for a user in the network based on the user's interactions with the network, wherein a behavior model for a...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Gil, Sylvain, Yip, Sing, Mihovilovic, Domingo, Stensmo, Magnus, Polak, Nir
Format: Patent
Sprache:eng
Schlagworte:
Online-Zugang:Volltext bestellen
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
container_end_page
container_issue
container_start_page
container_title
container_volume
creator Gil, Sylvain
Yip, Sing
Mihovilovic, Domingo
Stensmo, Magnus
Polak, Nir
description The present disclosure is directed to a system, method, and computer program for detecting and assessing security risks in an enterprise's computer network. A behavior model is built for a user in the network based on the user's interactions with the network, wherein a behavior model for a user indicates client device(s), server(s), and resources used by the user. The user's behavior during a period of time is compared to the user's behavior model. A risk assessment is calculated for the period of time based at least in part on the comparison between the user's behavior and the user's behavior model, wherein any one of certain anomalies between the user's behavior and the user's behavior model increase the risk assessment.
format Patent
fullrecord <record><control><sourceid>epo_EVB</sourceid><recordid>TN_cdi_epo_espacenet_US10095871B2</recordid><sourceformat>XML</sourceformat><sourcesystem>PC</sourcesystem><sourcerecordid>US10095871B2</sourcerecordid><originalsourceid>FETCH-epo_espacenet_US10095871B23</originalsourceid><addsrcrecordid>eNqNyk0KwjAQQOFsXIh6h3FfoVVE3SqK--q6hGRaQ80PMxOkt9eKB3D1ePBNla0HFvQFeJRHtAXoYMFEn7IgQaLYkfZjbTYCbSSwKGjEhe5LNTMyj8doMjkZgBz3DC6AhoDyitTP1aTVT8bFrzO1vJxvp-sKU2yQkzb4kc29rsrysN3vquN68495A-hoPx0</addsrcrecordid><sourcetype>Open Access Repository</sourcetype><iscdi>true</iscdi><recordtype>patent</recordtype></control><display><type>patent</type><title>System, method, and computer program product for detecting and assessing security risks in a network</title><source>esp@cenet</source><creator>Gil, Sylvain ; Yip, Sing ; Mihovilovic, Domingo ; Stensmo, Magnus ; Polak, Nir</creator><creatorcontrib>Gil, Sylvain ; Yip, Sing ; Mihovilovic, Domingo ; Stensmo, Magnus ; Polak, Nir</creatorcontrib><description>The present disclosure is directed to a system, method, and computer program for detecting and assessing security risks in an enterprise's computer network. A behavior model is built for a user in the network based on the user's interactions with the network, wherein a behavior model for a user indicates client device(s), server(s), and resources used by the user. The user's behavior during a period of time is compared to the user's behavior model. A risk assessment is calculated for the period of time based at least in part on the comparison between the user's behavior and the user's behavior model, wherein any one of certain anomalies between the user's behavior and the user's behavior model increase the risk assessment.</description><language>eng</language><subject>ALARM SYSTEMS ; CALCULATING ; COMPUTING ; COUNTING ; ELECTRIC COMMUNICATION TECHNIQUE ; ELECTRIC DIGITAL DATA PROCESSING ; ELECTRICITY ; ORDER TELEGRAPHS ; PHYSICS ; SIGNALLING ; SIGNALLING OR CALLING SYSTEMS ; TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</subject><creationdate>2018</creationdate><oa>free_for_read</oa><woscitedreferencessubscribed>false</woscitedreferencessubscribed></display><links><openurl>$$Topenurl_article</openurl><openurlfulltext>$$Topenurlfull_article</openurlfulltext><thumbnail>$$Tsyndetics_thumb_exl</thumbnail><linktohtml>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20181009&amp;DB=EPODOC&amp;CC=US&amp;NR=10095871B2$$EHTML$$P50$$Gepo$$Hfree_for_read</linktohtml><link.rule.ids>230,308,778,883,25553,76306</link.rule.ids><linktorsrc>$$Uhttps://worldwide.espacenet.com/publicationDetails/biblio?FT=D&amp;date=20181009&amp;DB=EPODOC&amp;CC=US&amp;NR=10095871B2$$EView_record_in_European_Patent_Office$$FView_record_in_$$GEuropean_Patent_Office$$Hfree_for_read</linktorsrc></links><search><creatorcontrib>Gil, Sylvain</creatorcontrib><creatorcontrib>Yip, Sing</creatorcontrib><creatorcontrib>Mihovilovic, Domingo</creatorcontrib><creatorcontrib>Stensmo, Magnus</creatorcontrib><creatorcontrib>Polak, Nir</creatorcontrib><title>System, method, and computer program product for detecting and assessing security risks in a network</title><description>The present disclosure is directed to a system, method, and computer program for detecting and assessing security risks in an enterprise's computer network. A behavior model is built for a user in the network based on the user's interactions with the network, wherein a behavior model for a user indicates client device(s), server(s), and resources used by the user. The user's behavior during a period of time is compared to the user's behavior model. A risk assessment is calculated for the period of time based at least in part on the comparison between the user's behavior and the user's behavior model, wherein any one of certain anomalies between the user's behavior and the user's behavior model increase the risk assessment.</description><subject>ALARM SYSTEMS</subject><subject>CALCULATING</subject><subject>COMPUTING</subject><subject>COUNTING</subject><subject>ELECTRIC COMMUNICATION TECHNIQUE</subject><subject>ELECTRIC DIGITAL DATA PROCESSING</subject><subject>ELECTRICITY</subject><subject>ORDER TELEGRAPHS</subject><subject>PHYSICS</subject><subject>SIGNALLING</subject><subject>SIGNALLING OR CALLING SYSTEMS</subject><subject>TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</subject><fulltext>true</fulltext><rsrctype>patent</rsrctype><creationdate>2018</creationdate><recordtype>patent</recordtype><sourceid>EVB</sourceid><recordid>eNqNyk0KwjAQQOFsXIh6h3FfoVVE3SqK--q6hGRaQ80PMxOkt9eKB3D1ePBNla0HFvQFeJRHtAXoYMFEn7IgQaLYkfZjbTYCbSSwKGjEhe5LNTMyj8doMjkZgBz3DC6AhoDyitTP1aTVT8bFrzO1vJxvp-sKU2yQkzb4kc29rsrysN3vquN68495A-hoPx0</recordid><startdate>20181009</startdate><enddate>20181009</enddate><creator>Gil, Sylvain</creator><creator>Yip, Sing</creator><creator>Mihovilovic, Domingo</creator><creator>Stensmo, Magnus</creator><creator>Polak, Nir</creator><scope>EVB</scope></search><sort><creationdate>20181009</creationdate><title>System, method, and computer program product for detecting and assessing security risks in a network</title><author>Gil, Sylvain ; Yip, Sing ; Mihovilovic, Domingo ; Stensmo, Magnus ; Polak, Nir</author></sort><facets><frbrtype>5</frbrtype><frbrgroupid>cdi_FETCH-epo_espacenet_US10095871B23</frbrgroupid><rsrctype>patents</rsrctype><prefilter>patents</prefilter><language>eng</language><creationdate>2018</creationdate><topic>ALARM SYSTEMS</topic><topic>CALCULATING</topic><topic>COMPUTING</topic><topic>COUNTING</topic><topic>ELECTRIC COMMUNICATION TECHNIQUE</topic><topic>ELECTRIC DIGITAL DATA PROCESSING</topic><topic>ELECTRICITY</topic><topic>ORDER TELEGRAPHS</topic><topic>PHYSICS</topic><topic>SIGNALLING</topic><topic>SIGNALLING OR CALLING SYSTEMS</topic><topic>TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION</topic><toplevel>online_resources</toplevel><creatorcontrib>Gil, Sylvain</creatorcontrib><creatorcontrib>Yip, Sing</creatorcontrib><creatorcontrib>Mihovilovic, Domingo</creatorcontrib><creatorcontrib>Stensmo, Magnus</creatorcontrib><creatorcontrib>Polak, Nir</creatorcontrib><collection>esp@cenet</collection></facets><delivery><delcategory>Remote Search Resource</delcategory><fulltext>fulltext_linktorsrc</fulltext></delivery><addata><au>Gil, Sylvain</au><au>Yip, Sing</au><au>Mihovilovic, Domingo</au><au>Stensmo, Magnus</au><au>Polak, Nir</au><format>patent</format><genre>patent</genre><ristype>GEN</ristype><title>System, method, and computer program product for detecting and assessing security risks in a network</title><date>2018-10-09</date><risdate>2018</risdate><abstract>The present disclosure is directed to a system, method, and computer program for detecting and assessing security risks in an enterprise's computer network. A behavior model is built for a user in the network based on the user's interactions with the network, wherein a behavior model for a user indicates client device(s), server(s), and resources used by the user. The user's behavior during a period of time is compared to the user's behavior model. A risk assessment is calculated for the period of time based at least in part on the comparison between the user's behavior and the user's behavior model, wherein any one of certain anomalies between the user's behavior and the user's behavior model increase the risk assessment.</abstract><oa>free_for_read</oa></addata></record>
fulltext fulltext_linktorsrc
identifier
ispartof
issn
language eng
recordid cdi_epo_espacenet_US10095871B2
source esp@cenet
subjects ALARM SYSTEMS
CALCULATING
COMPUTING
COUNTING
ELECTRIC COMMUNICATION TECHNIQUE
ELECTRIC DIGITAL DATA PROCESSING
ELECTRICITY
ORDER TELEGRAPHS
PHYSICS
SIGNALLING
SIGNALLING OR CALLING SYSTEMS
TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHICCOMMUNICATION
title System, method, and computer program product for detecting and assessing security risks in a network
url https://sfx.bib-bvb.de/sfx_tum?ctx_ver=Z39.88-2004&ctx_enc=info:ofi/enc:UTF-8&ctx_tim=2025-01-15T09%3A21%3A42IST&url_ver=Z39.88-2004&url_ctx_fmt=infofi/fmt:kev:mtx:ctx&rfr_id=info:sid/primo.exlibrisgroup.com:primo3-Article-epo_EVB&rft_val_fmt=info:ofi/fmt:kev:mtx:patent&rft.genre=patent&rft.au=Gil,%20Sylvain&rft.date=2018-10-09&rft_id=info:doi/&rft_dat=%3Cepo_EVB%3EUS10095871B2%3C/epo_EVB%3E%3Curl%3E%3C/url%3E&disable_directlink=true&sfx.directlink=off&sfx.report_link=0&rft_id=info:oai/&rft_id=info:pmid/&rfr_iscdi=true