×

Detecting and managing abnormal data behavior

  • US 10,057,296 B2
  • Filed: 10/05/2017
  • Issued: 08/21/2018
  • Est. Priority Date: 02/26/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method performed by one or more processors, the method comprising:

  • continuously;

    identifying one or more normal data movements performed by a particular computing device over a network;

    determining a current data movement profile for the particular computing device based on one or more identified data transfers during a particular time period, the current data movement profile including one or more current data movement attributes associated with the particular computing device and defining normal data movement for the particular computing device;

    updating data stored that represents the current data movement profile such that the stored data represents the current data movement profile that is regularly updated;

    identifying a data movement rule associated with the particular computing device, the data movement rule including a deviation amount representing a difference between an attribute of a detected data movement by the particular computing device outbound to a particular location, wherein the deviation amount specifying a percentage deviation from an amount of data transferred that triggers the data movement rule, and a corresponding current data movement attribute included in the current data movement profile for the particular computing device that indicates a violation of the data movement rule, and the data movement rule including one or more actions to be performed in response to a violation;

    detecting a data movement associated with the particular computing device;

    determining that the detected data movement represents an abnormal data movement in violation of the current data movement profile data movement rule; and

    performing the one or more actions associated with the data movement rule upon determining that the detected data movement represents a violation of the current data movement profile data movement rule.

View all claims
  • 7 Assignments
Timeline View
Assignment View
    ×
    ×