×

System and method directed to behavioral profiling services

  • US 10,505,959 B1
  • Filed: 12/09/2016
  • Issued: 12/10/2019
  • Est. Priority Date: 12/10/2015
  • Status: Active Grant
First Claim
Patent Images

1. A security appliance, comprising:

  • one or more processors; and

    a memory coupled to the one or more processors, the memory includes behavior profiling service logic that, when executed by the one or more processors, (i) creates a behavior profile for a particular entity based on received incoming data, and (ii) determines whether the behavior profile identifies that a malicious attack is being performed by the particular entity based on a comparison of the behavior profile to a reference profile;

    wherein the reference profile represents (a) historical behavior of the particular entity that is monitored over a prescribed period of time or (b) behavior of peers of the particular entity that is monitored over the same period of time;

    wherein the behavior profiling service logic further includes behavior profile generation logic that, when executed by the one or more processors, generates the behavior profile based, at least in part, on a plurality of attributes, the plurality of attributes including (a) a monitored source of the received incoming data and (b) the particular entity whose activities are being monitored; and

    wherein the behavior profile is defined by a plurality of features that are categorized in accordance with a selected feature set being one of a time feature set, a location feature set, and a payload feature set, wherein the location feature set includes a plurality of location-based features that are used to define access behavior by the particular entity, wherein the location-based features includes two or more of;

    (1) a frequency distribution of all unique geographic areas;

    (2) the geographic distance between two consecutive accessing locations; and

    (3) the moving speed between two consecutive accessing locations.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×