×

Context Aware Network Security Monitoring for Threat Detection

  • US 20130305357A1
  • Filed: 12/06/2012
  • Published: 11/14/2013
  • Est. Priority Date: 11/18/2010
  • Status: Active Grant
First Claim
Patent Images

1. A method for context aware network security monitoring for threat detection, the method comprising:

  • monitoring, by at least one processor, behavior of at least one node, associated with at least one user, in a network to generate a behavior profile for the at least one user;

    comparing, by the at least one processor, the behavior profile for the at least one user with a baseline behavior profile for the at least one user;

    determining, by the at least one processor, when there is a difference between the behavior profile for the at least one user and the baseline behavior profile for the at least one user;

    flagging an event associated with the difference, by the at least one processor, when the difference at least one of exceeds a baseline threshold level, does not exceed a baseline threshold level, meets at least one criterion, and does not meet at least one criterion; and

    classifying the event, by the at least one processor, to an event classification.

View all claims
  • 1 Assignment
Timeline View
Assignment View
    ×
    ×