×

DETECTING AND MANAGING ABNORMAL DATA BEHAVIOR

  • US 20160072848A1
  • Filed: 11/17/2015
  • Published: 03/10/2016
  • Est. Priority Date: 02/26/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method performed by one or more processors, the method comprising:

  • identifying one or more data movements performed by a particular computing device over a network;

    determining a normal data movement profile for the particular computing device based on one or more identified data transfers during a particular time period, the normal data movement profile including one or more normal data movement attributes associated with the particular computing device;

    identifying a data movement rule associated with the particular computing device, the data movement rule including a deviation amount representing a difference between an attribute of a detected data movement by the particular computing device and a corresponding normal data movement attribute included in the normal data movement profile for the particular computing device that indicates a violation of the data movement rule, and the data movement rule including one or more actions to be performed in response to a violation;

    detecting a data movement associated with the particular computing device;

    determining that the detected data movement represents a violation of the data movement rule; and

    performing the one or more actions associated with the data movement rule upon determining that the detected data movement represents a violation of the data movement rule.

View all claims
  • 7 Assignments
Timeline View
Assignment View
    ×
    ×