首页> 外国专利> BEHAVIOURAL-BASED NETWORK ANOMALY DETECTION BASED ON USER AND GROUP PROFILING

BEHAVIOURAL-BASED NETWORK ANOMALY DETECTION BASED ON USER AND GROUP PROFILING

机译:基于用户和组配置的基于行为的网络异常检测

摘要

A baseline can be defined using specific attributes of the network traffic.Using the established baseline,deviation can then be measured to detect anomaly on the network. The accuracyof the baseline is the mostimportant criterion of any effective network anomaly detection technique. In alocal area network (LAN)environment, the attributes change very frequently by many change agents; forexample, new entities, such asusers, application, and network-enabled devices, added to and removed from theLAN environment. Theinvention provides an improved method of establishing a baseline for networkanomaly detection based onuser's behaviour profiling. A user behaviour profiling is a distinct networkusage pattern pertaining to a specificindividual user operating on the LAN environment. No two users profiling wouldbe the same. A group of usersthat have similar network usage attributes can be extrapolated using datamining technique to establish a groupprofiling baseline to detect network usage anomaly. By combining user andgroup profiling, a network anomalydetection system can measure subtle shift in network usage and as a resultseparate good user's networkusage behaviour from the bad one. Using the said technique, a lower rate offalse positives of network anomalycan be created that is suitable to operate in a highly dynamic LANenvironment.
机译:可以使用网络流量的特定属性来定义基准。使用已建立的基准,然后可以测量偏差以检测网络上的异常。准确度基线的最高任何有效的网络异常检测技术的重要标准。在一个局域网(LAN)在环境中,许多更改代理会频繁更改属性;对于例如,新实体,例如用户,应用程序和支持网络的设备(添加到局域网环境。的本发明提供了一种建立网络基线的改进方法基于的异常检测用户的行为分析。用户行为分析是一个独特的网络与特定用途有关的使用方式在LAN环境上运行的单个用户。没有两个用户配置文件是相同的。一组用户可以使用数据外推具有相似网络使用属性的数据采矿技术建立一个小组分析基准以检测网络使用异常。通过结合用户和组分析,网络异常检测系统可以测量网络使用情况的细微变化,从而分开良好的用户网络不良行为的使用行为。使用上述技术,可以降低网络异常的误报可以创建适合在高度动态局域网中运行的文件环境。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号