Detecting abnormal data access based on data similarity

Embodiments are directed monitoring network traffic using network monitoring computers. Activity associated with a document in a network may be determined based on the network traffic. A profile may be generated based on a summarization of the activity associated with the document such that the prof...

Full description

Saved in:
Bibliographic Details
Main Authors Wu, Xue Jun, Dasgupta, Swagat, Schurr, Matthew Alexander
Format Patent
LanguageEnglish
Published 12.12.2023
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:Embodiments are directed monitoring network traffic using network monitoring computers. Activity associated with a document in a network may be determined based on the network traffic. A profile may be generated based on a summarization of the activity associated with the document such that the profile may be stored in a data store that stores other profiles. Similar profiles may be determined based on a classification of each profile in the data store based on similarities between the profile and the other profiles in the data store. In response to determining similar profiles, locations in the network associated with documents that correspond to the similar profiles may be determined. Locations may be classified based on the activity, the similar profiles and access policies. In response to portions of the locations being classified as inconsistent with the access policies may be reported.
Bibliography:Application Number: US202217708311