EP3304397B1

Detecting anomalous accounts using event logs

Abstract

This record has no abstract on file.

EP3304397B1, drawing sheet 1
Sheet 1 of 8

Term

9.7 yearsleft in the term

Expires 20 May 2036.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

15 claims: 2 independent, 13 dependent

  1. 1
    A system for anomalous process detection, comprising:an event log module configured to receive a plurality of event logs;a filter module configured to filter the plurality of event logs based on detected process creations;a receiving module configured to receive a directory path and process name for each detected process creation;a conversion module configured to convert each directory path to a sequence of integers based on a character count for each sub-directory of the directory path;a detection module configured to detect an anomalous process based on a threshold number of matching character counts and matching process names;and a display module configured to display the detected anomalous process.
  2. 6
    A method for anomalous process detection, the method comprising:receiving, via a processor, a plurality of event logs;filtering, via the processor, the plurality of event logs to detect process creations;receiving, via the processor, a directory path and process name for each detected process creation;converting, via the processor, each directory path to a sequence of integers based on character count;detecting, via the processor, an anomalous process based on a threshold number of matching character counts and matching process names;and displaying, via the processor, the detected anomalous process.