US2016080406A1PendingUtilityA1

Detecting anomalous activity from accounts of an online service

Assignee: MICROSOFT TECHNOLOGY LICENSING LLCPriority: Dec 19, 2013Filed: Nov 18, 2015Published: Mar 17, 2016
Est. expiryDec 19, 2033(~7.4 yrs left)· nominal 20-yr term from priority
H04L 63/1425H04L 67/306H04L 63/1416H04L 67/22H04W 12/12H04L 67/535G06Q 20/4016H04L 63/1408G06F 3/0481
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Anomalous activity is detected using event information that is received from accounts from within an online service. Generally, anomalous activity is detected by comparing a baseline profile that includes past event information for accounts of the online service with a recent profile that includes recent event information for the accounts. Anomalous activity is detected when the recent profile shows that one or more events are occurring more frequently as compared to the occurrence of the event the associated baseline profile. The events that are recorded and used in the anomaly detection may include all or a portion of events that are monitored by the online service. One or more reports may also be automatically generated and provided to one or more users to show activity that may be considered anomalous activity.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for detecting anomalous activity in an online service, comprising:
 accessing a baseline profile comprising past event information related to events that originate from accounts of the online service;   accessing a recent profile comprising recent event information related to recent events that originate from accounts of the online service;   comparing a frequency of the past event information in the baseline profile to a frequency of the recent event information in the recent profile to determine when anomalous activity is detected in the online service; and   reporting the anomalous activity when detected.   
     
     
         2 . The method of  claim 1 , wherein the past event information and the recent event information comprises security events of the online service. 
     
     
         3 . The method of  claim 1 , wherein the recent profile comprises recent event information that occurs from between a few hours and a day of activity related data. 
     
     
         4 . The method of  claim 1 , further comprising periodically accessing event information from accounts of the online service and updating the baseline profile and the recent profile using the accessed information. 
     
     
         5 . The method of  claim 1 , wherein comparing the frequency of the past event information in the baseline profile to the frequency of the recent event information in the recent profile to determine when anomalous activity is detected in the online service comprises determining when the frequency of at least one of the events in the recent event information is larger than the frequency of the at least one of the events in the past event information. 
     
     
         6 . The method of  claim 1 , further comprising automatically associating a weight with each of the events that are included in the baseline profile and the recent profile. 
     
     
         7 . The method of  claim 1 , wherein the baseline profile and the recent profile comprises event information that is obtained from operator accounts that have permissions to create, modify, and delete accounts for users. 
     
     
         8 . The method of  claim 1 , further comprising receiving configuration information relating to configuring events to monitor and include in the recent profile and the baseline profile. 
     
     
         9 . The method of  claim 1 , wherein reporting the anomalous activity when detected comprises automatically creating a report that ranks each account being monitored according to a detected level of anomalous activity and displaying more detailed information relating to the anomalous activity of at least one of the accounts when determined. 
     
     
         10 . A computer-readable storage medium storing computer-executable instructions for detecting anomalous activity in an online service, comprising:
 accessing a baseline profile comprising past event information related to events comprising security events that originate from accounts of the online service;   accessing a recent profile comprising recent event information related to recent events comprising the security events that originated within a last day from accounts of the online service;   comparing the baseline profile to the recent profile and when the baseline profile and the recent profile are different then detecting anomalous activity; and   reporting the anomalous activity when detected.   
     
     
         11 . The computer-readable storage medium of  claim 10 , further comprising periodically accessing a system log to obtain event information from accounts of the online service and updating the baseline profile and the recent profile using the accessed information. 
     
     
         12 . The computer-readable storage medium of  claim 10 , wherein comparing the baseline profile to the recent profile comprises examining a frequency of occurrence of the recent event information with the frequency of occurrence of the event information. 
     
     
         13 . The computer-readable storage medium of  claim 10 , further comprising associating a weight with each of the events that are included in the baseline profile and the recent profile that affects how much an occurrence of the event is used in detecting the anomalous activity. 
     
     
         14 . The computer-readable storage medium of  claim 10 , wherein the baseline profile comprises past event information from operator accounts. 
     
     
         15 . The computer-readable storage medium of  claim 10 , further comprising displaying a Graphical User Interface (GUI) and receiving configuration information relating to configuring the events from the GUI. 
     
     
         16 . The computer-readable storage medium of  claim 10 , wherein reporting the anomalous activity when detected comprises automatically creating a report and delivering the report and displaying more detailed information relating to the anomalous activity of at least one of the accounts in response to a selection of an account within the report. 
     
     
         17 . A system for detecting anomalous activity in an online service, comprising:
 a processor and memory;   an operating environment executing using the processor; and   an anomaly detector that is configured to perform actions comprising:   accessing a baseline profile comprising past event information related to events comprising security events that originate from accounts of the online service;   accessing a recent profile comprising recent event information related to recent events comprising the security events that originated within a last day from accounts of the online service;   comparing frequencies of past event information in the baseline profile to frequencies of the recent event information in the recent profile to determine when anomalous activity is detected in the online service; and   reporting the anomalous activity when detected.   
     
     
         18 . The system of  claim 17 , further comprising periodically accessing a system log to obtain event information from accounts of the online service and updating the baseline profile and the recent profile using the accessed information. 
     
     
         19 . The system of  claim 17 , further comprising associating a weight with each of the events that are included in the baseline profile and the recent profile that affects how much an occurrence of the event is used in detecting the anomalous activity. 
     
     
         20 . The system of  claim 17 , further comprising displaying a Graphical User Interface (GUI) and receiving configuration information relating to configuring the events from the GUI.

Join the waitlist — get patent alerts

Track US2016080406A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.