Monitoring the dangerous activity of computer network users

Abstract 

Two approaches to monitoring the dangerous activity of computer network users are presented. The first one relies on the technique of statistical hypotheses testing and uses self-organizing feature maps (Kohonen networks) for generating target statistics. The second approach recognizes dangerous activity via executed sequences of relevant typical actions, with their dynamics being represented with the aid of Markov chains.