ADDRRESSABLE SMART AGENT DATA TECHNOLOGY TO DETECT UNAUTHORIZED TRANSACTION ACTIVITY
A computer implemented and electronic process is provided that uses artificial intelligence to detect unauthorized activity by an insider or hacker. Electronic systems that employ artificial intelligence and machine learning to detect unauthorized transaction activity by insiders or hackers for a computer network system are also provided. Hardware required for carrying out the invention typically include a plurality of networked computers. Specialized software and/or firmware is typically needed in connection with the hardware for carrying out the invention.
1 . A computer implemented and electronic process that uses artificial intelligence to detect unauthorized activity by an insider or hacker, comprising the steps of:
analyzing activities and tasks of an administrator to detect any abnormal behavior using smart agent and artificial intelligence technologies;
beginning and calling into action the smart agent that represents the system administrator and other smart agents with an addressable call-output;
testing relationships of attributes of the smart agents included in a series of events and logs to a corresponding profile of the administrator and servers;
establishing a reference of normal behavior profile to each administrator and servers using past activities of the administrator; and
warning of unauthorized administrator activities upon activity comprising the sub-activities of:
(a) an instant behavior deviates from the reference normal behavior profile of the system administrator;
(b) an instant behavior deviates from the reference normal behavior of the serverver activities;
(c) an age timeout occurring before the state machine has started; or
(d) an age time not finishing in response to an addressable call-in.
2 . The process of claim 1 , further comprising:
building long term profiles, recursive profiles, real time profiles for each smart-agent by learning from system administrator activities; and
analyzing the system administrator activities to determine if activity reported in each activity report is classified as normal, timely, and harmonious with an instant task and job priorities.
3 . The process of claim 1 , further comprising:
testing to see what other addressable triggers-out and addressable call-out from the testing and scheduling issuance in a selected clock cycle; and
warning of an unauthorized transaction activity based on a profile by testing and issuing objections for smart agents that were not called into action yet were scheduled.
4 . The process of claim 1 , wherein the warning step takes place when at least two of the sub-activities of (a), (b) and (c) occur.
5 . The process of claim 4 , wherein the warning step takes place when all sub-activities of (a), (b) and (c) occur.
6 . The process of claim 1 , wherein the sub-activity comprises the instant behavior deviating substantially from the reference normal behavior profile.
7 . The process of claim 1 , taking place over the internet.
8 . An electronic system that employs artificial intelligence and machine learning to detect unauthorized transaction activity by insiders or hackers for a computer network system, comprising:
a plurality of networked computers;
electronic means for analyzing activities and tasks of an administrator to detect any abnormal behavior using smart agent and artificial intelligence technologies;
means for calling a smart-agent state machine for the administrator into operation with a smart-agent call-in trigger with an addressable output;
means for beginning and calling into action other smart agents with an addressable call-output;
means for testing relationships of transactional attributes of the smart agents included in a series of transactions to a corresponding profile of the administrator;
means for establishing a reference normal behavior profile from attributes of past transactions of the administrator; and
electronic means for warning of an unauthorized administrator transaction activity upon activity comprising the sub-activities of:
(a) an instant behavior deviates from the reference normal behavior profile for each system administrator or servers;
(b) an age timeout occurring before the state machine has started; or
(c) an age time not finishing in response to an addressable call-in.