A network node of a
threat detection network, a backend
server of a
threat detection network, a
threat detection network and a threat detection method in a threat detection network. The threat detection network comprises interconnected network nodes and a backend
system, wherein at least part of the nodes comprise security agent modules which collect data related to the respective network node. The method comprises collecting and / or analyzing at the network node data related to a network node, generating at least one local behavior model at the network node related to the network node on the basis of the collected and / or analyzed data, sharing at least one generated local behavior model related to the network node with one or more other nodes and / or with the backend
system, comparing user activity in a node to the generated local behavior model and / or a received behavior model, and alerting the backend and / or the other nodes, e.g. about
anomalous behavior, if deviation from the generated local behavior model and / or the received behavior model is detected, and / or comparing at the backend
system the anomalous data with other behavior models, e.g. with other behavior models in the same organization and / or behavior models of known malicious users, and sending from the backend system to the node results and / or data relating to the comparison.