IP Library Granted Patent US 12699778
Granted Patent B2
US 12699778 · App. 18/516,593 · Granted Aug 4, 2026

Risk scoring using supervised machine learning

Inventors: Christopher Balles (San Diego, CA); Kellen Arb (Austin, TX); Michael Cosmadelis (Mount Laurel, NJ); Sean Corlin (Upland, CA); Jeremy Fintel (Austin, TX)
Assignee: CrowdStrike, Inc.
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12699778
App. No.
18/516,593
Granted
Aug 4, 2026
Kind
B2
Abstract

Techniques for using supervised machine learning to train risk models used to analyze group data for security risks are discussed herein. A system can receive a user input identifying risk values associated with categories or attributes of a group having access to computing resources. The system can use the risk model to generate a risk score for the group. The risk score can be used to further analyze aspects of the group or provide recommendations to reduce or eliminate security risks.

Claims (46)

1 . A system comprising:

one or more processors; and

one or more non-transitory computer-readable media storing computer-executable instructions that, when executed, cause the one or more processors to perform operations comprising:

receiving a risk evaluation request to provide a first risk score for a first object of a group and second risk score for a second object of the group;

selecting an initial risk model to generate a trained risk model, wherein the trained risk model is used to generate the first risk score and the second risk score, wherein the trained risk model is generated by:

deconstructing the group into group attributes;

deconstructing the group attributes into attribute categories;

receiving a risk value for each of the attribute categories; and

generating the trained risk model by training the initial risk model, wherein training the initial risk model comprises modifying the initial risk model until training data applied to the risk model using a machine learning module generates an allowable risk score for a test group object of the training data;

generating the first risk score and the second risk score using the trained risk model; and

configuring recommendation data for the group based at least in part on the first risk score or the second risk score, the recommendation data comprising an indication of a high risk associated with the first risk score or the second risk score.

2 . The system of claim 1 , wherein the group comprises a security group and the group attributes comprise rules that control a traffic flow associated with the security group.

3 . The system of claim 1 , wherein selecting the initial risk model comprises analyzing the risk evaluation request to determine a group type associated with the risk evaluation request.

4 . The system of claim 1 , wherein selecting the initial risk model comprises determining a type of subscription service associated with the risk evaluation request.

5 . The system of claim 1 , wherein the allowable risk score for the test group object of the training data comprises a numerical value within a predetermined range of numerical values.

6 . The system of claim 1 , wherein receiving an input of the risk value for each of the attribute categories comprises receiving an input from a user at an input component.

7 . One or more non-transitory computer-readable media storing instructions executable by one or more processors, wherein the instructions, when executed, cause the one or more processors to perform operations comprising:

receiving a risk evaluation request to provide a first risk score for a first object of a group and second risk score for a second object of the group;

applying an initial risk model to generate a trained risk model, wherein the trained risk model is used to generate the first risk score and the second risk score, wherein the trained risk model is generated by:

deconstructing the group into group attributes;

deconstructing the group attributes into attribute categories;

receiving an input of a risk value for each of the attribute categories; and

generating trained the risk model by training the initial risk model, wherein training the initial risk model comprises modifying the initial risk model until training data applied to the risk model using a machine learning module generates an allowable risk score for a test group object of the training data;

generating the first risk score and the second risk score using the trained risk model; and

configuring recommendation data for the group based at least in part on the first risk score or the second risk score, the recommendation data comprising an indication of a high risk associated with the first risk score or the second risk score.

8 . The one or more non-transitory computer-readable media of claim 7 , wherein the group comprises a security group and the group attributes comprise rules that control a traffic flow associated with the security group.

9 . The one or more non-transitory computer-readable media of claim 7 , wherein selecting the initial risk model comprises analyzing the risk evaluation request to determine a group type associated with the risk evaluation request.

10 . The one or more non-transitory computer-readable media of claim 7 , wherein selecting initial the risk model comprises determining a type of subscription service associated with the risk evaluation request.

11 . The one or more non-transitory computer-readable media of claim 7 , wherein the allowable risk score for the test group object of the training data comprises a numerical value within a predetermined range of numerical values.

12 . The one or more non-transitory computer-readable media of claim 7 , wherein receiving the input of the risk value for each of the attribute categories comprises receiving an input from a user at an input component.

13 . The one or more non-transitory computer-readable media of claim 7 , wherein the risk value for each of the attribute categories comprises a numerical value between 0 and 1.

14 . The one or more non-transitory computer-readable media of claim 7 , wherein the recommendation data comprises a recommendation to isolate a group object having a risk score above a predetermined value.

15 . The one or more non-transitory computer-readable media of claim 7 , wherein the machine learning module uses a neural network regression algorithm.

16 . The one or more non-transitory computer-readable media of claim 7 , wherein the risk evaluation request is received from a cloud computing server providing cloud computing services to a host device providing computing services to the group or received from the host device providing the computing services to the group.

17 . A computer-implemented method comprising:

receiving a risk evaluation request to provide a first risk score for a first object of a group and second risk score for a second object of the group;

applying an initial risk model to generate a trained risk model, wherein the trained risk model is used to generate the first risk score and the second risk score, wherein the trained risk model is generated by:

deconstructing the group into group attributes;

deconstructing the group attributes into attribute categories;

receiving an input of a risk value for each of the attribute categories; and

generating the trained risk model by training the initial risk model, wherein training the risk model comprises modifying the initial risk model until training data applied to the risk model using a machine learning module generates an allowable risk score for a test group object of the training data;

generating the first risk score and the second risk score using the trained risk model; and

configuring recommendation data for the group based at least in part on the first risk score or the second risk score, the recommendation data comprising an indication of a high risk associated with the first risk score or the second risk score.

18 . The computer-implemented method of claim 17 , wherein selecting the initial risk model comprises analyzing the risk evaluation request to determine a group type associated with the risk evaluation request or determining a type of subscription service associated with the risk evaluation request.

19 . The computer-implemented method of claim 17 , wherein the allowable risk score for the test group object of the training data comprises a numerical value within a predetermined range of numerical values.

20 . The computer-implemented method of claim 17 , wherein receiving the input of the risk value for each of the attribute categories comprises receiving an input from a user at an input component.