IP Library Granted Patent US 8,321,958
Granted Patent B1
US 8,321,958 · App. 12/511,307 · Granted Nov 27, 2012

Detecting presence of a subject string in a target string and security event qualification based on prior behavior by an end user of a computer system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,321,958
App. No.
12/511,307
Granted
Nov 27, 2012
Kind
B1
Abstract

A software-based security agent that hooks into the operating system of a computer device in order to continuously audit the behavior and conduct of the end user of the computer device. The detected actions of the end user can be stored in a queue or log file that can be continuously monitored to detect patterns of behavior that may constitute a policy violation and/or security risk. When a pattern of behavior that may constitute a policy violation and/or security risk is detected, an event may be triggered. A frequency vector string matching algorithm also is disclosed. The frequency vector string matching algorithm may be used to detect the presence or partial presence of subject strings within a target string of alphanumeric characters. The frequency vector string matching algorithm could be used to detect typos in stored computer records or to search for records based on partial information. In addition, the frequency vector string matching algorithm could be used to search communications for sensitive information that has been manipulated, obscured, or partially elided. In addition, an anomaly analysis is disclosed for comparing behavior patterns of one user against the behavior patterns of other users to detect anomalous behaviors.

Claims (32)

1. A computer system for detecting presence of a subject string S in a target string T of alphanumeric characters, where T has a length m, the computer system comprising:

a processor circuit; and

a memory in communication with the processor circuit, wherein the memory stores instructions that when executed by the processor circuit cause the processor circuit to determine a similarity score indicative of a similarity between the subject string S and the target string T by:

for each of one or more substrings U of target string T, correlating a frequency of occurrence of a set C of n unique alphanumeric characters between the subject string S and the one or more substrings U, where n≦m;

normalizing a result of the correlation to produce a score for each of the one or more substrings U;

determining the similarity score indicative of the similarity between the subject string S and the target string T by selecting a greatest score from the scores for each of the one or more substrings U; and

at least partially responsive to selecting the greatest score, triggering a response to the subject string S in the target string T.

2. The computer system of claim 1 , wherein:

correlating the frequency of occurrence of the set C of n unique alphanumeric characters between the subject string S and the one or more substrings U for each of one or more substrings U of target string T comprises:

determining a vector ū=[u 1 , u 2 , . . . , u i , . . . , u n ] of n non-negative numbers, wherein the elements of the vector u correspond respectively to a count of the n unique alphanumeric characters in C that are present in a substring U of target string T, wherein the substring U has a length k where n≦k≦m; and

computing a dot product, denoted r, of normalizations of ū and v , where v is a vector of n non-negative numbers, where the elements of the vector v correspond respectively to a count of the unique alphanumeric characters in C that are present in the subject string S; and

normalizing the result of the correlation for each of one or more substrings U of target string T comprises:

computing a dot product, denoted t, of N and v , where N is a vector having n elements all being the same value;

projecting a first interval of values [t, 1] onto a second interval of values [0,1]; and

determining the score for the substring U of string T based on a mapping of r via the projection of the first interval onto the second interval.

3. The computer system of claim 2 , wherein the n elements of vector N if are all 1.

4. A computer-implemented method for detecting presence of a subject string S in a target string T of alphanumeric characters, where T has a length m, the method comprising:

for each of one or more substrings U of target string T:

correlating, by a computer system, a frequency of occurrence of a set C of n unique alphanumeric characters between the subject string S and the one or more substrings U, where n≦m;

normalizing, by the computer system, a result of the correlation to produce a score for each of the one or more substrings U;

determining, by the computer system, a similarity score indicative of the similarity between the subject string S and the target string T by selecting a greatest score from the score for each of the one or more substrings U;

at least partially responsive to selecting the greatest score, triggering a response to the presence of subject string S in the target string T; and

wherein the computer system comprises at least one computer device that comprises a processor circuit and a memory, wherein the memory stores instructions that are executed by the processor circuit.

5. The method of claim 4 , wherein:

correlating the frequency of occurrence of the set C of n unique alphanumeric characters between the subject string S and the one or more substrings U for each of one or more substrings U of target string T comprises:

determining a vector ū=[u 1 , u 2 , . . . , u i , . . . , u n ] of n non-negative numbers, wherein the elements of the vector u correspond respectively to a count of the n unique alphanumeric characters in C that are present in a substring U of target string T, wherein the substring U has a length k where n≦k≦m; and

computing a dot product, denoted r, of normalizations of ū and v , where is a vector of n non-negative numbers, where the elements of the vector v correspond respectively to a count of the unique alphanumeric characters in C that are present in the subject string S; and

normalizing the result of the correlation for each of one or more substrings U of target string T comprises:

computing a dot product, denoted t, of N and v , where N is a vector having n elements all being the same value;

projecting a first interval of values [t, 1] onto a second interval of values [0,1]; and

determining the score for the substring U of string T based on a mapping of r via the projection of the first interval onto the second interval.

6. The method of claim 5 , wherein the n elements of the vector N are all 1.

Assignments (9)
SECURITY INTEREST Recorded Dec 23, 2025
From: VERINT AMERICAS INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 074034/0292 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050612/0972) Recorded Nov 26, 2025
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: VERINT AMERICAS INC.
Reel/Frame 073796/0675 →
PATENT SECURITY AGREEMENT Recorded Oct 3, 2019
From: VERINT AMERICAS INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 050612/0972 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 19, 2018
From: NEXT IT CORPORATION
To: VERINT AMERICAS INC.
Reel/Frame 044963/0046 →
RELEASE OF SECURITY INTEREST Recorded Feb 18, 2018
From: POWERS, THOMAS; POWERS, GWENDOLYN
To: NEXT IT CORPORATION
Reel/Frame 044962/0795 →
RELEASE OF SECURITY INTEREST Recorded Feb 18, 2018
From: UNION BAY NEXT IT HOLDINGS, LLC
To: NEXT IT CORPORATION
Reel/Frame 044962/0659 →
SECURITY INTEREST Recorded Jun 16, 2014
From: NEXT IT CORPORATION
To: UNION BAY NEXT IT HOLDINGS, LLC
Reel/Frame 033182/0595 →
SECURITY INTEREST Recorded May 28, 2014
From: NEXT IT CORPORATION
To: POWERS, GWENDOLYN; POWERS, THOMAS
Reel/Frame 033045/0324 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2009
From: FLEMING, SAMUEL; WEEKS, RICHARD T.
To: NEXT IT CORPORATION
Reel/Frame 023021/0100 →