IP Library Granted Patent US 8,881,289
Granted Patent B2
US 8,881,289 · App. 13/334,304 · Granted Nov 4, 2014

User behavioral risk assessment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,881,289
App. No.
13/334,304
Granted
Nov 4, 2014
Kind
B2
Abstract

A predetermined particular behavioral profile is identified associated with at least one particular user of a computing system, the particular behavioral profile identifying expected behavior of the at least one user within the computing system. Activities associated with use of the computing system by the particular user are identified and it is determined whether the identified activities correlate with the particular behavioral profile. Identifying an activity that deviates from the particular behavioral profile beyond a particular threshold triggers a risk event relating to the particular user.

Claims (42)

1. At least one non-transitory machine accessible storage medium having instructions stored thereon, the instructions when executed on a machine, cause the machine to:

identify a predetermined particular behavioral profile associated with at least one particular user of a computing system, the particular behavioral profile identifying expected behavior of users within a set of one or more users within the computing system, wherein the particular behavioral profile is based on previously detected activities of at least one user in the set and the set comprises the particular user;

identify, using at least one computer processing device, activities associated with use of the computing system by the particular user; and

determined, for each of the identified activities, whether the activity correlates with the particular behavioral profile, wherein determining that the activity deviates from the particular behavioral profile beyond a particular threshold triggers a risk event relating to the particular user and determining that the activity deviates from the particular behavioral profile within the particular threshold causes the particular behavioral profile to be revised based at least in part on the particular activity.

2. The storage medium of claim 1 , wherein activities that do not deviate beyond the particular threshold are considered satisfactorily consistent with the particular behavioral profile and do not trigger risk events.

3. The storage medium of claim 1 , wherein the particular behavioral profile is a user-based behavioral profile based on a plurality of inputs describing prior activities of the particular user in the computing system.

4. The storage medium of claim 3 , wherein the instructions, when executed, further cause the machine to:

identify a second user-based behavioral profile associated with a second user of the computing system;

identify activities associated with use of the computing system by the second user; and

determine whether the identified activities of the second user correlate with the second user-based behavioral profile, wherein identifying an activity that deviates from the second behavioral profile beyond the particular threshold triggers a risk event relating to the second user.

5. The storage medium of claim 3 , wherein the first and second users are included in a plurality of users within the computing system and each user in the plurality of users has at least one corresponding user-based behavioral profile.

6. The storage medium of claim 5 , wherein the instructions, when executed, further cause the machine to determine an aggregate risk profile for the computing system based at least in part on the user-based behavioral profile of the plurality of users.

7. The storage medium of claim 6 , wherein determining the aggregate risk profile for the computing system includes:

identifying an association between a particular computing device in the computing system and the particular user;

determining a device risk profile of the particular computing device; and

determining a composite risk associated with the particular computing device based at least in part on the device risk profile of the particular computing device and the particular behavioral profile of the particular user of the particular computing device.

8. The storage medium of claim 7 , wherein determining the composite risk includes identifying, from the particular behavioral profile, a behavioral tendency of the particular user that corresponds to a particular vulnerability of the particular computing device identified from the device risk profile of the particular computing device.

9. The storage medium of claim 1 , wherein the set of users comprises a plurality of users and the particular behavioral profile is a group-based behavioral profile based on a plurality of inputs from the plurality of users, the plurality of inputs describing prior activities of the plurality of users in the computing system.

10. The storage medium of claim 9 , wherein the set of users is at least one of a business unit, users in a particular geographic location, users with a particular employment status, users in a particular department of an organization, and a set of all identified users of the computing system.

11. The storage medium of claim 1 , wherein the particular behavioral profile is based on a plurality of inputs received from a plurality of security tools providing security services within the computing system.

12. The storage medium of claim 11 , wherein the instructions, when executed, further cause the machine to initiate deployment of a countermeasure in response to determining that a particular activity of the particular user deviates from the particular behavioral profile beyond the particular threshold, wherein the countermeasure corresponds to a particular risk event triggered by the particular activity.

13. The storage medium of claim 12 , wherein the countermeasure is deployed using at least one of the plurality of security tools.

14. The storage medium of claim 13 , wherein the plurality of security tools include at least two of a firewall, a web gateway, a mail gateway, a host intrusion protection (HIP) tool, a network intrusion protection (NIP) tool, an anti-malware tool, a data loss prevention (DLP) tool, a system vulnerability manager, a system policy compliance manager, an asset criticality tool, and a security information management (SIM) tool.

15. The storage medium of claim 13 , wherein the plurality of security tools include a firewall, a web gateway, a mail gateway, a host intrusion protection (HIP) tool, a network intrusion protection (NIP) tool, an anti-malware tool, a data loss prevention (DLP) tool, a system vulnerability manager, a system policy compliance manager, an asset criticality tool, and a security information management (SIM) tool.

16. The storage medium of claim 11 , wherein at least one of the inputs originates from a host-based security tool operating on at least one end user computing device in the computing system identified as used by the particular user, the host-based security tool adapted to monitor behavior of users of the end user computing device at the end user computing device for use in detecting violations of user behavioral rules for the computing system.

17. The storage medium of claim 16 , wherein the instructions, when executed, further cause the machine to corroborate a determined deviation from the particular behavioral profile with a particular violation of a user behavior rule detected from monitoring of the end user computing device by the host-based security tool.

18. The storage medium of claim 1 , wherein the particular behavioral profile includes a plurality of categorical risk profiles for the particular user, each categorical risk profile describing determined tendencies of the particular user with regard to a respective category of system use.

19. A method comprising:

identifying a predetermined particular behavioral profile associated with at least one particular user of a computing system, the particular behavioral profile identifying expected behavior of users within a set of one or more users within the computing system, wherein the particular behavioral profile is based on previously detected activities of at least one user in the set and the set comprises the particular user;

identifying activities associated with use of the computing system by the particular user; and

determining, for each of the identified activities, whether the activity correlates with the particular behavioral profile, wherein determining that the activity deviates from the particular behavioral profile beyond a particular threshold triggers a risk event relating to the particular user and determining that the activity deviates from the particular behavioral profile within the particular threshold causes the particular behavioral profile to be revised based at least in part on the particular activity.

20. A system comprising:

at least one processor device;

at least one memory element; and

a user behavioral risk analysis engine, adapted when executed by the at least one processor device to:

identify a predetermined particular behavioral profile associated with at least one particular user of a computing system, the particular behavioral profile identifying expected behavior of users within a set of one or more users within the computing system, wherein the particular behavioral profile is based on previously detected activities of at least one user in the set and the set comprises the particular user;

identify a particular activity associated with use of the computing system by the particular user; and

determine, for each of the identified activities, whether the activity correlates with the particular behavioral profile, wherein determining that the activity deviates from the particular behavioral profile beyond a particular threshold triggers a risk event relating to the particular user and determining that the activity deviates from the particular behavioral profile within the particular threshold causes the particular behavioral profile to be revised based at least in part on the particular activity.

21. The system of claim 20 , further comprising at least two security tools from a set including a firewall, a web gateway, a mail gateway, a host intrusion protection (HIP) tool, a network intrusion protection (NIP) tool, an anti-malware tool, a data loss prevention (DLP) tool, a system vulnerability manager, a system policy compliance manager, an asset criticality tool, and a security information management (SIM) tool, wherein user activities associated with use of the computing system are identified by each of the at least two security tools.

22. The system of claim 20 , wherein the user behavioral risk analysis engine is further adapted, when executed, to:

identify a detected violation of a particular system usage rule in a plurality of system usage rules by the particular user through use of a particular computing device by the particular user within the computing system, wherein the detected violation is based on monitoring of the particular computing device by a security tool installed on the particular computing device; and

corroborate the determined deviation from the particular behavioral profile with the detected violation of the particular system usage rule by the particular user.

Assignments (20)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →