IP Library Granted Patent US 9,635,047
Granted Patent B2
US 9,635,047 · App. 14/723,192 · Granted Apr 25, 2017

User behavioral risk assessment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,635,047
App. No.
14/723,192
Granted
Apr 25, 2017
Kind
B2
Abstract

A particular activity performed by a particular user of a computing device is identified, for instance, by an agent installed on the computing device. It is determined that the particular activity qualifies as a particular use violation in a plurality of pre-defined use violations. A behavioral risk score for the particular score for the user is determined based at least in part on the determination that the particular activity of the particular user qualifies as a particular use violation. Determining that the particular activity qualifies as a particular use violation can include determining that the particular activity violates a particular rule or event trigger corresponding to a particular pre-defined use violation.

Claims (62)

1. At least one non-transitory machine accessible storage medium having instructions stored thereon, the instructions when executed on a machine, cause the machine to:

receive, at a computing device, first rule data corresponding to a first set of rules maintained at a remote risk assessment engine, wherein the first set of rules is associated with a particular user;

use the first rule data to monitor user activity on the computing device during a first session;

detect a particular activity performed by the particular user on the computing device during the first session;

determine, based on the first rule data, that the particular activity qualifies as a first potential violation;

send a first report to the risk assessment engine identifying the first potential violation detected at the computing device, wherein the first report identifies the particular user;

generate behavioral tendency data describing behavioral tendencies of the particular user detected by a behavior monitor executing on the computing device;

send the behavioral tendency data to the risk assessment engine to apply to a behavior profile of the particular user maintained by the risk assessment engine;

receive an indication from the risk assessment engine, responsive to the first report, that the first potential violation is a violation; and

perform a remediation action at the particular computing device based on the indication.

2. A method comprising:

receiving, at a computing device, rule data corresponding to a set of rules maintained at a remote risk assessment engine, wherein the set of rules is associated with a particular user;

using the rule data to monitor user activity on the computing device during a first session;

detecting, at the computing device, a particular activity performed by the particular user on a computing device during the first session;

determining, based on the rule data, that the particular activity qualifies as a potential violation;

sending a report to the risk assessment engine identifying the potential violation detected at the computing device, wherein the first report identifies the particular user;

generating behavioral tendency data describing behavioral tendencies of the particular user detected by a behavior monitor executing on the computing device;

sending the behavioral tendency data to the risk assessment engine to apply to a behavior profile of the particular user maintained by the risk assessment engine;

receiving an indication from the risk assessment engine, responsive to the report, that the potential violation is a violation; and

performing a remediation action at the particular computing device based on the indication.

3. A system comprising:

at least one processor device;

at least one memory element; and

a user behavioral risk agent installed on a particular computing device, wherein the user behavioral risk agent is executable to:

receive, at a computing device, rule data corresponding to a set of rules maintained at a remote risk assessment engine, wherein the set of rules is associated with a particular user, and the rule data abstracts rules in the set of rules;

use the rule data to monitor user activity on the computing device for violations of the rule data during a particular session;

detect, at the particular computing device, a particular activity performed by the particular user on the particular computing device during the particular session;

determine, based on the rule data, that the particular activity qualifies as a potential violation;

send a report to the risk assessment engine identifying the potential violation detected at the computing device;

generate behavioral tendency data describing behavioral tendencies of the particular user detected by a behavior monitor executing on the computing device;

send the behavioral tendency data to the risk assessment engine to apply to a behavior profile maintained by the risk assessment engine;

receive an indication from the risk assessment engine, responsive to the report, that the potential violation is a violation, wherein the indication is based at least in part on whether the potential violation deviates from the behavior profile; and

perform a remediation action at the particular computing device based on the indication.

4. The storage medium of claim 1 , wherein the first rule data is stored locally at the computing device together with at least second rule data corresponding to a second set of rules associated with a second user.

5. The storage medium of claim 4 , wherein the particular activity is not determined to be a potential violation when the second rule data is applied at the computing device.

6. The storage medium of claim 4 , wherein the instructions when executed further cause the machine to:

identify that a second user uses the computing device during a second session;

use the second rule data to monitor user activity on the computing device during the second session;

detect, at the computing device, the particular activity performed by the second user on the computing device during the second session;

determine, based on the second rule data, that the particular activity performed by the second user comprises a second potential violation;

send a second report to the risk assessment engine identifying the second potential violation detected at the computing device; and

receive an indication from the risk assessment engine, responsive to the second report, that the second potential violation is not a violation.

7. The storage medium of claim 4 , wherein the instructions when executed further cause the machine to:

identify that a second user uses the computing device during a second session;

use the second rule data to monitor user activity on the computing device during the second session;

detect, at the computing device, the particular activity performed by the second user on the computing device during the second session; and

determine, based on the second rule data, that the particular activity performed by the second user does not comprise a second potential violation.

8. The storage medium of claim 1 , wherein the first set of rules is generated at the risk assessment engine based on the behavior profile.

9. The storage medium of claim 8 , wherein the first set of rules is modified based on the first report.

10. The storage medium of claim 1 , wherein the report describes context information related to the particular activity.

11. The storage medium of claim 10 , wherein the context information describes another activity performed by the user at the computing device during the first session.

12. The storage medium of claim 1 , wherein the first rule data is used by a software-implemented agent installed on the computing device and the agent determines that the particular activity performed by the first user comprises the first potential violation.

13. The storage medium of claim 12 , wherein the agent communicates directly with the risk assessment engine.

14. The storage medium of claim 12 , wherein the indication of the violation triggers a countermeasure to be applied at the computing device.

15. The storage medium of claim 14 , wherein the countermeasure is deployed, at least in part, using the agent.

16. The storage medium of claim 14 , wherein the indication comprises instructions for use by the agent in deploying the countermeasure.

17. The storage medium of claim 1 , wherein the report includes an indication that the particular activity was performed by the first user.

18. The system of claim 3 , wherein the rule data comprises first rule data, and the first rule data is stored in the memory together with second rule data corresponding to a second set of rules associated with a second user.

19. The system of claim 3 , wherein the system further comprises the risk assessment engine, and the risk assessment engine is executable to:

receive reports from a plurality of computing devices reporting respective potential violations determined at the computing devices;

determine whether the potential violations qualify as one of a plurality of defined use violations; and

determine a behavioral risk score for the first user.

Assignments (20)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →