IP Library Granted Patent US 9,558,193
Granted Patent B2
US 9,558,193 · App. 15/096,093 · Granted Jan 31, 2017

Detecting behavioral patterns and anomalies using activity data

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,558,193
App. No.
15/096,093
Granted
Jan 31, 2017
Kind
B2
Abstract

Activity data is analyzed or evaluated to detect behavioral patterns and anomalies. When a particular pattern or anomaly is detected, a system may send a notification or perform a particular task. This activity data may be collected in an information management system, which may be policy based. Notification may be by way e-mail, report, pop-up message, or system message. Some tasks to perform upon detection may include implementing a policy in the information management system, disallowing a user from connecting to the system, and restricting a user from being allowed to perform certain actions. To detect a pattern, activity data may be compared to a previously defined or generated activity profile.

Claims (71)

1. A method of managing information of a system comprising:

providing a plurality of information management rules;

providing an activity database;

gathering activity data from a first target in the activity database;

gathering activity data from a second target in the activity database, wherein the first target is a different entity from the second target;

associating at least a first rule of the plurality of information management rules to the first target;

evaluating the gathered activity data from the first and second targets according to a detection algorithm, wherein the detection algorithm detects at least one of:

a first condition comprising the first target has attempted to access a unit of information more than X1 times in a Y1 time period; or

a second condition comprising the first target has attempted to access more than X2 units of information in a Y2 time period;

based on the detection algorithm, determining at least one of the first or second conditions has occurred, associating a second rule of the plurality of information management rules to the first target;

for the first target, controlling usage of information based on the at least first rule and second rule of the plurality of information management rules;

based on the detection algorithm, determining at least one of the first or second conditions occurring, associating an additional second rule to the first target;

for the first target, controlling usage of information based on the at least first rule of the plurality of information management rules and the additional second rule;

for a first activity at the first target, evaluating whether the at least first rule of the plurality of information management rules applies based on the first activity; and

for the first activity at the first target, evaluating whether the additional second rule applies based on the first activity, wherein the additional second rule comprises a first abstraction, the first abstraction is defined in a first definition statement stored separately from the additional second rule and the first abstraction.

2. The method of claim 1 , wherein the detection algorithm detects at least one of further comprises:

a third condition comprising the first target has an aggregated usage time in a program above a time value X3 in a Y3 time period.

3. The method of claim 1 , wherein the activity database is stored on the first target.

4. The method of claim 1 , wherein the activity database is stored on a server where the plurality of information management rules is stored.

5. The method of claim 1 , wherein the activity database is stored on an intelligence server and the plurality of information management rules is stored on a policy server, where the policy and intelligence servers are separate and distinct from one another.

6. The method of claim 1 , further comprising:

based on the detection algorithm, adding the additional second rule to the plurality of information management rules.

7. The method of claim 1 , wherein the detection algorithm comprises executing an online analytical processing (OLAP) task of the first target.

8. The method of claim 1 , wherein values of X1 and Y1 are user selectable.

9. The method of claim 1 , wherein a value of X1 is an integer.

10. The method of claim 1 , wherein the detection algorithm detects the first target has attempted to transfer a document classified as confidential to the second target.

11. The method of claim 1 , wherein the detection algorithm detects the first target has attempted to transfer a document classified as confidential to a removable medium.

12. The method of claim 1 , wherein the removable medium includes a Universal Serial Bus (USB) device.

13. The method of claim 1 , wherein the detection algorithm detects the first target has attempted to transfer a document classified as confidential to a recipient outside the information management system.

14. The method of claim 1 , further comprising:

generating a report based on the detection algorithm.

15. The method of claim 1 , further comprising:

logging in the activity database a denial of access at the first target for an unsuccessful attempt to access information of the information management system by the first target.

16. The method of claim 1 , wherein the detection algorithm comprises at least one rule.

17. The method of claim 1 , wherein the evaluating the gathered activity data according to the detection algorithm detects an effectiveness of a policy.

18. The method of claim 1 wherein a value of X2 is an integer.

19. A method of managing information of a system comprising:

providing a plurality of information management rules;

providing an activity database;

gathering activity data from a first target in the activity database;

gathering activity data from a second target in the activity database, wherein the first target is a different entity from the second target;

associating at least a first rule of the plurality of information management rules to the first target;

evaluating the gathered activity data according to a detection algorithm, wherein the detection algorithm detects at least one of:

a first condition comprising the first target has attempted to access a unit of information more than X1 times in a Y1 time period; or

a second condition comprising the first target has attempted to access more than X2 units of information in a Y2 time period;

based on the detection algorithm, determining at least one of the first or second conditions has occurred, associating a second rule of the plurality of information management rules to the first target;

for the first target, controlling usage of information based on the at least first rule and second rule of the plurality of information management rules;

based on the detection algorithm, determining at least one of the first or second conditions occurring, associating an additional second rule to the first target;

for the first target, controlling usage of information based on the at least first rule of the plurality of information management rules and the additional second rule;

for a first activity at the first target, evaluating whether the at least first rule of the plurality of information management rules applies based on the first activity; and

for the first activity at the first target, evaluating whether the additional second rule applies based on the first activity, wherein the additional second rule comprises a first abstraction, the first abstraction is defined in a first definition statement stored separately from the additional second rule and the first abstraction, wherein the evaluating whether the additional second rule applies comprises:

retrieving the first definition statement; and

when evaluating the second rule, replacing the first abstraction of the additional second rule by the first definition statement.

20. A method of managing information of a system comprising:

providing a plurality of information management rules;

providing an activity database;

gathering activity data from a first target in the activity database;

gathering activity data from a second target in the activity database, wherein the first target is a different entity from the second target;

associating at least a first rule of the plurality of information management rules to the first target;

evaluating the gathered activity data according to a detection algorithm, wherein the detection algorithm detects at least one of:

a first condition comprising the first target has attempted to access a unit of information more than X1 times in a Y1 time period; or

a second condition comprising the first target has attempted to access more than X2 units of information in a Y2 time period;

based on the detection algorithm, determining at least one of the first or second conditions has occurred, associating a second rule of the plurality of information management rules to the first target;

for the first target, controlling usage of information based on the at least first rule and second rule of the plurality of information management rules;

based on the detection algorithm, determining at least one of the first or second conditions occurring, associating an additional second rule to the first target;

for the first target, controlling usage of information based on the at least first rule of the plurality of information management rules and the additional second rule;

for a first activity at the first target, evaluating whether the at least first rule of the plurality of information management rules applies based on the first activity;

for the first activity at the first target, evaluating whether the additional second rule applies based on the first activity, wherein the additional second rule comprises a first abstraction, the first abstraction is defined in a first definition statement stored separately from the additional second rule and the first abstraction, wherein the evaluating whether the additional second rule applies comprises:

retrieving the first definition statement; and

when evaluating the second rule, replacing the first abstraction of the additional second rule by the first definition statement; and

evaluating the additional second rule with the replaced first definition statement.

Assignments (1)
SECURITY AGREEMENT Recorded Jun 30, 2020
From: NEXTLABS, INC
To: ROSEBUD CAPITAL, LLC
Reel/Frame 053095/0330 →