IP Library Granted Patent US 10,505,965
Granted Patent B2
US 10,505,965 · App. 15/253,263 · Granted Dec 10, 2019

User behavioral risk assessment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,505,965
App. No.
15/253,263
Granted
Dec 10, 2019
Kind
B2
Abstract

A particular activity performed by a particular user of a computing device is identified, for instance, by an agent installed on the computing device. It is determined that the particular activity qualifies as a particular use violation in a plurality of pre-defined use violations. A behavioral risk score for the particular score for the user is determined based at least in part on the determination that the particular activity of the particular user qualifies as a particular use violation. Determining that the particular activity qualifies as a particular use violation can include determining that the particular activity violates a particular rule or event trigger corresponding to a particular pre-defined use violation.

Claims (48)

1. At least one non-transitory machine accessible storage medium having instructions stored thereon, the instructions when executed on a machine, cause the machine to:

develop a behavioral profile associated with a particular user to characterize the user's behavior;

analyze data from a computing device, wherein the data describes:

at least one of a plurality of activities by the particular user at the computing device, and

at least one identifier associated with the computing device, wherein the at least one identifier comprises one or more of a MAC address or an IP address;

detect that the data indicates a security threat, based at least in part on a determination that the data indicates a deviation from the behavior of the behavioral profile; and

initiate one or more countermeasures to attempt to mitigate against the security threat,

wherein the one or more countermeasures restrict access by the computing device to one or more computing resources, and

wherein the one or more countermeasures require reauthentication of the computing device to allow access to the one or more computing resources.

2. The storage medium of claim 1 , wherein the instructions, when executed, further cause the machine to:

determine an association between the computing device and the particular user; and

associate the behavioral profile with the data received from the computing device based on the association.

3. The storage medium of claim 1 , wherein the one or more countermeasures restrict network access by the computing device.

4. The storage medium of claim 3 , wherein the one or more countermeasures comprise a web gateway.

5. The storage medium of claim 3 , wherein the one or more countermeasures comprise a firewall.

6. The storage medium of claim 1 , wherein the computing resources comprise one or more files.

7. The storage medium of claim 1 , wherein the one or more countermeasures disable the computing device.

8. The storage medium of claim 1 , wherein the plurality of activities comprise an authentication action performed at the computing device.

9. The storage medium of claim 8 , wherein the behavioral profile is based on one or more authentication actions performed by the particular user.

10. The storage medium of claim 1 , wherein the behavioral profile is based at least in part on email use of the particular user.

11. The storage medium of claim 1 , wherein the behavioral profile is based at least in part on online activities performed by the particular user.

12. The storage medium of claim 1 , wherein the behavioral profile is based at least in part on compliance, by the particular user, with a set of security policies.

13. The storage medium of claim 12 , wherein the set of security policies comprise policies of a particular organization.

14. The storage medium of claim 1 , wherein the instructions, when executed, further cause the machine to:

determine, from the data, that a particular one of a plurality of predefined use violations has been performed at the computing device.

15. The storage medium of claim 14 , wherein the data indicates detection of the particular predefined use violation by the computing device.

16. The storage medium of claim 14 , wherein detecting that the data indicates the security threat is further based on the particular predefined use violation.

17. A method comprising:

developing a behavioral profile associated with a particular user to characterize the user's behavior;

analyzing data from a computing device, wherein the data describes:

at least one of a plurality of activities by the particular user at the computing device, and

at least one identifier associated with the computing device, wherein the at least one identifier comprises one or more of a MAC address or an IP address;

detecting that the data indicates a security threat, based at least in part on a determination that the data indicates a deviation from the behavior of the behavioral profile; and

initiating one or more countermeasures to attempt to mitigate against the security threat,

wherein the one or more countermeasures restrict access by the computing device to one or more computing resources, and

wherein the one or more countermeasures require reauthentication of the computing device to allow access to the one or more computing resources.

18. A system comprising:

at least one processor;

at least one memory;

a risk engine, executable by the at least one processor, to:

develop a behavioral profile associated with a particular user to characterize the user's behavior;

analyze data from a computing device, wherein the data describes:

at least one of a plurality of activities by the particular user at the computing device, and

at least one identifier associated with the computing device, wherein the at least one identifier comprises one or more of a MAC address or an IP address;

detect that the data indicates a security threat, based at least in part on a determination that the data indicates a deviation from the behavior of the behavioral profile; and

initiate performance of one or more security activities to attempt to mitigate against the security threat, wherein the one or more security activities comprise forcing forced re-authentication of the computing device.

19. The system of claim 18 , further comprising one or more security tools, wherein the risk engine is executable to invoke the security tools to perform the one or more security activities.

20. The system of claim 19 , wherein at least a portion of the one or more security tools are hosted on the computing device and another portion of the one or more security tools are hosted remote from the computing device.

Assignments (20)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 061007/0124 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →