IP Library Granted Patent US 10,291,638
Granted Patent B1
US 10,291,638 · App. 15/260,189 · Granted May 14, 2019

Cloud activity threat detection for sparse and limited user behavior data

Inventors: Sandeep Chandana (Fremont, CA); Santosh Raghuram Kumar (Mountain View, CA); Sekhar Sarukkai (Cupertino, CA); Satyanarayana Vummidi (Sunnyvale, CA); Madhavi Kavathekar (San Jose, CA); Vinay Gupta (San Jose, CA)
Assignee: Skyhigh Networks, LLC
H04L63/1425G06F7/24H04L63/1441G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,291,638
App. No.
15/260,189
Granted
May 14, 2019
Kind
B1
Abstract

A cloud security system and method implements cloud activity threat detection using analysis of cloud usage user behavior. In particular, the cloud security system and method implements threat detection for users, cloud service providers, or tenants (enterprises) of the cloud security system who are new or unknown to the cloud security system and therefore lacking sufficient cloud activity data to generate an accurate behavior model for effective threat detection. In accordance with embodiments of the present invention, the cloud security system and method performs user behavior analysis to generate generalized user behavior models for user groups, where each user group includes users with similar cloud usage behavior. The user behavior models of the user groups are assigned to users with sparse cloud activity data. In this manner, the cloud security system and method of the present invention ensures effective threat detection by using accurate and reliable user behavior models.

Claims (36)

1. A method of detecting anomalies in usage activities at one or more cloud-based service providers associated with users of an enterprise, the method comprising:

receiving, using a hardware processor, cloud usage activity data from activity logs of users accessing the one or more cloud-based service providers on behalf of the enterprise;

aggregating, using the hardware processor, the cloud usage activity data of the users over predetermined time intervals;

analyzing, using the hardware processor, the aggregated cloud usage activity data to generate a user behavior model for each user comprising one or more coefficients describing the user's cloud usage behavior;

analyzing, using the hardware processor, the user behavior models of the users to form user groups with similar user behavior;

generating, using the hardware processor, a generalized user behavior model for each user group, the generalized user behavior model comprising one or more coefficients describing the user group's cloud usage behavior;

for a user having sparse cloud usage activity data, assigning, using the hardware processor, the user to a user group and assigning, using the hardware processor, the generalized user behavior model of the user group as the user behavior model for the user;

generating, using the hardware processor, a threat detection threshold for each user using the coefficients of the user behavior model of the user and prior cloud usage data of the user belonging to a prior time period;

receiving, using the hardware processor, an event stream of cloud usage activity data of the users for a current time period;

detecting, using the hardware processor, anomalies in the cloud usage activities data of each user in the event stream using the threat detection threshold of the respective user, the anomalies indicating potential security risk associated with usage activities at the cloud-based service providers; and

performing an action based on the detected anomalies.

2. The method of claim 1 , further comprising:

storing, using the hardware processor, the cloud usage activity data and the aggregated cloud usage activity data in a database, the cloud usage activity data being stored as a time series of data for each user,

wherein the prior cloud usage data is provided from the database.

3. The method of claim 2 , wherein storing, using the hardware processor, the cloud usage activity data and the aggregated cloud usage activity data in a database comprises:

storing a set of cloud activity attributes associated with each service action at a cloud-based service provider, the set of cloud activity attributes comprising a number of bytes of data in the service action, a number of times the cloud-based service provider has been visited, or a number of reports being accessed.

4. The method of claim 1 , further comprising:

storing, using the hardware processor, the coefficients describing the user behavior models of the users in a database.

5. The method of claim 1 , wherein performing an action based on the detected anomalies comprises ranking the detected anomalies based on risk levels.

6. The method of claim 1 , wherein performing an action based on the detected anomalies comprises filtering the detected anomalies to remove anomalies having a low risk rating.

7. The method of claim 1 , wherein performing an action based on the detected anomalies comprises generating a report of the detected anomalies.

8. The method of claim 1 , wherein aggregating, using the hardware processor, the cloud usage activity data of the users over predetermined time intervals further comprises:

classifying, using the hardware processor, the aggregated cloud usage activity data into a first category of office-hour activity data and a second category of non-office-hour activity data.

9. The method of claim 1 , wherein analyzing, using the hardware processor, the user behavior models of the users to form user groups with similar user behavior further comprises:

identifying users with similar coefficient values in the user behavior models; and

grouping users with similar coefficient values in the user behavior models into a user group.

10. The method of claim 1 , wherein for a user having sparse cloud usage activity data, assigning, using the hardware processor, the user to a user group comprises:

identifying a user group having similar cloud activity attribute values as the user, the cloud activity attribute values relating to cloud usage activity data being measured; and

assigning the user to a user group with similar cloud activity attribute values.

11. The method of claim 10 , wherein identifying a user group having similar cloud activity attribute values as the user comprises:

identifying a user group having similar cloud activity attribute values as the user, the cloud activity attributes comprising a number of bytes of data in a service action, a number of times the one of the one or more cloud-based service providers has been visited, or a number of reports being accessed.

12. The method of claim 10 , wherein the steps of analyzing the aggregated cloud usage activity data to generate a user behavior model for each user to assigning the user to a user group and assigning the generalized user behavior model of the user group as the user behavior model for the user are repeated at a periodic interval to update the coefficients of the user behavior models of each user.

13. The method of claim 1 , wherein generating, using the hardware processor, the threat detection threshold for each user using the coefficients of the user behavior model of the user and prior cloud usage data of the user belonging to a prior time period comprises:

generating the threat detection threshold as a parameter level to indicate normal or abnormal cloud usage behavior.

14. The method of claim 1 , wherein generating, using the hardware processor, the threat detection threshold for each user using the coefficients of the user behavior model of the user and prior cloud usage data of the user belonging to a prior time period comprises:

generating the threat detection threshold as a criterion to indicate normal or abnormal cloud usage behavior.

Assignments (15)
ASSIGNMENT OF INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Apr 14, 2025
From: UBS AG, STAMFORD BRANCH
To: ACQUIOM AGENCY SERVICES LLC
Reel/Frame 070840/0598 →
INTERCOMPANY FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jan 24, 2025
From: SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 070618/0001 →
RELEASE OF SECURITY INTEREST Recorded Oct 28, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: SKYHIGH SECURITY LLC
Reel/Frame 069272/0570 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded May 9, 2022
From: SKYHIGH NETWORKS, LLC
To: SKYHIGH SECURITY LLC
Reel/Frame 059912/0601 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 046416/0286 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: SKYHIGH NETWORKS, LLC
Reel/Frame 054211/0739 →
CORRECTIVE ASSIGNMENT TO CORRECT THE RECEIVING PARTY DATA PREVIOUSLY RECORDED AT REEL: 046416 FRAME: 0286. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 19, 2020
From: SKYHIGH NETWORKS, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 054560/0325 →
CHANGE OF NAME Recorded Dec 18, 2018
From: SKYHIGH NETWORKS, INC.
To: SKYHIGH NETWORKS, LLC
Reel/Frame 049041/0961 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0286 →
SECURITY INTEREST Recorded Jul 20, 2018
From: SKYHIGH NETWORKS, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 046416/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 7, 2016
From: CHANDANA, SANDEEP; KUMAR, SANTOSH RAGHURAM; SARUKKAI, SEKHAR; VUMMIDI, SATYANARAYANA; KAVATHEKAR, MADHAVI; GUPTA, VINAY
To: SKYHIGH NETWORKS, INC.
Reel/Frame 040245/0537 →
Cited By (4)
US 12,204,650 US 12,463,978 US 12,526,319 US 12,598,188