IP Library Granted Patent US 9,946,717
Granted Patent B2
US 9,946,717 · App. 15/421,281 · Granted Apr 17, 2018

Detecting behavioral patterns and anomalies using activity data

Inventor: Keng Lim (Atherton, CA)
Assignee: NextLabs, Inc.
G06F17/30091G06F17/30082G06F17/30165
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,946,717
App. No.
15/421,281
Granted
Apr 17, 2018
Kind
B2
Abstract

Activity data is analyzed or evaluated to detect behavioral patterns and anomalies. When a particular pattern or anomaly is detected, a system may send a notification or perform a particular task. This activity data may be collected in an information management system, which may be policy based. Notification may be by way e-mail, report, pop-up message, or system message. Some tasks to perform upon detection may include implementing a policy in the information management system, disallowing a user from connecting to the system, and restricting a user from being allowed to perform certain actions. To detect a pattern, activity data may be compared to a previously defined or generated activity profile.

Claims (59)

1. A method of managing information of a system comprising:

providing a plurality of information management rules;

providing an activity database;

gathering activity data from a first target in the activity database;

gathering activity data from a second target in the activity database;

associating at least a first rule of the plurality of information management rules to the first target;

evaluating the gathered activity data according to a detection algorithm, wherein the detection algorithm detects at least a first condition;

based on the detection algorithm, determining the first condition has occurred, and then associating a second rule to the first target;

for the first target, controlling usage of the information based on the at least first rule of the plurality information management rules and the second rule;

for a first activity at the first target, evaluating whether the at least first rule of the plurality of information management rules applies based on the first activity; and

for the first activity at the first target, evaluating whether the second rule applies based on the first activity, wherein the second rule comprises a first abstraction, the first abstraction is defined in a first definition statement stored separately from the second rule and the first abstraction.

2. The method of claim 1 , wherein the first condition comprises the first target having attempted to access a unit of information more than X1 times in a Y1 time period.

3. The method of claim 1 , wherein the first condition comprises the first target having attempted to access more than X2 units of information in a Y2 time period.

4. The method of claim 1 , wherein the first condition comprises the first target having an aggregated usage time in a program above a time value X3 in a Y3 time period.

5. The method of claim 1 , wherein the evaluating whether the second rule applies comprising:

retrieving the first definition statement, and when evaluating the second rule, replacing the first abstraction of the second rule by the first definition statement.

6. The method of claim 1 , wherein the activity database is stored on the first target.

7. The method of claim 1 , wherein the activity database is stored on a server where the plurality of information management rules is stored.

8. The method of claim 1 , wherein the activity database is stored on an intelligence server and the plurality of information management rules is stored on a policy server, where the policy and intelligence servers are separate.

9. The method of claim 1 , further comprising:

based on the detection algorithm, adding the second rule to the plurality of information management rules.

10. A method of managing information of a system comprising:

providing a plurality of information management rules;

providing an activity database;

gathering activity data from a first target in the activity database;

gathering activity data from a second target in the activity database;

associating at least a first rule of the plurality of information management rules to the first target;

evaluating the gathered activity data according to a detection algorithm, wherein the detection algorithm detects at least a first condition;

based on the detection algorithm, determining the first condition has occurred, and then associating a second rule to the first target;

for the first target, controlling usage of the information based on the at least first rule of the plurality of information management rules and the second rule;

based on the detection algorithm, determining the first condition has occurred, associating an additional second rule to the first target;

for the first target, controlling the usage of the information based on the at least first rule of the plurality of information management rules and the additional second rule;

for a first activity at the first target, evaluating whether the at least first rule of the plurality of information management rules applies based on the first activity; and

for the first activity at the first target, evaluating whether the additional second rule applies based on the first activity, wherein the additional second rule comprises a first abstraction, the first abstraction is defined in a first definition statement stored separately from the additional second rule and the first abstraction.

11. The method of claim 10 , wherein the first condition comprises the first target having attempted to access a unit of information more than X1 times in a Y1 time period.

12. The method of claim 10 , wherein the first condition comprises the first target having attempted to access more than X2 units of information in a Y2 time period.

13. The method of claim 10 , wherein the evaluating whether the additional second rule applies comprising:

retrieving the first definition statement; and

when evaluating the second rule, replacing the first abstraction of the additional second rule by the first definition statement.

14. The method of claim 13 , further comprising:

evaluating the second rule with the replaced first definition statement.

15. The method of claim 10 , wherein the activity database is stored on the first target.

16. The method of claim 10 , wherein the activity database is stored on a server where the plurality of information management rules is stored.

17. The method of claim 10 , wherein the activity database is stored on an intelligence server and the plurality of information management rules is stored on a policy server, where the policy and intelligence servers are separate.

18. The method of claim 10 , further comprising:

based on the detection algorithm, adding the additional second rule to the plurality of information management rules.

19. A method of managing information of a system comprising:

providing a plurality of information management rules;

providing an activity database;

gathering activity data from a first target in the activity database;

gathering activity data from a second target in the activity database;

associating at least a first rule of the plurality of information management rules to the first target;

evaluating the gathered activity data according to a detection algorithm, wherein the detection algorithm detects at least a first condition;

based on the detection algorithm, determining the first condition has occurred, and then associating a second rule to the first target;

for the first target, controlling usage of the information based on the at least first rule of the plurality of information management rules and the second rule;

for a first activity at the first target, evaluating whether the at least first rule of the plurality of information management rules applies based on the first activity; and

for the first activity at the first target, evaluating whether the second rule applies based on the first activity, wherein the second rule comprises a first abstraction, the first abstraction is defined in a first definition statement stored separately from the second rule and the first abstraction, and the evaluating whether the second rule applies comprises retrieving the first definition statement, and when evaluating the second rule, replacing the first abstraction of the second rule by the first definition statement.

20. The method of claim 19 , further comprising:

evaluating the second rule with the replaced first definition statement.

Assignments (1)
SECURITY AGREEMENT Recorded Jun 30, 2020
From: NEXTLABS, INC
To: ROSEBUD CAPITAL, LLC
Reel/Frame 053095/0330 →
Continuity (12)
Continuation 15096093 · Apr 11, 2016
Continuation 14513731 · Oct 14, 2014
Continuation 11615657 · Dec 22, 2006
Continuation In Part 11383159 · May 12, 2006
Continuation In Part 11383161 · May 12, 2006
Continuation In Part 11383164 · May 12, 2006
Provisional Application 60755019 · Dec 29, 2005
Provisional Application 60766036 · Dec 29, 2005
Provisional Application 60743121 · Jan 11, 2006
Provisional Application 60821050 · Aug 1, 2006
Provisional Application 60870195 · Dec 15, 2006
Related Publication 20170142125A1 · May 18, 2017