IP Library Granted Patent US 10,447,712
Granted Patent B2
US 10,447,712 · App. 15/449,042 · Granted Oct 15, 2019

Systems and user interfaces for dynamic and interactive investigation of bad actor behavior based on automatic clustering of related data in various data structures

Inventors: Alexander Visbal (New York, NY); James Thompson (San Francisco, CA); Marvin Sum (Sunnyvale, CA); Jason Ma (Mountain View, CA); Bing Jie Fu (Redwood City, CA); Ilya Nepomnyashchiy (Mountain View, CA); Devin Witherspoon (Palo Alto, CA); Victoria Lai (Palo Alto, CA); Steven Berler (Menlo Park, CA); Alexei Smaliy (Palo Alto, CA); Suchan Lee (Redwood City, CA)
Assignee: Palantir Technologies Inc.
H04L63/1416G06F3/0482G06F3/04842G06F16/24578G06F16/287G06F16/9038G06Q40/00G06Q40/02H04L63/1425H04L63/1433G06F12/1036G06F16/34G06F21/552G06K9/6218G06K9/6253
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,447,712
App. No.
15/449,042
Granted
Oct 15, 2019
Kind
B2
Abstract

Embodiments of the present disclosure relate to a data analysis system that may automatically generate memory-efficient clustered data structures, automatically analyze those clustered data structures, automatically tag and group those clustered data structures, and provide results of the automated analysis and grouping in an optimized way to an analyst. The automated analysis of the clustered data structures (also referred to herein as data clusters) may include an automated application of various criteria or rules so as to generate a tiled display of the groups of related data clusters such that the analyst may quickly and efficiently evaluate the groups of data clusters. In particular, the groups of data clusters may be dynamically re-grouped and/or filtered in an interactive user interface so as to enable an analyst to quickly navigate among information associated with various groups of data clusters and efficiently evaluate those data clusters in the context of, for example, a fraud investigation.

Claims (62)

1. A computer system configured to provide a dynamic user interface relating to visualization of alerts of malicious network activity, the computer system comprising:

one or more electronic data structures configured to store a plurality of clusters of data items, wherein each cluster of data items represents a group of related malicious network activities; and

one or more hardware computer processors configured to execute software code to cause the computer system to:

access the plurality of clusters of data items from the one or more electronic data structures;

analyze the plurality of clusters of data items to determine, for each cluster of the plurality of clusters, respective types of malicious network activity associated with the clusters of data items;

group, into a plurality of groups of clusters, the plurality of clusters of data items such that each group of clusters of the plurality of groups of clusters comprises clusters of data items associated with respective same types of malicious network activity; and

provide a dynamic graphical user interface including a plurality of tiles each representing a different one of the plurality of groups of clusters, wherein each of the respective tiles includes at least:

respective indications of the types of malicious network activity associated with the respective tiles; and

respective numbers of data clusters included in the groups of clusters associated with the respective tiles representing the types of malicious network activity.

2. The computer system of claim 1 , wherein the one or more hardware computer processors are further configured to execute software code to cause the computer system to:

further analyze the plurality of clusters of data items to determine respective numbers of clusters of the plurality of clusters having each of a plurality of types of malicious network activity.

3. The computer system of claim 1 , wherein each of the respective tiles further includes:

respective time-based graphs showing events associated with data clusters of the respective groups of clusters associated with the respective tiles.

4. The computer system of claim 3 , wherein the one or more hardware computer processors are further configured to execute software code to cause the computer system to:

in response to selection of a tile of the plurality of tiles, update the graphical user interface such that the time-based graph associated with the selected tile is resized to be larger and comprise a greater portion of the graphical user interface.

5. The computer system of claim 3 , wherein each of the respective tiles further includes:

respective indications of numbers of critical malicious network activities associated with the respective tiles.

6. The computer system of claim 5 , wherein the plurality of tiles are spatially organized in the graphical user interface according to the numbers of critical malicious network activities associated with the respective tiles.

7. The computer system of claim 5 , wherein the plurality of tiles are each colored to indicate the respective numbers of critical malicious network activities associated with the respective tiles.

8. The computer system of claim 1 , wherein the one or more hardware computer processors are further configured to execute software code to cause the computer system to:

determine a change to a data item of a cluster of the plurality of clusters; and

at least one of:

re-analyze the plurality of clusters to determine respective types of malicious network activity associated with the clusters of data items, or

re-group the plurality of clusters of data items into a plurality of groups of clusters.

9. A computer system configured to provide a dynamic user interface relating to visualization of alerts of malicious activity, the computer system comprising:

one or more electronic data structures configured to store a plurality of clusters of data items, wherein each cluster of data items represents a group of related malicious activities; and

one or more hardware computer processors configured to execute software code to cause the computer system to:

access the plurality of clusters of data items from the one or more electronic data structures;

analyze the plurality of clusters of data items to determine, for each of the clusters, respective one or more attribute values associated with the respective clusters of data items;

provide a dynamic user interface configured to include at least indications of a plurality of types of attributes; and

in response to a user input selecting a first type of attribute, update the dynamic user interface to include at least:

indications of a first one or more attribute values associated with the first type of attribute, wherein each of the first one or more attribute values is indicated along with a corresponding graphical tile in the dynamic user interface; and

for each of the first one or more attribute values, and overlaid on the respective graphical tiles, respective numbers of data clusters associated with the respective one or more attribute values.

10. The computer system of claim 9 , wherein the one or more hardware computer processors are further configured to execute software code to cause the computer system to:

in response to a user input selecting a second type of attribute, update the dynamic user interface to include at least:

indications of a second one or more attribute values associated with the second type of attribute, wherein each of the second one or more attribute values is indicated along with a corresponding graphical tile in the dynamic user interface; and

for each of the second one or more attribute values, and overlaid on the respective graphical tiles, respective numbers of data clusters associated with the respective one or more attribute values.

11. The computer system of claim 9 , wherein each of the respective graphical tiles is further overlaid with:

respective time-based graphs showing events associated with data clusters associated with the respective one or more attribute values represented by the respective graphical tiles.

12. The computer system of claim 11 , wherein the one or more hardware computer processors are further configured to execute software code to cause the computer system to:

in response to selection of a graphical tile of the plurality of tiles, update the dynamic user interface such that the time-based graph associated with the selected graphical tile is resized to be larger and comprise a greater portion of the dynamic user interface.

13. The computer system of claim 11 , wherein each of the respective graphical tiles is further overlaid with:

respective indications of numbers of critical malicious activities associated with data clusters associated the respective tiles.

14. A computer system configured to provide a dynamic user interface relating to visualization of alerts of malicious network activity, the computer system comprising:

one or more electronic data structures configured to store a plurality of clusters of data items, wherein each cluster of data items represents a group of related malicious network activities; and

one or more hardware computer processors configured to execute software code to cause the computer system to:

access the plurality of clusters of data items from the one or more electronic data structures;

analyze the plurality of clusters of data items to determine, for each cluster of the plurality of clusters:

respective types of malicious network activity associated with the clusters of data items, and

respective criticalities of the malicious network activity represented by the respective clusters of data items; and

provide a dynamic user interface configured to include at least:

for each cluster of the plurality of clusters, a respective graphical tile representing an alert corresponding to the cluster, wherein the graphical tile visually indicates at least the criticality of the malicious network activity represented by the cluster and a type of the malicious network activity represented by the cluster.

15. The computer system of claim 14 , wherein the one or more hardware computer processors are further configured to execute software code to cause the computer system to:

in response to a user input selecting a first tile representing a first alert, update the dynamic user interface to display at least:

detailed information associated with the cluster associated with the first alert.

16. The computer system of claim 15 , wherein:

each respective graphical tile further visually indicates a time-based graph including events associated with data items of the respective clusters represented by the respective graphical tiles, and

the detailed information includes an enlarged time-based graph.

17. The computer system of claim 14 , wherein the graphical tile visually indicates that criticality of the malicious network activity represented by the cluster by at least one or an icon or a color.

18. The computer system of claim 14 , wherein the dynamic user interface is further configured to include at least:

a first visualization indicating, for each type of malicious network activity of the plurality of types of malicious network activity, respective portions of the plurality of clusters having the type of malicious network activity; and

a second visualization comprising a chart indicating, over a period of time, numbers of malicious network activities.

Assignments (8)
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 15, 2017
From: VISBAL, ALEXANDER; THOMPSON, JAMES; SUM, MARVIN; MA, JASON; FU, BING JIE; NEPOMNYASHCHIY, ILYA; WITHERSPOON, DEVIN; LAI, VICTORIA; BERLER, STEVEN; SMALIY, ALEXEI; LEE, SUCHAN
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 042385/0479 →