IP Library Granted Patent US 10,841,321
Granted Patent B1
US 10,841,321 · App. 15/472,231 · Granted Nov 17, 2020

Systems and methods for detecting suspicious users on networks

Inventor: Anand Athavle (San Jose, CA)
Assignee: Veritas Technologies LLC
H04L63/1425G06F16/24575G06F16/24578H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,841,321
App. No.
15/472,231
Granted
Nov 17, 2020
Kind
B1
Abstract

The disclosed computer-implemented method for detecting suspicious users on networks may include (1) identifying a first cluster of users based on at least one static attribute of the users; (2) identifying a second cluster of users based on both the at least one static attribute of the users and at least one dynamic attribute of the users, where a respective dynamic attribute weight applied to the at least one dynamic attribute when defining the second clusters is based on network monitoring telemetry; (3) comparing the first cluster with the second cluster to identify an outlying user; and (4) designating the outlying user as suspicious.

Claims (89)

1. A computer-implemented method for detecting suspicious users on networks, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

calculating connection weights between users by adding respective static attribute weights of the users when the users have the same static attribute weights;

identifying a first cluster of users based on the calculated connection weights;

identifying a second cluster of users based on both at least one static attribute of the users and at least one dynamic attribute of the users, wherein the identifying the second cluster of users comprises:

adjusting the calculated connection weight between a set of users to create an adjusted connection weight by:

multiplying the calculated connection weight between the set of users by a predetermined factor when a respective dynamic attribute weight of the set of users is within a predetermined range; and

dividing the calculated connection weight between the set of users by the predetermined factor when the respective dynamic attribute weight of the set of users is outside of the predetermined range; and

identifying the second cluster of users based on the adjusted connection weight;

comparing the first cluster with the second cluster to identify an outlying user; and

designating the outlying user as suspicious.

2. The computer-implemented method of claim 1 , wherein the comparing further comprises comparing distances between locations of each user in the first cluster and the second cluster to identify the outlying user.

3. The computer-implemented method of claim 1 , wherein the at least one static attribute is based on a user profile.

4. The computer-implemented method of claim 3 , wherein the user profile comprises at least one of:

a job title;

a job grade;

a job location;

a job department;

a country; and

a primary language.

5. The computer-implemented method of claim 1 , wherein the at least one dynamic attribute is based on user behavior.

6. The computer-implemented method of claim 5 , wherein the user behavior comprises at least one of:

a number of files accessed;

a number of file permissions;

a number of file reads;

a number of file writes;

a number of file creates;

a number of file deletes;

a number of file permission changes;

a number of file renames;

a number of files to which the user has access;

a number of internet protocol addresses that the user accesses; and

a number of files that the user owns.

7. The computer-implemented method of claim 1 , further comprising performing at least one security action in response to designating the outlying user as suspicious.

8. A system for detecting suspicious users on networks, the system comprising:

an identifying module, stored in memory, that:

calculates connection weights between users by adding respective static attribute weights of the users when the users have the same static attribute weights;

identifies a first cluster of users based on the calculated connection weights; and

identifies a second cluster of users based on both the at least one static attribute of the users and at least one dynamic attribute of the users, wherein the identifying the second cluster of users comprises:

adjusting the calculated connection weight between a set of users to create an adjusted connection weight by:

multiplying the calculated connection weight between the set of users by a predetermined factor when a respective dynamic attribute weight of the set of users is within a predetermined range; and

dividing the calculated connection weight between the set of users by the predetermined factor when the respective dynamic attribute weight of the set of users is outside of the predetermined range; and

identifying the second cluster of users based on the adjusted connection weight;

a comparing module, stored in memory, that compares the first cluster with the second cluster to identify an outlying user;

a designating module, stored in memory, that designates the outlying user as suspicious; and

at least one physical processor that executes the identifying module, the comparing module, and the designating module.

9. The system of claim 8 , wherein the comparing further comprises comparing distances between locations of each user in the first cluster and the second cluster to identify the outlying user.

10. The system of claim 8 , wherein the at least one static attribute is based on a user profile.

11. The system of claim 10 , wherein the user profile comprises at least one of:

a job title;

a job grade;

a job location;

a job department;

a country; and

a primary language.

12. The system of claim 8 , wherein the at least one dynamic attribute is based on user behavior.

13. The system of claim 12 , wherein the user behavior comprises at least one of:

a number of files accessed;

a number of file permissions;

a number of file reads;

a number of file writes;

a number of file creates;

a number of file deletes;

a number of file permission changes;

a number of file renames;

a number of files to which the user has access;

a number of internet protocol addresses that the user accesses; and

a number of files that the user owns.

14. The system of claim 8 , further comprising a security module, stored in memory, that performs at least one security action in response to designating the outlying user as suspicious.

15. A non-transitory computer-readable medium comprising one or more computer-executable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

calculate connection weights between users by adding respective static attribute weights of the users when the users have the same static attribute weights;

identify a first cluster of users based on the calculated connection weights;

identify a second cluster of users based on both at least one static attribute of the users and at least one dynamic attribute of the users, wherein the identifying the second cluster of users comprises:

adjusting the calculated connection weight between a set of users to create an adjusted connection weight by:

multiplying the calculated connection weight between the set of users by a predetermined factor when a respective dynamic attribute weight of the set of users is within a predetermined range; and

dividing the calculated connection weight between the set of users by the predetermined factor when the respective dynamic attribute weight of the set of users is outside of the predetermined range; and

identifying the second cluster of users based on the adjusted connection weight;

compare the first cluster with the second cluster to identify an outlying user; and

designate the outlying user as suspicious.

16. The non-transitory computer-readable medium of claim 15 , wherein the computer-executable instructions that cause the computing device to compare the first cluster with the second cluster further comprise computer-executable instructions that cause the computing device to compare distances between locations of each user in the first cluster and the second cluster to identify the outlying user.

17. The non-transitory computer-readable medium of claim 15 , wherein the at least one static attribute is based on a user profile.

18. The non-transitory computer-readable medium of claim 15 , further comprising computer-executable instructions that cause the computing device to perform at least one security action in response to designating the outlying user as suspicious.

19. The non-transitory computer-readable medium of claim 17 , wherein the user profile comprises at least one of:

a job title;

a job grade;

a job location;

a job department;

a country; and

a primary language.

20. The non-transitory computer-readable medium of claim 15 , further comprising computer-executable instructions that cause the computing device to perform at least one security action in response to designating the outlying user as suspicious.

Assignments (13)
SECURITY INTEREST Recorded Dec 12, 2025
From: ARCTERA US LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 073951/0470 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT R/F 069585/0150 Recorded Dec 1, 2025
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: ARCTERA US LLC
Reel/Frame 073833/0848 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT R/F 070530/0497 Recorded Dec 1, 2025
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: ARCTERA US LLC
Reel/Frame 073833/0730 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069574/0931 →
PATENT SECURITY AGREEMENT Recorded Dec 10, 2024
From: ARCTERA US LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069585/0150 →
SECURITY INTEREST Recorded Dec 10, 2024
From: ARCTERA US LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 069563/0243 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC
To: ARCTERA US LLC
Reel/Frame 069548/0468 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 052426/0001 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 054535/0565 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Apr 16, 2020
From: VERITAS TECHNOLOGIES, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 052426/0001 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Jul 10, 2017
From: VERITAS TECHNOLOGIES LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 043141/0403 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2017
From: ATHAVLE, ANAND
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 041772/0212 →
Cited By (1)
US 12,395,845