IP Library Granted Patent US 10,447,718
Granted Patent B2
US 10,447,718 · App. 15/979,023 · Granted Oct 15, 2019

User profile definition and management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,447,718
App. No.
15/979,023
Granted
Oct 15, 2019
Kind
B2
Abstract

A method, system and computer-usable medium for performing a security analysis operation within a security environment, comprising: monitoring electronically-observable user behavior about a particular entity; maintaining a state about the particular entity, the state representing a context of a particular event; converting the electronically-observable user behavior into electronic information representing the electronically-observable user behavior; generating a user behavior profile based upon the electronic information representing the electronically-observable user behavior; and, analyzing the event using the state of the entity and the user behavior profile.

Claims (63)

1. A computer-implementable method for performing a security analysis operation within a security environment, comprising:

monitoring electronically-observable user behavior about a particular entity;

maintaining a state about the particular entity, the state representing a context of a particular event;

converting the electronically-observable user behavior into electronic information representing the electronically-observable user behavior;

generating a user behavior profile based upon the electronic information representing the electronically-observable user behavior, the user behavior profile comprising a collection of information that describes the particular entity, the collection of information comprising at least one of a user profile attribute, a user behavior factor and a user mindset factor;

generating a mindset profile for the particular entity, the mindset profile representing aspects of the particular entity that are inferred based upon the electronically-observable user behavior, the mindset profile being generated using a combination of the user behavior profile and the state;

performing a security analysis operation via a security analytics system, the security analysis operation analyzing the event using the state of the entity, the mindset profile and the user behavior profile, the analyzing determining whether the electronically-observable user behavior about the particular entity does not correspond to known good behavior, the security analysis operation determining that the particular entity represents a security threat to an organization associated with the security analytics system when the electronically-observable user behavior about the particular entity does not correspond to known good behavior; and,

performing an enforcement operation when the electronically-observable user behavior about the particular entity does not correspond to known good behavior.

2. The method of claim 1 , further comprising:

associating the mindset profile within the user behavior profile.

3. The method of claim 1 , further comprising:

associating a higher-level meaning with the event based upon the analyzing.

4. The method of claim 1 , wherein:

the analyzing calculates how anomalous the event is.

5. The method of claim 1 , wherein:

the monitoring electronically-observable user behavior comprises monitoring a plurality of points of observability, at least some of the plurality of points of observability corresponding to respective layers of user interaction; and,

each of the plurality of points of observability is converted into respective electronic information representing respective points of observability.

6. The method of claim 5 , wherein:

the plurality of points of observability comprise an action based point of observability, an activity based point of observability and a behavior based point of observability.

7. The method of claim 5 , wherein:

the plurality of points of observability observer user behavior within at least one of a physical domain and a cyberspace environment.

8. The method of claim 1 , wherein:

the user behavior profile comprises a multi-faceted user behavior profile comprising a plurality of facets, each of the plurality of facets corresponding to at least one of a user authentication factor, a user identification factor and a user behavior factor.

9. The method of claim 1 , further comprising:

identifying certain electronically-observable user behavior used for generating the user behavior profile as known good behavior;

determining whether additional electronically-observable user behavior do not correspond to the known good behavior; and,

performing an enforcement operation when additional electronically-observable user behavior do not correspond to the known good behavior.

10. The method of claim 8 , further comprising:

monitoring an information technology environment using the user behavior profile;

performing an enforcement operation if a user interaction with the information technology environment does not correspond to interactions based upon the user behavior profile.

11. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code for generating a user behavior profile, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring electronically-observable user behavior about a particular entity;

maintaining a state about the particular entity, the state representing a context of a particular event;

converting the electronically-observable user behavior into electronic information representing the electronically-observable user behavior;

generating a user behavior profile based upon the electronic information representing the electronically-observable user behavior, the user behavior profile comprising a collection of information that describes the particular entity, the collection of information comprising at least one of a user profile attribute, a user behavior factor and a user mindset factor;

generating a mindset profile for the particular entity, the mindset profile representing aspects of the particular entity that are inferred based upon the electronically-observable user behavior, the mindset profile being generated using a combination of the user behavior profile and the state;

performing a security analysis operation via a security analytics system, the security analysis operation analyzing the event using the state of the entity, the mindset profile and the user behavior profile, the analyzing determining whether the electronically-observable user behavior about the particular entity does not correspond to known good behavior, the security analysis operation determining that the particular entity represents a security threat to an organization associated with the security analytics system when the electronically-observable user behavior about the particular entity does not correspond to known good behavior; and,

performing an enforcement operation when the electronically-observable user behavior about the particular entity does not correspond to known good behavior.

12. The system of claim 11 , wherein the instructions executable by the processor are further configured for:

associating the mindset profile within the user behavior profile.

13. The system of claim 11 , wherein:

associating a higher-level meaning with the event based upon the analyzing.

14. The system of claim 11 , wherein:

the analyzing calculates how anomalous the event is.

15. The system of claim 11 , wherein:

the monitoring electronically-observable user behavior comprises monitoring a plurality of points of observability, at least some of the plurality of points of observability corresponding to respective layers of user interaction; and,

each of the plurality of points of observability is converted into respective electronic information representing respective points of observability.

16. The system of claim 15 , wherein:

the plurality of points of observability comprise an action based point of observability, an activity based point of observability and a behavior based point of observability.

17. The system of claim 15 , wherein:

the plurality of points of observability observer user behavior within at least one of a physical domain and a cyberspace environment.

18. The system of claim 11 , wherein:

the user behavior profile comprises a multi-faceted user behavior profile comprising a plurality of facets, each of the plurality of facets corresponding to at least one of a user authentication factor, a user identification factor and a user behavior factor.

19. The system of claim 18 , wherein the instructions executable by the processor are further configured for:

identifying certain electronically-observable user behavior used for generating the user behavior profile as known good behavior;

determining whether additional electronically-observable user behavior do not correspond to the known good behavior; and,

performing an enforcement operation when additional electronically-observable user behavior do not correspond to the known good behavior.

20. The system of claim 18 , wherein the instructions executable by the processor are further configured for:

monitoring an information technology environment using the plurality of user behavior profiles;

performing an enforcement operation if a user interaction with the information technology environment does not correspond to interactions based upon at least one of the plurality of user behavior profiles.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055492/0266 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Jul 6, 2018
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 046495/0561 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2018
From: FORD, RICHARD ANTHONY
To: FORCEPOINT, LLC
Reel/Frame 046166/0731 →