IP Library Granted Patent US 10,949,428
Granted Patent B2
US 10,949,428 · App. 16/033,770 · Granted Mar 16, 2021

Constructing event distributions via a streaming scoring operation

Inventors: Christopher Poirel (Baltimore, MD); William Renner (Baltimore, MD); Eduardo Luiggi (Ellicott City, MD); Phillip Bracikowski (Indianapolis, IN)
Assignee: Forcepoint, LLC
G06F16/24568G06F7/14G06F16/285
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,949,428
App. No.
16/033,770
Granted
Mar 16, 2021
Kind
B2
Abstract

A method, system and computer-usable medium for performing a streaming scoring operation, comprising: receiving a stream of events, the stream of events comprising a plurality of events; ingesting the plurality of events; extracting features from the plurality of events to provide extracted features; and, generating a streaming scoring value based upon the extracted features.

Claims (71)

1. A computer-implementable method for performing a streaming scoring operation, comprising:

receiving a stream of events, the stream of events comprising a plurality of events, each of the plurality of events referring to an occurrence of an action performed by an entity;

ingesting the plurality of events into a streaming query framework;

extracting features from the plurality of events to provide extracted features via the streaming query framework;

generating a streaming scoring value based upon the extracted features via the streaming query framework; and,

using the streaming scoring value to identify anomalous, abnormal, unexpected or malicious behavior associated with the entity.

2. The method of claim 1 , further comprising:

performing a statistical distribution operation on the extracted features when generating the streaming scoring value, the statistical-distribution operation determining probability distributions of the extracted features.

3. The method of claim 1 , further comprising:

generating a scoring container, and wherein

when extracting features from the plurality of events using the scoring container to identify any outliers from the plurality of extracted features.

4. The method of claim 3 , wherein:

the scoring container is one of a plurality of scoring containers; and further comprising

merging the plurality of scoring containers by combining scoring containers across a plurality of time intervals.

5. The method of claim 1 , further comprising:

determining whether an event matches a query associated with a particular feature;

applying the query to the stream of events; and

classifying a plurality of ingested events based upon whether the plurality of ingested events match the query.

6. The method of claim 5 , wherein:

the query is included within a set of queries;

the set of queries comprise a set of defined queries, each of the set of defined queries comprising an associated feature; and,

applying the set of queries to the stream of events results in categorization of each event with respect to features associated with a subset of queries for which each event matches.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

receiving a stream of events, the stream of events comprising a plurality of events, each of the plurality of events referring to an occurrence of an action performed by an entity;

ingesting the plurality of events into a streaming query framework;

extracting features from the plurality of events to provide extracted features via the streaming query framework;

generating a streaming scoring value based upon the extracted features via the streaming query framework; and,

using the streaming scoring value to identify anomalous, abnormal, unexpected or malicious behavior associated with the entity.

8. The system of claim 7 , wherein the instructions are further configured for:

performing a statistical distribution operation on the extracted features when generating the streaming scoring value, the statistical distribution operation determining statistical distributions of the matching features.

9. The system of claim 7 , wherein the instructions are further configured for:

generating a scoring container, and wherein

when extracting features from the plurality of events using the scoring container to identify any outliers from the plurality of events.

10. The system of claim 9 , wherein:

the scoring container is one of a plurality of scoring containers; and further comprising

merging the plurality of scoring containers by combining scoring containers across a plurality of time intervals.

11. The system of claim 7 , wherein:

determining whether an event matches a query associated with a particular feature;

applying the query to the stream of events; and

classifying a plurality of ingested events based upon whether the plurality of ingested events match the query.

12. The system of claim 11 , wherein:

the query is included within a set of queries;

the set of queries comprise a set of defined queries, each of the set of defined queries comprising an associated feature; and,

applying the set of queries to the stream of events results in categorization of each event with respect to features associated with a subset of queries for which each event matches.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

receiving a stream of events, the stream of events comprising a plurality of events, each of the plurality of events referring to an occurrence of an action performed by an entity;

ingesting the plurality of events into a streaming query framework;

extracting features from the plurality of events to provide extracted features via the streaming query framework;

generating a streaming scoring value based upon the extracted features via the streaming query framework; and,

using the streaming scoring value to identify anomalous, abnormal, unexpected or malicious behavior associated with the entity.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

performing a statistical distribution operation on the extracted features when generating the streaming scoring value, the statistical distribution operation determining statistical distributions of the extracted features.

15. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

generating a scoring container, and wherein

when extracting features from the plurality of events using the scoring container to identify any outliers from the plurality of events.

16. The non-transitory, computer-readable storage medium of claim 15 , wherein:

the scoring container is one of a plurality of scoring containers; and further comprising

merging the plurality of scoring containers by combining scoring containers across a plurality of time intervals.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

determining whether an event matches a query associated with a particular feature;

applying the query to the stream of events; and

classifying a plurality of ingested events based upon whether the plurality of ingested events match the query.

18. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the query is included within a set of queries;

the set of queries comprise a set of defined queries, each of the set of defined queries comprising an associated feature; and,

applying the set of queries to the stream of events results in categorization of each event with respect to features associated with a subset of queries for which each event matches.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0524 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2018
From: POIREL, CHRISTOPHER; RENNER, WILLIAM; LUIGGI, EDUARDO; BRACIKOWSKI, PHILLIP
To: FORCEPOINT, LLC
Reel/Frame 046334/0451 →