IP Library Granted Patent US 11,436,512
Granted Patent B2
US 11,436,512 · App. 16/033,798 · Granted Sep 6, 2022

Generating extracted features from an event

Inventors: Christopher Poirel (Baltimore, MD); William Renner (Baltimore, MD); Eduardo Luiggi (Ellicott City, MD); Phillip Bracikowski (Indianapolis, IN)
Assignee: Forcepoint, LLC
G06N7/005H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,436,512
App. No.
16/033,798
Granted
Sep 6, 2022
Kind
B2
Abstract

A method, system and computer-usable medium for performing a feature generation operation. The performing a feature generation operation including: receiving a stream of events, the stream of events comprising a plurality of events; applying labels to applicable events from the plurality of events, the applying labels providing a labeled event; and, processing the labeled event to extract a feature from the labeled event, the processing providing a feature associated with an event.

Claims (59)

1. A computer-implementable method for performing a feature generation operation, comprising:

receiving a stream of data via a protected endpoint, the stream of data representing electronically-observable interactions by a user, the protected endpoint identifying a plurality of events from the interactions by the user;

applying labels to applicable events from the plurality of events, the applying labels providing a labeled events, the applying labels to applicable events facilitating identification of certain interrelated events from the plurality of events;

processing the labeled events to extract a feature from respective labeled events, the feature being associated with an event, the feature referring to a property, characteristic or attribute of the event;

analyzing the feature associated with the event;

generating a feature score for the feature associated with the event, the feature score being generated based upon a scoring container update operation, the scoring container update operation using a scoring container, the scoring container comprising a container implemented to provide an approximation of a probability distribution over the values the scoring container contains, based upon samples from the probability distribution;

generating a risk score for the user based on the analyzing; and,

performing a risk assessment operation via a security analytics system based on the feature associated with the event and the risk score.

2. The method of claim 1 , wherein:

the applying labels to the applicable events from the plurality of events classifies the applicable events from the plurality of events with associated metadata.

3. The method of claim 1 , wherein:

extracting features comprises performing transformation operations on certain features associated with an event to generate a smaller set of derived features.

4. The method of claim 3 , wherein:

the smaller set of derived features facilitates determination of a distribution of associated features corresponding to a particular event.

5. The method of claim 1 , wherein:

the feature associated with the event comprises at least one of a number of bytes uploaded, a time of day, a presence of certain terms in unstructured content, respective domains associated with senders and recipients of information, and a Uniform Resource Locator (URL) classification of a web page visit.

6. The method of claim 1 , wherein:

extracting features performs at least one of an exact feature extract operation and a multi match feature extract operation.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

receiving a stream of data via a protected endpoint, the stream of data representing electronically-observable interactions by a user, the protected endpoint identifying a plurality of events from the interactions by the user;

applying labels to applicable events from the plurality of events, the applying labels providing a labeled events, the applying labels to applicable events facilitating identification of certain interrelated events from the plurality of events;

processing the labeled events to extract a feature from respective labeled events, the feature being associated with an event, the feature referring to a property, characteristic or attribute of the event;

analyzing the feature associated with the event;

generating a feature score for the feature associated with the event, the feature score being generated based upon a scoring container update operation, the scoring container update operation using a scoring container, the scoring container comprising a container implemented to provide an approximation of a probability distribution over the values the scoring container contains, based upon samples from the probability distribution;

generating a risk score for the user based on the analyzing; and,

performing a risk assessment operation via a security analytics system based on the feature associated with the event and the risk score.

8. The system of claim 7 , wherein:

the applying labels to the applicable events from the plurality of events classifies the applicable events from the plurality of events with associated metadata.

9. The system of claim 7 , wherein:

extracting features comprises performing transformation operations on certain features associated with an event to generate a smaller set of derived features.

10. The system of claim 9 , wherein:

the smaller set of derived features facilitates determination of a distribution of associated features corresponding to a particular event.

11. The system of claim 7 , wherein:

the feature associated with the event comprises at least one of a number of bytes uploaded, a time of day, a presence of certain terms in unstructured content, respective domains associated with senders and recipients of information, and a Uniform Resource Locator (URL) classification of a web page visit.

12. The system of claim 7 , wherein:

extracting features performs at least one of an exact feature extract operation and a multi match feature extract operation.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

receiving a stream of data via a protected endpoint, the stream of data representing electronically-observable interactions by a user, the protected endpoint identifying a plurality of events from the interactions by the user;

applying labels to applicable events from the plurality of events, the applying labels providing a labeled events, the applying labels to applicable events facilitating identification of certain interrelated events from the plurality of events;

processing the labeled events to extract a feature from respective labeled events, the feature being associated with an event, the feature referring to a property, characteristic or attribute of the event;

analyzing the feature associated with the event;

generating a feature score for the feature associated with the event, the feature score being generated based upon a scoring container update operation, the scoring container update operation using a scoring container, the scoring container comprising a container implemented to provide an approximation of a probability distribution over the values the scoring container contains, based upon samples from the probability distribution;

generating a risk score for the user based on the analyzing; and,

performing a risk assessment operation via a security analytics system based on the feature associated with the event and the risk score.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the applying labels to applicable events from the plurality of events classifies the applicable events from the plurality of events with associated metadata.

15. The non-transitory, computer-readable storage medium of claim 13 , wherein:

extracting features comprises performing transformation operations on certain features associated with an event to generate a smaller set of derived features.

16. The non-transitory, computer-readable storage medium of claim 15 , wherein:

the smaller set of derived features facilitates determination of a distribution of associated features corresponding to a particular event.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the feature associated with the event comprises at least one of a number of bytes uploaded, a time of day, a presence of certain terms in unstructured content, respective domains associated with senders and recipients of information, and a Uniform Resource Locator (URL) classification of a web page visit.

18. The non-transitory, computer-readable storage medium of claim 13 , wherein:

extracting features performs at least one of an exact feature extract operation and a multi match feature extract operation.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (9)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0524 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2018
From: POIREL, CHRISTOPHER; RENNER, WILLIAM; LUIGGI, EDUARDO; BRACIKOWSKI, PHILLIP
To: FORCEPOINT, LLC
Reel/Frame 046334/0792 →