IP Library Granted Patent US 10,298,603
Granted Patent B2
US 10,298,603 · App. 16/042,702 · Granted May 21, 2019

Supervisory control and data acquisition

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,298,603
App. No.
16/042,702
Granted
May 21, 2019
Kind
B2
Abstract

Aspects of the present disclosure relate to computer system security. A machine accesses a set of records corresponding to a set of users having access to a computer system. The machine stores, for each user in the set of users, a baseline profile representing baseline activity of the user with respect to a set of data sources of the computer system. The machine monitors activity of the set of users with respect to the set of data sources. The machine determines, based on monitoring the activity of the set of users, that a user action of a specified user, with respect to one or more data sources from the set of data sources, is anomalous relative to the baseline profile of the specified user. The machine provides a digital transmission representing the anomalous user action.

Claims (46)

1. A control server comprising:

one or more processors; and

a memory storing instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

storing, for each user in a set of users having access to a set of data sources, a baseline profile indicating whether the user has previously modified a certificate authority for the set of data sources;

monitoring activity of the set of users with respect to the set of data sources;

determining, based on monitoring the activity of the set of users, that a user action of a specified user comprises modifying the certificate authority;

determining that the specified user has never modified the certificate authority previously; and

providing, in response to determining that the user action comprises modifying the certificate authority and in response to determining that the specified user has never modified the certificate authority previously, a digital transmission representing the user action of the specified user.

2. The control server of claim 1 , wherein the set of data sources is hosted at a computer system.

3. The control server of claim 2 , wherein the set of data sources comprises one or more of: a packet log of packets travelling between the computer system and an external network, a driver log of the computer system, a secure socket layer (SSL) certificate authority (CA) of the computer system, a programmable logic controller (PLC) of the computer system, a simple mail transfer protocol (SMTP) log of the computer system, a web access log of the computer system, service repos of the computer system, network drives of the computer system, workstation performance logs of the computer system, and workstation network traffic of the computer system.

4. The control server of claim 2 , wherein the set of users having access to the set of data sources comprise system administrators of the computer system.

5. The control server of claim 2 , the operations further comprising:

blocking access, by the specified user, to the computer system in response to determining that the user action comprises modifying the certificate authority and in response to determining that the specified user has never modified the certificate authority previously.

6. The control server of claim 1 , the operations further comprising:

detecting that the user action includes accessing the set of data sources at a time of day different from a time of day for accessing the set of data sources specified in the baseline profile.

7. The control server of claim 1 , the operations further comprising:

detecting that the user action includes accessing the set of data sources from a geographic location different from a geographic location for accessing the set of data sources specified in the baseline profile.

8. A non-transitory machine-readable medium storing instructions which, when executed by one or more processors of a machine, cause the one or more processors to perform operations comprising:

storing, for each user in a set of users having access to a set of data sources, a baseline profile indicating whether the user has previously modified a certificate authority for the set of data sources;

monitoring activity of the set of users with respect to the set of data sources;

determining, based on monitoring the activity of the set of users, that a user action of a specified user comprises modifying the certificate authority;

determining that the specified user has never modified the certificate authority previously; and

providing, in response to determining that the user action comprises modifying the certificate authority and in response to determining that the specified user has never modified the certificate authority previously, a digital transmission representing the user action of the specified user.

9. The machine-readable medium of claim 8 , wherein the set of data sources is hosted at a computer system.

10. The machine-readable medium of claim 9 , wherein the set of data sources comprises one or more of:

a packet log of packets travelling between the computer system and an external network, a driver log of the computer system, a secure socket layer (SSL) certificate authority (CA) of the computer system, a programmable logic controller (PLC) of the computer system, a simple mail transfer protocol (SMTP) log of the computer system, a web access log of the computer system, service repos of the computer system, network drives of the computer system, workstation performance logs of the computer system, and workstation network traffic of the computer system.

11. The machine-readable medium of claim 9 , wherein the set of users having access to the set of data sources comprise system administrators of the computer system.

12. The machine-readable medium of claim 9 , the operations further comprising:

blocking access, by the specified user, to the computer system in response to determining that the user action comprises modifying the certificate authority and in response to determining that the specified user has never modified the certificate authority previously.

13. The machine-readable medium of claim 8 , the operations further comprising:

detecting that the user action includes accessing the set of data sources at a time of day different from a time of day for accessing the set of data sources specified in the baseline profile.

14. The machine-readable medium of claim 8 , the operations further comprising:

detecting that the user action includes accessing the set of data sources from a geographic location different from a geographic location for accessing the set of data sources specified in the baseline profile.

15. A method comprising:

storing, for each user in a set of users having access to a set of data sources, a baseline profile indicating whether the user has previously modified a certificate authority for the set of data sources;

monitoring activity of the set of users with respect to the set of data sources;

determining, based on monitoring the activity of the set of users, that a user action of a specified user comprises modifying the certificate authority;

determining that the specified user has never modified the certificate authority previously; and

providing, in response to determining that the user action comprises modifying the certificate authority and in response to determining that the specified user has never modified the certificate authority previously, a digital transmission representing the user action of the specified user.

16. The method of claim 15 , wherein the set of data sources is hosted at a computer system.

17. The method of claim 16 , wherein the set of data sources comprises one or more of: a packet log of packets travelling between the computer system and an external network, a driver log of the computer system, a secure socket layer (SSL) certificate authority (CA) of the computer system, a programmable logic controller (PLC) of the computer system, a simple mail transfer protocol (SMTP) log of the computer system, a web access log of the computer system, service repos of the computer system, network drives of the computer system, workstation performance logs of the computer system, and workstation network traffic of the computer system.

18. The method of claim 16 , wherein the set of users having access to the set of data sources comprise system administrators of the computer system.

19. The method of claim 16 , further comprising:

blocking access, by the specified user, to the computer system in response to determining that the user action comprises modifying the certificate authority and in response to determining that the specified user has never modified the certificate authority previously.

20. The method of claim 15 , further comprising:

detecting that the user action includes accessing the set of data sources at a time of day different from a time of day for accessing the set of data sources specified in the baseline profile.

Assignments (8)
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 23, 2018
From: BECKER, NOMI; SMITLEY, ISAAC
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 046431/0529 →