IP Library Granted Patent US 10,642,998
Granted Patent B2
US 10,642,998 · App. 16/045,301 · Granted May 5, 2020

Section-based security information

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,642,998
App. No.
16/045,301
Granted
May 5, 2020
Kind
B2
Abstract

A method, system and computer-usable medium for generating session-based security information. Generating the session-based security information includes the steps of monitoring user behavior between an enactor and an entity; detecting user behavior data associated with the user behavior; generating a session using the user behavior data, the session relating to an entity discrete interaction of the enactor; and, associating the session and the session-based security information with the user profile.

Claims (73)

1. A computer-implementable method for generating session-based security information, comprising:

monitoring user behavior between an enactor and an entity;

detecting user behavior data associated with the user behavior;

generating a session using the user behavior data, the session relating to an entity discrete interaction of the enactor;

generating a fingerprint, the fingerprint comprising a collection of information providing a distinctive, characteristic indicator of an identify of the enactor;

generating a session-based fingerprint using the fingerprint, the session-based fingerprint comprising a unique identifier of the enactor associated with the session;

associating the session, the session-based security information and the session-based fingerprint with a user profile;

using the session-based security information to detect anomalous, abnormal, unexpected or malicious behavior; and,

mitigating a risk associated with the anomalous, abnormal, unexpected or malicious behavior, the mitigating being performed via an endpoint agent executing on a hardware processor of an information handling system.

2. The method of claim 1 , wherein:

the collection of information comprises a user profile element.

3. The method of claim 1 , wherein:

the session comprises at least one of a plurality of session characteristics, the session characteristics comprising

two sessions being contiguous;

two sessions being associated but noncontiguous;

the session being associated with other sessions;

the session being a subset of another session; and,

the interval of time of the session overlapping with an interval of time of another session.

4. The method of claim 1 , wherein:

the user behavior enacted during the session is associated with an event.

5. The method of claim 1 , further comprising:

using the session-based fingerprint to perform security analytics operations.

6. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring user behavior between an enactor and an entity;

detecting user behavior data associated with the user behavior;

generating a session using the user behavior data, the session relating to an entity discrete interaction of the enactor;

generating a fingerprint, the fingerprint comprising a collection of information providing a distinctive, characteristic indicator of an identify of the enactor;

generating a session-based fingerprint using the fingerprint, the session-based fingerprint comprising a unique identifier of the enactor associated with the session;

associating the session, the session-based security information and the session-based fingerprint with a user profile;

using the session-based security information to detect anomalous, abnormal, unexpected or malicious behavior; and,

mitigating a risk associated with the anomalous, abnormal, unexpected or malicious behavior, the mitigating being performed via an endpoint agent executing on a hardware processor of an information handling system.

7. The system of claim 6 , wherein:

the collection of information comprises a user profile element.

8. The system of claim 6 , wherein:

the session comprises at least one of a plurality of session characteristics, the session characteristics comprising

two sessions being contiguous;

two sessions being associated but noncontiguous;

the session being associated with other sessions;

the session being a subset of another session; and,

the interval of time of the session overlapping with an interval of time of another session.

9. The system of claim 6 , wherein:

the user behavior enacted during the session is associated with an event.

10. The system of claim 6 , wherein the instructions executable by the processor are further configured for:

using the session-based fingerprint to perform security analytics operations.

11. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring user behavior between an enactor and an entity;

detecting user behavior data associated with the user behavior;

generating a session using the user behavior data, the session relating to an entity discrete interaction of the enactor;

generating a fingerprint, the fingerprint comprising a collection of information providing a distinctive, characteristic indicator of an identify of the enactor;

generating a session-based fingerprint using the fingerprint, the session-based fingerprint comprising a unique identifier of the enactor associated with the session;

associating the session, the session-based security information and the session-based fingerprint with a user profile;

using the session-based security information to detect anomalous, abnormal, unexpected or malicious behavior; and,

mitigating a risk associated with the anomalous, abnormal, unexpected or malicious behavior, the mitigating being performed via an endpoint agent executing on a hardware processor of an information handling system.

12. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the collection of information comprises a user profile element.

13. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the session comprises at least one of a plurality of session characteristics, the session characteristics comprising

two sessions being contiguous;

two sessions being associated but noncontiguous;

the session being associated with other sessions;

the session being a subset of another session; and,

the interval of time of the session overlapping with an interval of time of another session.

14. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the user behavior enacted during the session is associated with an event.

15. The non-transitory, computer-readable storage medium of claim 11 , wherein the computer executable instructions are further configured for:

using the session-based fingerprint to perform security analytics operations.

16. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

17. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2018
From: FORD, RICHARD A.; IRVINE, ANN; SNYDER, RUSSELL; REEVE, ADAM
To: FORCEPOINT, LLC
Reel/Frame 046615/0391 →