IP Library Granted Patent US 10,721,268
Granted Patent B2
US 10,721,268 · App. 16/239,081 · Granted Jul 21, 2020

Systems and user interfaces for dynamic and interactive investigation based on automatic clustering of related data in various data structures

Inventors: Harkirat Singh (New York, NY); Brendan Weickert (McLean, CA); Matthew Sprague (Palo Alto, CA); Michael Kross (Palo Alto, CA); Adam Borochoff (New York, NY); Parvathy Menon (Palo Alto, CA); Michael Harris (Palo Alto, CA)
Assignee: Palantir Technologies Inc.
H04L63/145G06F16/23G06F16/244G06F16/2465G06F16/24578G06F16/26G06F16/283G06F16/285G06F16/287G06F16/288G06F16/335G06F16/35G06F16/355G06F16/9535G06Q10/10G06Q20/382G06Q20/4016G06Q30/0185G06Q40/00G06Q40/02G06Q40/025G06Q40/10G06Q40/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,721,268
App. No.
16/239,081
Granted
Jul 21, 2020
Kind
B2
Abstract

In various embodiments, systems, methods, and techniques are disclosed for generating a collection of clusters of related data from a seed. Seeds may be generated based on seed generation strategies or rules. Clusters may be generated by, for example, retrieving a seed, adding the seed to a first cluster, retrieving a clustering strategy or rules, and adding related data and/or data entities to the cluster based on the clustering strategy. Various cluster scores may be generated based on attributes of data in a given cluster. Further, cluster metascores may be generated based on various cluster scores associated with a cluster. Clusters may be ranked based on cluster metascores. Various embodiments may enable an analyst to discover various insights related to data clusters, and may be applicable to various tasks including, for example, tax fraud detection, beaconing malware detection, malware user-agent detection, and/or activity trend detection, among various others.

Claims (68)

1. A computer system comprising:

one or more computer readable storage devices configured to store:

host-based events associated with one or more computing devices; and

activity trend-related data items; and

one or more hardware computer processors in communication with the one or more computer readable storage devices and configured to execute computer executable instructions to cause the computer system to:

execute a cluster engine configured to at least:

determine a first group of host-based events that indicate a same first activity type and are associated with a first host and a reference time period;

determine, based at least on the first group of host-based events, a first statistical deviation in the first activity type on the first host for the reference time period;

determine a second group of host-based events the indicate the same first activity type and are associated with the first host and a test time period;

determine, based at least on the second group of host-based events, a second statistical deviation in the first activity type on the first host for the test time period;

in response to determining that the first statistical deviation compared to the second statistical deviation satisfies a particular threshold, designate a host-based event from the second group as a seed;

generate a data item cluster based on the seed, wherein generating the data item cluster comprises:

adding the seed to the data item cluster; and

adding to the data item cluster one or more activity trend-related data items, from the activity trend-related data items, determined to be associated with the seed; and

determine scores for the data item cluster and a plurality of additional data items clusters generated based on host-based events; and

execute a workflow engine configured to at least:

cause presentation of the data item cluster and the plurality of additional data item clusters in a user interface of a client computing device; and

order the presented data item cluster and the plurality of additional data item clusters in the user interface based at least in part on the respective determined scores for the data item cluster and the plurality of additional data item clusters.

2. The computer system of claim 1 , wherein the activity trend-related data items include at least one of: data items associated with captured host-based events, Internet Protocol addresses, external domains, users, or computing devices, and wherein hosts comprise computing devices in a network.

3. The computer system of claim 1 , wherein the one or more hardware computer processors are configured to execute the computer executable instructions to further cause the computer system to:

execute the cluster engine further configured to at least:

identify the one or more activity trend-related data items determined to be associated with the seed based at least on a clustering strategy, wherein the clustering strategy queries the host-based events and/or the activity trend-related data items to determine at least one of: the particular host associated with the seed, one or more host-based events associated with the particular host, one or more host-based events associated with the seed, users of the particular host, data items associated with the particular host, other hosts associated with the same particular activity type of host-based events, Internet Protocol addresses associated with the particular host, external domains associated with the seed, or computing devices associated with the particular host.

4. The computer system of claim 3 , wherein identifying one or more activity trend-related data items determined to be associated with the seed further comprises determining a particular activity trend-related data item and the seed are both associated with a common metadata property value.

5. The computer system of claim 4 , wherein the common property value includes at least one of: a username, a domain, an Internet Protocol address, a computing device identifier, or an event identifier.

6. The computer system of claim 1 , wherein the first statistical deviation comprises a Z-score.

7. A computer-implemented method comprising:

by one or more processors executing program instructions:

executing a cluster engine configured to at least:

access one or more computer readable storage devices configured to store:

host-based events associated with one or more computing devices; and

activity trend-related data items;

determine a first group of host-based events that indicate a same first activity type and are associated with a first host and a reference time period;

determine, based at least on the first group of host-based events, a first statistical deviation in the first activity type on the first host for the reference time period;

determine a second group of host-based events the indicate the same first activity type and are associated with the first host and a test time period;

determine, based at least on the second group of host-based events, a second statistical deviation in the first activity type on the first host for the test time period;

in response to determining that the first statistical deviation compared to the second statistical deviation satisfies a particular threshold, designate a host-based event from the second group as a seed;

generate a data item cluster based on the seed, wherein generating the data item cluster comprises:

adding the seed to the data item cluster; and

adding to the data item cluster one or more activity trend-related data items, from the activity trend-related data items, determined to be associated with the seed; and

determine scores for the data item cluster and a plurality of additional data items clusters generated based on host-based events; and

executing a workflow engine configured to at least:

cause presentation of the data item cluster and the plurality of additional data item clusters in a user interface of a client computing device; and

order the presented data item cluster and the plurality of additional data item clusters in the user interface based at least in part on the respective determined scores for the data item cluster and the plurality of additional data item clusters.

8. The computer-implemented method of claim 7 , wherein the activity trend-related data items include at least one of: data items associated with captured host-based events, Internet Protocol addresses, external domains, users, or computing devices, and wherein hosts comprise computing devices in a network.

9. The computer-implemented method of claim 7 further comprising:

by the one or more processors executing program instructions:

executing the cluster engine further configured to at least:

identify the one or more activity trend-related data items determined to be associated with the seed based at least on a clustering strategy, wherein the clustering strategy queries the host-based events and/or the activity trend-related data items to determine at least one of: the particular host associated with the seed, one or more host-based events associated with the particular host, one or more host-based events associated with the seed, users of the particular host, data items associated with the particular host, other hosts associated with the same particular activity type of host-based events, Internet Protocol addresses associated with the particular host, external domains associated with the seed, or computing devices associated with the particular host.

10. The computer-implemented method of claim 9 , wherein identifying one or more activity trend-related data items determined to be associated with the seed further comprises determining a particular activity trend-related data item and the seed are both associated with a common metadata property value.

11. The computer-implemented method of claim 10 , wherein the common property value includes at least one of: a username, a domain, an Internet Protocol address, a computing device identifier, or an event identifier.

12. The computer-implemented method of claim 7 , wherein the first statistical deviation comprises a Z-score.

13. A non-transitory computer readable storage medium having program instructions embodied therewith, the program instructions executable by one or more processors to cause the one or more processors to:

execute a cluster engine configured to at least:

access one or more computer readable storage devices configured to store:

host-based events associated with one or more computing devices; and

activity trend-related data items;

determine a first group of host-based events that indicate a same first activity type and are associated with a first host and a reference time period;

determine, based at least on the first group of host-based events, a first statistical deviation in the first activity type on the first host for the reference time period;

determine a second group of host-based events the indicate the same first activity type and are associated with the first host and a test time period;

determine, based at least on the second group of host-based events, a second statistical deviation in the first activity type on the first host for the test time period;

in response to determining that the first statistical deviation compared to the second statistical deviation satisfies a particular threshold, designate a host-based event from the second group as a seed;

generate a data item cluster based on the seed, wherein generating the data item cluster comprises:

adding the seed to the data item cluster; and

adding to the data item cluster one or more activity trend-related data items, from the activity trend-related data items, determined to be associated with the seed; and

determine scores for the data item cluster and a plurality of additional data items clusters generated based on host-based events; and

execute a workflow engine configured to at least:

cause presentation of the data item cluster and the plurality of additional data item clusters in a user interface of a client computing device; and

order the presented data item cluster and the plurality of additional data item clusters in the user interface based at least in part on the respective determined scores for the data item cluster and the plurality of additional data item clusters.

Assignments (8)
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2019
From: SINGH, HARKIRAT; WEICKERT, BRENDAN; SPRAGUE, MATTHEW; KROSS, MICHAEL; BOROCHOFF, ADAM; MENON, PARVATHY; HARRIS, MICHAEL
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 049214/0959 →
Cited By (2)
US 12,238,136 US 12,361,074