IP Library Granted Patent US 10,664,614
Granted Patent B2
US 10,664,614 · App. 16/295,429 · Granted May 26, 2020

Gracefully handling endpoint feedback when starting to monitor

Inventors: Richard A. Ford (Austin, TX); Ann Irvine (Baltimore, MD); Adam Reeve (Redmond, WA); Russell Snyder (Baltimore, MD); Benjamin Shih (Baltimore, MD)
Assignee: Forcepoint LLC
G06F21/6245G06F11/3438G06F21/552G06F21/577G06F21/602G06F21/6254G06F21/84H04L63/1408H04L63/1425H04L63/1433H04L63/1441H04L67/025H04L67/141H04L67/146H04L67/22H04L67/306G06F2221/031G06F2221/032G06F2221/034H04L63/20H04L67/289H04L2209/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,664,614
App. No.
16/295,429
Granted
May 26, 2020
Kind
B2
Abstract

A method, system and computer-usable medium for adaptively assessing risk associated with an endpoint, comprising: determining a risk level corresponding to an entity associated with an endpoint; selecting a frequency and a duration of an endpoint monitoring interval; collecting user behavior to collect user behavior associated with the entity for the duration of the endpoint monitoring interval via the endpoint; processing the user behavior to generate a current risk score for the entity; comparing the current risk score of the user to historical risk scores to determine whether a risk score of a user has changed; and changing the risk score of the user to the current risk score when the risk score of the user has changed.

Claims (52)

1. A computer-implementable method for adaptively assessing risk associated with an endpoint, comprising:

determining a risk level corresponding to an entity associated with an endpoint;

selecting a frequency of when to perform an endpoint monitoring interval and a duration of the endpoint monitoring interval;

collecting user behavior associated with the entity for the duration of the endpoint monitoring interval via the endpoint;

processing the user behavior to generate a current risk score for the entity, the processing comprising applying a risk-adaptive security policy to the user behavior, the risk-adaptive policy comprising a security policy implemented to be revised to adaptively remediate risk associated with a user behavior;

comparing the current risk score of the entity to a historical risk score of the entity to determine whether a risk score of a user has changed; and

changing the risk score of the entity to the current risk score when the risk score of the entity has changed; and wherein

the risk adaptive policy is revised to increase the frequency of the endpoint monitoring interval when the current risk score of the entity increases over a plurality of endpoint monitoring intervals, the current risk score increasing being when the current risk score increases by less than 20% over the historical risk score; and,

the risk adaptive policy is revised to increase the frequency of the endpoint monitoring interval and the duration of the endpoint monitoring interval when the current risk score of the entity increases over a plurality of endpoint monitoring intervals, the current risk score increasing being when the current risk score increases by more than 20% over the historical risk score.

2. The method of claim 1 , wherein:

the risk adaptive security policy is revised via a security analytics system.

3. The method of claim 1 , wherein:

the endpoint comprises a risk-adaptive feature pack, the risk-adaptive feature pack comprising at least one of an event data detector module, an event data collector module and the risk-adaptive security policy.

4. The method of claim 1 further comprising:

decreasing the duration of the endpoint monitoring interval when the current risk score of the entity declines over a plurality of endpoint monitoring intervals; and,

decreasing the frequency of the endpoint monitoring interval when the current risk score of the entity remains substantially the same over a plurality of endpoint monitoring intervals.

5. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

determining a risk level corresponding to an entity associated with an endpoint;

selecting a frequency of when to perform an endpoint monitoring interval and a duration of the endpoint monitoring interval;

collecting user behavior associated with the entity for the duration of the endpoint monitoring interval via the endpoint;

processing the user behavior to generate a current risk score for the entity, the processing comprising applying a risk-adaptive security policy to the user behavior, the risk-adaptive policy comprising a security policy implemented to be revised to adaptively remediate risk associated with a user behavior;

comparing the current risk score of the entity to a historical risk score of the entity to determine whether a risk score of a user has changed; and

changing the risk score of the entity to the current risk score when the risk score of the entity has changed; and wherein

the risk adaptive policy is revised to increase the frequency of the endpoint monitoring interval when the current risk score of the entity increases over a plurality of endpoint monitoring intervals, the current risk score increasing being when the current risk score increases by less than 20% over the historical risk score; and,

the risk adaptive policy is revised to increase the frequency of the endpoint monitoring interval and the duration of the endpoint monitoring interval when the current risk score of the entity increases over a plurality of endpoint monitoring intervals, the current risk score increasing being when the current risk score increases by more than 20% over the historical risk score.

6. The system of claim 5 , wherein:

the risk adaptive security policy is revised via a security analytics system.

7. The system of claim 5 , wherein:

the endpoint comprises a risk-adaptive feature pack, the risk-adaptive feature pack comprising at least one of an event data detector module, an event data collector module and the risk-adaptive security policy.

8. The system of claim 5 , wherein the instructions executable by the processor are further configured for:

decreasing the duration of the endpoint monitoring interval when the current risk score of the entity declines over a plurality of endpoint monitoring intervals; and,

decreasing the frequency of the endpoint monitoring interval when the current risk score of the entity remains substantially the same over a plurality of endpoint monitoring intervals.

9. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

determining a risk level corresponding to an entity associated with an endpoint;

collecting user behavior associated with the entity via the endpoint;

processing the user behavior to generate a current risk score for the entity, the processing comprising applying a risk-adaptive security policy to the user behavior, the risk-adaptive policy comprising a security policy implemented to be revised to adaptively remediate risk associated with a user behavior;

comparing the current risk score of the entity to a historical risk score of the entity to determine whether a risk score of a user has changed; and

changing the risk score of the entity to the current risk score when the risk score of the entity has changed.

10. The non-transitory, computer-readable storage medium of claim 9 , wherein:

the risk adaptive security policy is revised via a security analytics system.

11. The non-transitory, computer-readable storage medium of claim 9 , wherein:

the endpoint comprises a risk-adaptive feature pack, the risk-adaptive feature pack comprising at least one of an event data detector module, an event data collector module and the risk-adaptive security policy.

12. The non-transitory, computer-readable storage medium of claim 9 , wherein the computer executable instructions are further configured for:

decreasing the duration of the endpoint monitoring interval when the current risk score of the entity declines over a plurality of endpoint monitoring intervals; and,

decreasing the frequency of the endpoint monitoring interval when the current risk score of the entity remains substantially the same over a plurality of endpoint monitoring intervals.

13. The non-transitory, computer-readable storage medium of claim 9 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

14. The non-transitory, computer-readable storage medium of claim 9 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0524 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 7, 2019
From: FORD, RICHARD A.; IRVINE, ANN; REEVE, ADAM; SNYDER, RUSSELL; SHIH, BENJAMIN
To: FORCEPOINT, LLC
Reel/Frame 048530/0728 →