IP Library Granted Patent US 11,843,621
Granted Patent B2
US 11,843,621 · App. 16/297,335 · Granted Dec 12, 2023

Behavior based profiling

Inventors: Yang Zhang (Fremont, CA); Arun Raghuramu (San Jose, CA); Siying Yang (Cupertino, CA)
Assignee: FORESCOUT TECHNOLOGIES, INC.
H04L63/1425G06F16/285G06F16/288G06N5/047G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,843,621
App. No.
16/297,335
Granted
Dec 12, 2023
Kind
B2
Abstract

Systems, methods, and related technologies for profiling an entity and classifying an entity based on a profile are described. In certain aspects, accessing data associated with one or more communications of an entity is accessed and one or more behaviors based on the data associated with the one or more communications of the entity are determined. One or more sequences of the one or more behaviors of the entity are determined and a profile is determined based on the one or more sequences of the one or more behaviors, wherein the profile comprises a classification of the entity. The profile may then be stored.

Claims (57)

1. A method comprising:

accessing data associated with one or more communications of a first entity on a network;

determining one or more behaviors based on the data associated with the one or more communications of the first entity;

determining one or more sequences of the one or more behaviors of the first entity;

determining, by a processing device, a profile of the first entity based on the one or more sequences of the one or more behaviors, wherein the profile comprises a classification of the first entity;

determining a state machine of the profile of the first entity, wherein the state machine is associated with the classification against which the one or more behaviors can be matched, wherein the state machine comprises one or more states corresponding to each of the one or more behaviors to be matched, and wherein the state machine transitions to a next state upon detection of a behavior of the one or more behaviors corresponding to a current state of the state machine within a period of time associated with the current state;

detecting a second entity coming onto the network;

monitoring communications of the second entity on the network;

determining one or more static attributes associated with the second entity based on the communications of the second entity;

determining behaviors of the second entity based on the communications of the second entity; and

classifying, responsive to detecting the second entity coming onto the network, the second entity as a compromised entity based on a combination of the one or more static attributes associated with the second entity and the state machine of the profile of the first entity as applied to the behaviors of the second entity.

2. The method of claim 1 , wherein the profile comprises a sequence of behaviors associated with the classification.

3. The method of claim 2 , wherein the profile further comprises an attribute associated with the first entity.

4. The method of claim 1 , wherein the one or more communications associated with the first entity are accessed from at least one of a log, traffic data, information from an external system, or classification information.

5. The method of claim 4 , wherein the classification information is based on an attribute associated with the first entity.

6. The method of claim 1 , wherein the one or more sequences of behavior comprises a plurality of behaviors associated with a period of time.

7. The method of claim 1 , wherein at least one state of the state machine is associated with an occurrence of a first behavior.

8. The method of claim 1 , wherein the profile comprises a plurality of rules, wherein the plurality of rules comprises at least one conditional rule.

9. The method of claim 1 , further comprising:

storing the profile by uploading the profile to a remote system.

10. The method of claim 1 further comprising:

validating the profile.

11. The method of claim 1 , wherein data associated with the one or more communications of the first entity comprises information associated with an environment comprising the first entity.

12. The method of claim 1 further comprising:

applying a policy based on the classification of the second entity.

13. A system comprising:

a memory; and

a processing device, operatively coupled to the memory, to:

access data associated with one or more communications of a first entity on a network;

determine one or more behaviors based on the data associated with the one or more communications of the first entity;

determine one or more sequences of the one or more behaviors of the first entity;

determine a profile of the first entity based on the one or more sequences of the one or more behaviors, wherein the profile comprises a classification of the first entity;

determine a state machine of the profile of the first entity, wherein the state machine is associated with the classification against which the one or more behaviors can be matched, wherein the state machine comprises one or more states corresponding to each of the one or more behaviors to be matched, and wherein the state machine transitions to a next state upon detection of a behavior of the one or more behaviors corresponding to a current state of the state machine within a period of time associated with the current state;

detect a second entity coming onto the network;

monitor communications of the second entity on the network;

determine one or more static attributes associated with the second entity based on the communications of the second entity;

determine behaviors of the second entity based on the communications of the second entity; and

classify, responsive to detecting the second entity coming onto the network, the second entity as a compromised entity based on a combination of the one or more static attributes associated with the second entity and the state machine of the profile of the first entity as applied to the behaviors of the second entity.

14. The system of claim 13 , wherein the profile comprises a sequence of behaviors associated with the classification.

15. The system of claim 13 , wherein the profile further comprises an attribute associated with the first entity.

16. The system of claim 13 , wherein the one or more sequences of behavior comprises a plurality of behaviors associated with a period of time.

17. The system of claim 13 , wherein the profile comprises a state machine, wherein at least one state of the state machine is associated with an occurrence of a first behavior.

18. The system of claim 13 , wherein the profile comprises a plurality of rules, wherein the plurality of rules comprises at least one conditional rule.

19. A non-transitory computer readable medium having instructions encoded thereon that, when executed by a processing device, cause the processing device to:

access data associated with one or more communications of a first entity on a network;

determine one or more behaviors based on the data associated with the one or more communications of the first entity;

determine one or more sequences of the one or more behaviors of the first entity;

determine, using the processing device, a profile of the first entity based on the one or more sequences of the one or more behaviors, wherein the profile comprises a classification of the first entity;

determine a state machine of the profile of the first entity, wherein the state machine is associated with the classification against which the one or more behaviors can be matched, wherein the state machine comprises one or more states corresponding to each of the one or more behaviors to be matched, and wherein the state machine transitions to a next state upon detection of a behavior of the one or more behaviors corresponding to a current state of the state machine within a period of time associated with the current state;

detect a second entity coming onto the network;

monitor communications of the second entity on the network;

determine one or more static attributes associated with the second entity based on the communications of the second entity;

determine behaviors of the second entity based on the communications of the second entity; and

classify, responsive to detecting the second entity coming onto the network, the second entity as a compromised entity based on a combination of the one or more static attributes associated with the second entity and the state machine of the profile of the first entity as applied to the behaviors of the second entity.

20. The non-transitory computer readable medium of claim 19 , wherein the profile comprises a sequence of behaviors associated with the classification.

21. The non-transitory computer readable medium of claim 19 , wherein the profile further comprises an attribute associated with the first entity.

22. The non-transitory computer readable medium of claim 19 , wherein the one or more sequences of behavior comprises a plurality of behaviors associated with a period of time.

Assignments (2)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 17, 2020
From: FORESCOUT TECHNOLOGIES, INC.
To: OWL ROCK CAPITAL CORPORATION, AS ADMINISTRATIVE AGENT
Reel/Frame 053519/0982 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2019
From: ZHANG, YANG; RAGHURAMU, ARUN; YANG, SIYING
To: FORESCOUT TECHNOLOGIES, INC.
Reel/Frame 048558/0993 →
Continuity (1)
Related Publication 20200287924A1 · Sep 10, 2020