IP Library Granted Patent US 10,915,644
Granted Patent B2
US 10,915,644 · App. 16/530,769 · Granted Feb 9, 2021

Collecting data for centralized use in an adaptive trust profile event via an endpoint

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,915,644
App. No.
16/530,769
Granted
Feb 9, 2021
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for generating an adaptive trust profile via an adaptive trust profile operation. In various embodiments the adaptive trust profile operation includes: monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the monitoring comprising monitoring at least one of the plurality of electronically-observable actions via a protected endpoint; converting the plurality of electronically-observable actions of the entity to electronic information representing the plurality of actions of the entity; and generating an adaptive trust profile based upon the action of the entity.

Claims (55)

1. A computer-implementable method for generating an adaptive trust profile, comprising:

monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the monitoring comprising monitoring at least one of the plurality of electronically-observable actions via a protected endpoint, the protected endpoint comprising an endpoint device and an endpoint agent, the endpoint agent executing on a hardware processor of the endpoint device;

converting the plurality of electronically-observable actions of the entity to electronic information representing the plurality of actions of the entity;

providing the electronic information representing the plurality of actions of the entity to a security analytics system, the security analytics system being implemented in a centralized location;

generating, via the security analytics system, the adaptive trust profile based upon the plurality of electronically-observable actions of the entity, the adaptive trust profile comprising an inference regarding the entity, the inference regarding the entity being based upon the plurality of actions of the entity; and,

determining whether the entity behavior is of analytic utility based upon the inference regarding the entity.

2. The method of claim 1 , wherein:

the centralized location comprises at least one of a corporate data center and a cloud environment.

3. The method of claim 1 , wherein:

the security analytics system provides adaptive trust profile information to the protected endpoint.

4. The method of claim 1 , wherein:

the protected endpoint comprises an analytics module and an adaptive trust profile feature pack.

5. The method of claim 4 , wherein:

the adaptive trust profile feature pack system comprises an event data detector module, an entity behavior detector module and a session correlation module.

6. The method of claim 1 , further comprising:

adaptively responding to mitigate risk.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the monitoring comprising monitoring at least one of the plurality of electronically-observable actions via a protected endpoint, the protected endpoint comprising an endpoint device and an endpoint agent, the endpoint agent executing on a hardware processor of the endpoint device;

converting the plurality of electronically-observable actions of the entity to electronic information representing the plurality of actions of the entity;

providing the electronic information representing the plurality of actions of the entity to a security analytics system, the security analytics system being implemented in a centralized location;

generating, via the security analytics system, the adaptive trust profile based upon the plurality of electronically-observable actions of the entity, the adaptive trust profile comprising an inference regarding the entity, the inference regarding the entity being based upon the plurality of actions of the entity; and,

determining whether the entity behavior is of analytic utility based upon the inference regarding the entity.

8. The system of claim 7 , wherein:

the centralized location comprises at least one of a corporate data center and a cloud environment.

9. The system of claim 7 , wherein:

the security analytics system provides adaptive trust profile information to the protected endpoint.

10. The system of claim 7 , wherein:

the protected endpoint comprises an analytics module and an adaptive trust profile feature pack.

11. The system of claim 10 , wherein:

the adaptive trust profile feature pack system comprises an event data detector module, an entity behavior detector module and a session correlation module.

12. The system of claim 11 , wherein the instructions executable by the processor are further configured for:

adaptively responding to mitigate risk.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the monitoring comprising monitoring at least one of the plurality of electronically-observable actions via a protected endpoint, the protected endpoint comprising an endpoint device and an endpoint agent, the endpoint agent executing on a hardware processor of the endpoint device;

converting the plurality of electronically-observable actions of the entity to electronic information representing the plurality of actions of the entity;

providing the electronic information representing the plurality of actions of the entity to a security analytics system, the security analytics system being implemented in a centralized location;

generating, via the security analytics system, the adaptive trust profile based upon the plurality of electronically-observable actions of the entity, the adaptive trust profile comprising an inference regarding the entity, the inference regarding the entity being based upon the plurality of actions of the entity; and,

determining whether the entity behavior is of analytic utility based upon the inference regarding the entity.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the centralized location comprises at least one of a corporate data center and a cloud environment.

15. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the security analytics system provides adaptive trust profile information to the protected endpoint.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the protected endpoint comprises an analytics module and an adaptive trust profile feature pack.

17. The non-transitory, computer-readable storage medium of claim 16 , wherein:

the adaptive trust profile feature pack system comprises an event data detector module, an entity behavior detector module and a session correlation module.

18. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

adaptively responding to mitigate risk.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 2, 2019
From: FORD, RICHARD A.
To: FORCEPOINT LLC
Reel/Frame 049946/0978 →