IP Library Granted Patent US 11,082,440
Granted Patent B2
US 11,082,440 · App. 16/592,888 · Granted Aug 3, 2021

User profile definition and management

Inventor: Richard Anthony Ford (Austin, TX)
Assignee: Forcepoint LLC
H04L63/1425H04L63/1416H04L63/1441H04L67/10H04L67/22H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,082,440
App. No.
16/592,888
Granted
Aug 3, 2021
Kind
B2
Abstract

A method, system and computer-usable medium for performing a security analysis operation within a security environment, comprising: monitoring electronically-observable user behavior about a particular entity; maintaining a state about the particular entity, the state representing a context of a particular event; converting the electronically-observable user behavior into electronic information representing the electronically-observable user behavior; generating a user behavior profile based upon the electronic information representing the electronically-observable user behavior; and, analyzing the event using the state of the entity and the user behavior profile.

Claims (63)

1. A computer-implementable method for performing a security analysis operation within a security environment, comprising:

monitoring electronically-observable user behavior about a particular entity;

maintaining a state about the particular entity, the state representing a context of a particular event;

converting the electronically-observable user behavior into electronic information representing the electronically-observable user behavior;

generating a user behavior profile based upon the electronic information representing the electronically-observable user behavior, the user behavior profile comprising a collection of information that describes the particular entity, the collection of information comprising at least one of a user profile attribute, a user behavior factor and a user mindset factor;

generating a collection of information reflecting an inferred state of a user at a particular time, the collection of information reflecting the inferred state of the user at the particular time representing aspects of the particular entity that are inferred based upon the electronically-observable user behavior;

performing a security analysis operation via a security analytics system, the security analysis operation analyzing the event using the state of the entity, the collection of information reflecting the inferred state of the user at the particular time and the user behavior profile, the analyzing determining whether the electronically-observable user behavior about the particular entity does not correspond to known good behavior, the security analysis operation determining that the particular entity represents a security threat to an organization associated with the security analytics system when the electronically-observable user behavior about the particular entity does not correspond to known good behavior; and,

performing an enforcement operation when the electronically-observable user behavior about the particular entity does not correspond to known good behavior.

2. The method of claim 1 , further comprising:

associating the collection of information reflecting the inferred state of the user at the particular time with the user behavior profile.

3. The method of claim 1 , further comprising:

associating a higher-level meaning with the event based upon the analyzing.

4. The method of claim 1 , further comprising:

using the user behavior profile and the state to generate a user mindset profile.

5. The method of claim 1 , wherein:

the monitoring electronically-observable user behavior comprises monitoring a plurality of points of observability, at least some of the plurality of points of observability corresponding to respective layers of user interaction; and,

each of the plurality of points of observability is converted into respective electronic information representing respective points of observability.

6. The method of claim 5 , wherein:

the plurality of points of observability comprise an action based point of observability, an activity based point of observability and a behavior based point of observability.

7. The method of claim 5 , wherein:

the plurality of points of observability observer user behavior within at least one of a physical domain and a cyberspace environment.

8. The method of claim 1 , wherein:

the user behavior profile comprises a multi-faceted user behavior profile comprising a plurality of facets, each of the plurality of facets corresponding to at least one of a user authentication factor, a user identification factor and a user behavior factor.

9. The method of claim 1 , further comprising:

identifying certain electronically-observable user behavior used for generating the user behavior profile as known good behavior;

determining whether additional electronically-observable user behavior do not correspond to the known good behavior; and,

performing an enforcement operation when additional electronically-observable user behavior do not correspond to the known good behavior.

10. The method of claim 8 , further comprising:

monitoring an information technology environment using the user behavior profile;

performing an enforcement operation if a user interaction with the information technology environment does not correspond to interactions based upon the user behavior profile.

11. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code for generating a user behavior profile, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring electronically-observable user behavior about a particular entity;

maintaining a state about the particular entity, the state representing a context of a particular event;

converting the electronically-observable user behavior into electronic information representing the electronically-observable user behavior;

generating a user behavior profile based upon the electronic information representing the electronically-observable user behavior, the user behavior profile comprising a collection of information that describes the particular entity, the collection of information comprising at least one of a user profile attribute, a user behavior factor and a user mindset factor;

generating a collection of information reflecting an inferred state of a user at a particular time, the collection of information reflecting the inferred state of the user at the particular time representing aspects of the particular entity that are inferred based upon the electronically-observable user behavior;

performing a security analysis operation via a security analytics system, the security analysis operation analyzing the event using the state of the entity, the collection of information reflecting the inferred state of the user at the particular time and the user behavior profile, the analyzing determining whether the electronically-observable user behavior about the particular entity does not correspond to known good behavior, the security analysis operation determining that the particular entity represents a security threat to an organization associated with the security analytics system when the electronically-observable user behavior about the particular entity does not correspond to known good behavior; and,

performing an enforcement operation when the electronically-observable user behavior about the particular entity does not correspond to known good behavior.

12. The system of claim 11 , wherein the instructions executable by the processor are further configured for:

associating the collection of information reflecting the inferred state of the user at the particular time with the user behavior profile.

13. The system of claim 11 , wherein the instructions executable by the processor are further configured for:

associating a higher-level meaning with the event based upon the analyzing.

14. The system of claim 11 , wherein the instructions executable by the processor are further configured for:

using the user behavior profile and the state to generate a user mindset profile.

15. The system of claim 11 , wherein:

the monitoring electronically-observable user behavior comprises monitoring a plurality of points of observability, at least some of the plurality of points of observability corresponding to respective layers of user interaction; and,

each of the plurality of points of observability is converted into respective electronic information representing respective points of observability.

16. The system of claim 15 , wherein:

the plurality of points of observability comprise an action based point of observability, an activity based point of observability and a behavior based point of observability.

17. The system of claim 15 , wherein:

the plurality of points of observability observer user behavior within at least one of a physical domain and a cyberspace environment.

18. The system of claim 11 , wherein:

the user behavior profile comprises a multi-faceted user behavior profile comprising a plurality of facets, each of the plurality of facets corresponding to at least one of a user authentication factor, a user identification factor and a user behavior factor.

19. The system of claim 18 , wherein the instructions executable by the processor are further configured for:

identifying certain electronically-observable user behavior used for generating the user behavior profile as known good behavior;

determining whether additional electronically-observable user behavior do not correspond to the known good behavior; and,

performing an enforcement operation when additional electronically-observable user behavior do not correspond to the known good behavior.

20. The system of claim 18 , wherein the instructions executable by the processor are further configured for:

monitoring an information technology environment using the plurality of user behavior profiles;

performing an enforcement operation if a user interaction with the information technology environment does not correspond to interactions based upon at least one of the plurality of user behavior profiles.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055452/0207 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Feb 27, 2020
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 052045/0482 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2019
From: FORD, RICHARD A.
To: FORCEPOINT LLC
Reel/Frame 050636/0375 →
Continuity (4)
Continuation 15979023 · May 14, 2018
Continuation In Part 15958738 · Apr 20, 2018
Provisional Application 62506300 · May 15, 2017
Related Publication 20200036740A1 · Jan 30, 2020