IP Library Granted Patent US 11,799,877
Granted Patent B2
US 11,799,877 · App. 16/713,419 · Granted Oct 24, 2023

Supervisory control and data acquisition

Inventors: Nomi Becker (Smithtown, NY); Isaac Smitley (Arlington, VA)
Assignee: Palantir Technologies Inc.
H04L63/1416H04L63/0227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,799,877
App. No.
16/713,419
Granted
Oct 24, 2023
Kind
B2
Abstract

Aspects of the present disclosure relate to computer system security. A machine accesses a set of records corresponding to a set of users having access to a computer system. The machine stores, for each user in the set of users, a baseline profile representing baseline activity of the user with respect to a set of data sources of the computer system. The machine monitors activity of the set of users with respect to the set of data sources. The machine determines, based on monitoring the activity of the set of users, that a user action of a specified user, with respect to one or more data sources from the set of data sources, is anomalous relative to the baseline profile of the specified user. The machine provides a digital transmission representing the anomalous user action.

Claims (34)

1. A control server comprising:

one or more processors; and

a memory storing instructions which, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

storing, for each user in a set of users having access to a set of data sources, a baseline profile representing baseline activity of the user with respect to a set of data sources;

monitoring activity of the set of users with respect to the set of data sources;

transmitting, to a client device for display thereat, a representation of a plurality of user activities of the set of users, each user activity unit among the plurality of user activities having at least a time, an action type, a user identifier, and whether each user activity unit is consistent with the baseline profile;

determining that a user activity unit from among the representation of the plurality of user activities is inconsistent with the baseline profile of a user from among the set of users, the user activity unit comprising modifying a certificate authority;

determining that the user has never modified the certificate authority previously; and

transmitting, responsive to determining that the user activity unit comprises modifying the certificate authority, and that the user has never modified the certificate authority previously, to the client device for display thereat, a digital transmission that comprises a detailed view of the inconsistent user activity unit, wherein the detailed view includes a display of at least a portion of the baseline profile that corresponds with the inconsistent user activity unit.

2. The control server of claim 1 , wherein the action type of the user activity unit is a data transmission, wherein the representation of a plurality of actions indicates that the action type is a data transmission, and wherein the detailed view indicates an amount of data transmitted, a source Internet Protocol (IP) address of the data transmission, and a destination IP address of the data transmission.

3. The control server of claim 1 , wherein the set of data sources is hosted at a computer system.

4. The control server of claim 3 , wherein the set of data sources comprises one or more of: a packet log of packets travelling between the computer system and an external network, a driver log of the computer system, a secure socket layer (SSL) certificate authority (CA) of the computer system, a programmable logic controller (PLC) of the computer system, a simple mail transfer protocol (SMTP) log of the computer system, a web access log of the computer system, service repos of the computer system, network drives of the computer system, workstation performance logs of the computer system, and workstation network traffic of the computer system.

5. The control server of claim 3 , wherein the set of users having access to the set of data sources comprise system administrators of the computer system.

6. A non-transitory machine-readable medium storing instructions which, when executed by one or more processors of a machine, cause the one or more processors to perform operations comprising:

storing, for each user in a set of users having access to a set of data sources, a baseline profile representing baseline activity of the user with respect to a set of data sources;

monitoring activity of the set of users with respect to the set of data sources;

transmitting, to a client device for display thereat, a representation of a plurality of user activities of the set of users, each user activity unit among the plurality of user activities having at least a time, an action type, a user identifier, and whether each user activity unit is consistent with the baseline profile;

determining that a user activity unit from among the representation of the plurality of user activities is inconsistent with the baseline profile of a user from among the set of users, the user activity unit comprising modifying a certificate authority;

determining that the user has never modified the certificate authority previously; and

transmitting, responsive to determining that the user activity unit comprises modifying the certificate authority, and that the user has never modified the certificate authority previously, to the client device for display thereat, a digital transmission that comprises a detailed view of the inconsistent user activity unit, wherein the detailed view includes a display of at least a portion of the baseline profile that corresponds with the inconsistent user activity unit.

7. The machine-readable medium of claim 6 , wherein the action type of the user activity unit is a data transmission, wherein the representation of a plurality of actions indicates that the action type is a data transmission, and wherein the detailed view indicates an amount of data transmitted, a source Internet Protocol (IP) address of the data transmission, and a destination IP address of the data transmission.

8. The machine-readable medium of claim 6 , wherein the set of data sources is hosted at a computer system.

9. The machine-readable medium of claim 8 , wherein the set of data sources comprises one or more of: a packet log of packets travelling between the computer system and an external network, a driver log of the computer system, a secure socket layer (SSL) certificate authority (CA) of the computer system, a programmable logic controller (PLC) of the computer system, a simple mail transfer protocol (SMTP) log of the computer system, a web access log of the computer system, service repos of the computer system, network drives of the computer system, workstation performance logs of the computer system, and workstation network traffic of the computer system.

10. The machine-readable medium of claim 8 , wherein the set of users having access to the set of data sources comprise system administrators of the computer system.

11. A method comprising:

storing, for each user in a set of users having access to a set of data sources, a baseline profile representing baseline activity of the user with respect to a set of data sources;

monitoring activity of the set of users with respect to the set of data sources;

transmitting, to a client device for display thereat, a representation of a plurality of user activities of the set of users, each user activity unit among the plurality of user activities having at least a time, an action type, a user identifier, and whether each user activity unit is consistent with the baseline profile,

determining that a user activity unit from among the representation of the plurality of user activities is inconsistent with the baseline profile of a user from among the set of users, the user activity unit comprising modifying a certificate authority;

determining that the user has never modified the certificate authority previously; and

transmitting, responsive to determining that the user activity unit comprises modifying the certificate authority, and that the user has never modified the certificate authority previously, to the client device for display thereat, a digital transmission that comprises a detailed view of the inconsistent user activity unit, wherein the detailed view includes a display of at least a portion of the baseline profile that corresponds with the inconsistent user activity unit.

12. The method of claim 11 , wherein the action type of the user activity unit is a data transmission, wherein the representation of a plurality of actions indicates that the action type is a data transmission, and wherein the detailed view indicates an amount of data transmitted, a source Internet Protocol (IP) address of the data transmission, and a destination IP address of the data transmission.

13. The method of claim 11 , wherein the set of data sources is hosted at a computer system.

14. The method of claim 13 , wherein the set of data sources comprises one or more of: a packet log of packets travelling between the computer system and an external network, a driver log of the computer system, a secure socket layer (SSL) certificate authority (CA) of the computer system, a programmable logic controller (PLC) of the computer system, a simple mail transfer protocol (SMTP) log of the computer system, a web access log of the computer system, service repos of the computer system, network drives of the computer system, workstation performance logs of the computer system, and workstation network traffic of the computer system.

Assignments (4)
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
CORRECTIVE ASSIGNMENT TO CORRECT THE 2ND INVENTOR'S NAME PREVIOUSLY RECORDED AT REEL: 51275 FRAME: 216. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Dec 31, 2019
From: BECKER, NOMI; SMITLEY, ISAAC
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 051450/0318 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 13, 2019
From: BECKER, NOMI; SMITELY, ISAAC
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 051275/0216 →
Continuity (5)
Continuation 16359021 · Mar 20, 2019
Continuation 16042702 · Jul 23, 2018
Continuation 15434930 · Feb 16, 2017
Provisional Application 62352933 · Jun 21, 2016
Related Publication 20200120116A1 · Apr 16, 2020