IP Library Patent Application 16791442
Patent Application
App. No. 16/791,442

Determining an Abstraction Level for Contents of an Entity Behavior Catalog

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/791,442
Abstract

A system, method, and computer-readable medium are disclosed for performing an entity behavior cataloging operation. The entity behavior cataloging operation includes: identifying a security related activity, the security related activity being based upon an observable from an electronic data source; analyzing the security related activity, the analyzing identifying an event of analytic utility associated with the security related activity; generating entity behavior catalog data based upon the event of analytic utility associated with the security related activity, the entity behavior catalog data comprising an associated abstraction level; using the entity behavior catalog data and the associated abstraction level to generate a hierarchical set of entity behaviors representing a security risk; and, storing the hierarchical set of entity behaviors within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation.

Claims (55)

1 . A computer-implementable method for cataloging entity behavior, comprising:

identifying a security related activity, the security related activity being based upon an observable from an electronic data source;

analyzing the security related activity, the analyzing identifying an event of analytic utility associated with the security related activity;

generating entity behavior catalog data based upon the event of analytic utility associated with the security related activity, the entity behavior catalog data comprising an associated abstraction level;

using the entity behavior catalog data and the associated abstraction level to generate a hierarchical set of entity behaviors representing a security risk; and,

storing the hierarchical set of entity behaviors within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation.

2 . The method of claim 1 , wherein:

the associated abstraction level includes a behavior scenario abstraction level.

3 . The method of claim 1 , wherein:

the associated abstraction level includes a risk use case abstraction level.

4 . The method of claim 1 , wherein:

the associated abstraction level includes an entity behavior profile abstraction level.

5 . The method of claim 1 , wherein:

the associated abstraction level includes an entity attribute and behavior abstraction level.

6 . The method of claim 5 , wherein:

the associated abstraction level includes at least one of an activity abstraction level and observable abstraction level.

7 . A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

identifying a security related activity, the security related activity being based upon an observable from an electronic data source;

analyzing the security related activity, the analyzing identifying an event of analytic utility associated with the security related activity;

generating entity behavior catalog data based upon the event of analytic utility associated with the security related activity, the entity behavior catalog data comprising an associated abstraction level;

using the entity behavior catalog data and the associated abstraction level to generate a hierarchical set of entity behaviors representing a security risk; and,

storing the hierarchical set of entity behaviors within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation.

8 . The system of claim 7 , wherein:

the associated abstraction level includes a behavior scenario abstraction level.

9 . The system of claim 7 , wherein:

the associated abstraction level includes a risk use case abstraction level.

10 . The system of claim 7 , wherein:

the associated abstraction level includes an entity behavior profile abstraction level.

11 . The system of claim 7 , wherein:

the associated abstraction level includes an entity attribute and behavior abstraction level.

12 . The system of claim 11 , wherein:

the associated abstraction level includes at least one of an activity abstraction level and observable abstraction level.

13 . A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

identifying a security related activity, the security related activity being based upon an observable from an electronic data source;

analyzing the security related activity, the analyzing identifying an event of analytic utility associated with the security related activity;

generating entity behavior catalog data based upon the event of analytic utility associated with the security related activity, the entity behavior catalog data comprising an associated abstraction level;

using the entity behavior catalog data and the associated abstraction level to generate a hierarchical set of entity behaviors representing a security risk; and,

storing the hierarchical set of entity behaviors within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation.

14 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the associated abstraction level includes a behavior scenario abstraction level.

15 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the associated abstraction level includes a risk use case abstraction level.

16 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the associated abstraction level includes an entity behavior profile abstraction level.

17 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the associated abstraction level includes an entity attribute and behavior abstraction level.

18 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the associated abstraction level includes at least one of an activity abstraction level and observable abstraction level.

19 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20 . The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 4, 2020
From: ROSS, ALAN; RYAN, TOBIAS JOHNATHON; MARTY, RAFFAEL
To: FORCEPOINT LLC
Reel/Frame 052558/0643 →