IP Library Granted Patent US 11,630,902
Granted Patent B2
US 11,630,902 · App. 16/791,445 · Granted Apr 18, 2023

Representing sets of behaviors within an entity behavior catalog

Inventors: Alan Ross (Austin, TX); Raffael Marty (Austin, TX); Margaret Cunningham (Austin, TX); Ruchika Pandey (Del Mar, CA)
Assignee: Forcepoint LLC
G06F21/577G06F21/552G06F21/554G06F21/566G06F21/6227G06N5/04G06N20/00H04L63/102H04L63/1425H04L63/1433H04L63/1441G06F2221/033G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,630,902
App. No.
16/791,445
Granted
Apr 18, 2023
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for performing an entity behavior cataloging operation. The entity behavior cataloging operation includes: identifying a plurality of security related activities, the plurality of security related activities being based upon observables from an electronic data source; analyzing the plurality of security related activities, the analyzing identifying a set of entity behaviors associated with the plurality of security related activities; and, performing a security operation via a security system, the security operation accessing entity behavior catalog data stored within an entity behavior catalog based upon the set of entity behaviors associated with the plurality of security related activities, the entity behavior catalog providing an inventory of entity behaviors for use when performing the security operation.

Claims (55)

1. A computer-implementable method for cataloging entity behavior, comprising:

identifying a plurality of security related activities, the plurality of security related activities being based upon observables from an electronic data source;

analyzing the plurality of security related activities, the analyzing identifying a set of entity behaviors associated with the plurality of security related activities; and,

performing a security operation via a security system, the security operation accessing entity behavior catalog data stored within an entity behavior catalog based upon the set of entity behaviors associated with the plurality of security related activities, the entity behavior catalog providing an inventory of entity behaviors for use when performing the security operation, the entity behavior catalog data comprising an entity behavior profiles repository, the entity behavior profiles repository containing a plurality of entity behavior profiles, each entity behavior profile comprising information that describes an identity of a particular entity and behavior associated with the particular entity, the security operation using an entity behavior profile of the plurality of entity behavior profiles in combination with an entity state to generate a user entity mindset profile, the user entity mindset profile comprising information that reflects an inferred mental state of the particular entity;

processing an entity behavior profile of a particular entity and user entity mindset profile of the particular entity to generate an inference regarding the particular entity;

processing the entity behavior profile of the particular entity and the inference regarding the particular entity to associate the entity behavior profile of the particular entity with a corresponding security risk use case selected from a plurality of security risk use cases, each corresponding security risk use case comprising a set of security related activities that create a security risk narrative, the security risk narrative being used to adaptively draw inferences from the set of entity behaviors associated with the plurality of security related activities.

2. The method of claim 1 , wherein:

the set of entity behaviors comprise at least one of a user entity behavior and a non-user entity behavior.

3. The method of claim 2 , wherein:

each behavior of the set of entity behaviors has an associated attribute, the associated attribute comprising at least one of a user entity attribute associated with the user entity behavior and a non-user entity attribute associated with the non-user entity behavior.

4. The method of claim 1 , wherein:

the entity behavior catalog comprises an entity behavior catalog repository, the entity behavior catalog repository comprising a security vulnerability scenarios repository, a risk use cases repository, an entity attributes repository, an entity behaviors repository, and an entity behavior model repository.

5. The method of claim 1 , wherein:

an analytic utility detection operation uses the entity behavior catalog to determine whether an event is of analytic utility.

6. The method of claim 5 , wherein:

the security analytics system performs the analytic utility detection operation.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

identifying a plurality of security related activities, the plurality of security related activities being based upon observables from an electronic data source;

analyzing the plurality of security related activities, the analyzing identifying a set of entity behaviors associated with the plurality of security related activities; and,

performing a security operation via a security system, the security operation accessing entity behavior catalog data stored within an entity behavior catalog based upon the set of entity behaviors associated with the plurality of security related activities, the entity behavior catalog providing an inventory of entity behaviors for use when performing the security operation, the entity behavior catalog data comprising an entity behavior profiles repository, the entity behavior profiles repository containing a plurality of entity behavior profiles, each entity behavior profile comprising information that describes an identity of a particular entity and behavior associated with the particular entity, the security operation using an entity behavior profile of the plurality of entity behavior profiles in combination with an entity state to generate a user entity mindset profile, the user entity mindset profile comprising information that reflects an inferred mental state of the particular entity

processing an entity behavior profile of a particular entity and mindset profile of the particular entity to generate an inference regarding the particular entity;

processing the entity behavior profile of the particular entity and the inference regarding the particular entity to associate the entity behavior profile of the particular entity with a corresponding security risk use case selected from a plurality of security risk use cases, each corresponding security risk use case comprising a set of security related activities that create a security risk narrative, the security risk narrative being used to adaptively draw inferences from the set of entity behaviors associated with the plurality of security related activities.

8. The system of claim 7 , wherein:

the set of entity behaviors comprise at least one of a user entity behavior and a non-user entity behavior.

9. The system of claim 8 , wherein:

each behavior of the set of entity behaviors has an associated attribute, the associated attribute comprising at least one of a user entity attribute associated with the user entity behavior and a non-user entity attribute associated with the non-user entity behavior.

10. The system of claim 7 , wherein:

the entity behavior catalog comprises an entity behavior catalog repository, the entity behavior catalog repository comprising a security vulnerability scenarios repository, a risk use cases repository, an entity attributes repository, an entity behaviors repository, and an entity behavior model repository.

11. The system of claim 7 , wherein:

an analytic utility detection operation uses the entity behavior catalog to determine whether an event is of analytic utility.

12. The system of claim 11 , wherein:

the security analytics system performs the analytic utility detection operation.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

identifying a plurality of security related activities, the plurality of security related activities being based upon observables from an electronic data source;

analyzing the plurality of security related activities, the analyzing identifying a set of entity behaviors associated with the plurality of security related activities; and,

performing a security operation via a security system, the security operation accessing entity behavior catalog data stored within an entity behavior catalog based upon the set of entity behaviors associated with the plurality of security related activities, the entity behavior catalog providing an inventory of entity behaviors for use when performing the security operation, the entity behavior catalog data comprising an entity behavior profiles repository, the entity behavior profiles repository containing a plurality of entity behavior profiles, each entity behavior profile comprising information that describes an identity of a particular entity and behavior associated with the particular entity, the security operation using an entity behavior profile of the plurality of entity behavior profiles in combination with an entity state to generate a user entity mindset profile, the user entity mindset profile comprising information that reflects an inferred mental state of the particular entity

processing an entity behavior profile of a particular entity and mindset profile of the particular entity to generate an inference regarding the particular entity;

processing the entity behavior profile of the particular entity and the inference regarding the particular entity to associate the entity behavior profile of the particular entity with a corresponding security risk use case selected from a plurality of security risk use cases, each corresponding security risk use case comprising a set of security related activities that create a security risk narrative, the security risk narrative being used to adaptively draw inferences from the set of entity behaviors associated with the plurality of security related activities.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the set of entity behaviors comprise at least one of a user entity behavior and a non-user entity behavior.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein:

each behavior of the set of entity behaviors has an associated attribute, the associated attribute comprising at least one of a user entity attribute associated with the user entity behavior and a non-user entity attribute associated with the non-user entity behavior.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the entity behavior catalog comprises an entity behavior catalog repository, the entity behavior catalog repository comprising a security vulnerability scenarios repository, a risk use cases repository, an entity attributes repository, an entity behaviors repository, and an entity behavior model repository.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

an analytic utility detection operation uses the entity behavior catalog to determine whether an event is of analytic utility.

18. The non-transitory, computer-readable storage medium of claim 17 , wherein:

the security analytics system performs the analytic utility detection operation.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2020
From: ROSS, ALAN; MARTY, RAFFAEL; CUNNINGHAM, MARGARET; PANDEY, RUCHIKA
To: FORCEPOINT LLC
Reel/Frame 052024/0230 →