IP Library Granted Patent US 11,295,023
Granted Patent B2
US 11,295,023 · App. 16/791,454 · Granted Apr 5, 2022

Defining groups of behaviors for storage within an entity behavior catalog

Inventors: Alan Ross (Austin, TX); Raffael Marty (Austin, TX); Margaret Cunningham (Austin, TX); Ruchika Pandey (Del Mar, CA)
Assignee: Forcepoint, LLC
G06F21/577G06F21/552G06F21/554G06F21/566G06F21/6227G06N5/04G06N20/00H04L63/102H04L63/1425H04L63/1433H04L63/1441G06F2221/033G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,295,023
App. No.
16/791,454
Granted
Apr 5, 2022
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for performing an entity behavior cataloging operation. The entity behavior cataloging operation includes: identifying a plurality of security related activities, the plurality of security related activities being based upon an observable from an electronic data source; analyzing the plurality of security related activities, the analyzing identifying a plurality of events of analytic utility associated with the plurality of security related activities; generating a set of entity behavior catalog data based upon the event of analytic utility associated with the security related activity, the set of entity behavior catalog data comprising an associated group of behaviors; and, storing the set of entity behavior data and the associated group of behaviors within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation.

Claims (61)

1. A computer-implementable method for cataloging entity behavior, comprising:

identifying a plurality of security related activities, the plurality of security related activities being based upon an observable from an electronic data source;

analyzing the plurality of security related activities, the analyzing identifying a plurality of events of analytic utility associated with the plurality of security related activities;

generating a set of entity behavior catalog data based upon the event of analytic utility associated with the security related activity, the set of entity behavior catalog data comprising an associated group of behaviors;

storing the set of entity behavior data and the associated group of behaviors within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation, the entity behavior catalog comprising an entity behavior profiles repository, the entity behavior profiles repository containing a plurality of entity behavior profiles, each entity behavior profile comprising information that describes an identity of a particular entity and behavior associated with the particular entity;

processing an entity behavior profile of a particular entity and contextual information relating to the particular entity to generate an inference regarding the particular entity;

processing the entity behavior profile of the particular entity and the inference regarding the particular entity to associate the entity behavior profile with a corresponding security risk use case; and,

associating the corresponding security risk use case with a corresponding security vulnerability scenario.

2. The method of claim 1 , wherein:

the group of behaviors comprise at least one of a user entity behavior and a non-user entity behavior.

3. The method of claim 2 , wherein:

each behavior of the group of behaviors has an associated attribute, the associated attribute comprising at least one of a user entity attribute associated with the user entity behavior and a non-user entity attribute associated with the non-user entity behavior.

4. The method of claim 1 , wherein:

the entity behavior catalog comprises an entity behavior catalog repository, the entity behavior catalog repository comprising at least one of a security vulnerability scenarios repository, a risk use cases repository, an entity behavior profiles repository, an entity attributes repository, an entity behaviors repository, an activities repository and an observables repository.

5. The method of claim 1 , wherein:

the group of behaviors are stored within at least one of the security vulnerability scenarios repository, the risk use cases repository, the entity behavior profiles repository, the entity attributes repository, the entity behaviors repository, the activities repository and the observables repository.

6. The method of claim 1 , wherein:

a behavior of the group of behaviors comprises at least one of a security vulnerability scenario, a risk use case, an entity behavior profile, an entity attribute, an entity behavior, an activities and an observable.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

identifying a plurality of security related activities, the plurality of security related activities being based upon an observable from an electronic data source;

analyzing the plurality of security related activities, the analyzing identifying a plurality of events of analytic utility associated with the plurality of security related activities;

generating a set of entity behavior catalog data based upon the event of analytic utility associated with the security related activity, the set of entity behavior catalog data comprising an associated group of behaviors;

storing the set of entity behavior data and the associated group of behaviors within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation, the entity behavior catalog comprising an entity behavior profiles repository, the entity behavior profiles repository containing a plurality of entity behavior profiles, each entity behavior profile comprising information that describes an identity of a particular entity and behavior associated with the particular entity;

processing an entity behavior profile of a particular entity and contextual information relating to the particular entity to generate an inference regarding the particular entity;

processing the entity behavior profile of the particular entity and the inference regarding the particular entity to associate the entity behavior profile with a corresponding security risk use case; and,

associating the corresponding security risk use case with a corresponding security vulnerability scenario.

8. The system of claim 7 , wherein:

the group of behaviors comprise at least one of a user entity behavior and a non-user entity behavior.

9. The system of claim 8 , wherein:

each behavior of the group of behaviors has an associated attribute, the associated attribute comprising at least one of a user entity attribute associated with the user entity behavior and a non-user entity attribute associated with the non-user entity behavior.

10. The system of claim 7 , wherein:

the entity behavior catalog comprises an entity behavior catalog repository, the entity behavior catalog repository comprising at least one of a security vulnerability scenarios repository, a risk use cases repository, an entity behavior profiles repository, an entity attributes repository, an entity behaviors repository, an activities repository and an observables repository.

11. The system of claim 7 , wherein:

the group of behaviors are stored within at least one of the security vulnerability scenarios repository, the risk use cases repository, the entity behavior profiles repository, the entity attributes repository, the entity behaviors repository, the activities repository and the observables repository.

12. The system of claim 7 , wherein:

a behavior of the group of behaviors comprises at least one of a security vulnerability scenario, a risk use case, an entity behavior profile, an entity attribute, an entity behavior, an activities and an observable.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

identifying a plurality of security related activities, the plurality of security related activities being based upon an observable from an electronic data source;

analyzing the plurality of security related activities, the analyzing identifying a plurality of events of analytic utility associated with the plurality of security related activities;

generating a set of entity behavior catalog data based upon the event of analytic utility associated with the security related activity, the set of entity behavior catalog data comprising an associated group of behaviors;

storing the set of entity behavior data and the associated group of behaviors within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation, the entity behavior catalog comprising an entity behavior profiles repository, the entity behavior profiles repository containing a plurality of entity behavior profiles, each entity behavior profile comprising information that describes an identity of a particular entity and behavior associated with the particular entity;

processing an entity behavior profile of a particular entity and contextual information relating to the particular entity to generate an inference regarding the particular entity;

processing the entity behavior profile of the particular entity and the inference regarding the particular entity to associate the entity behavior profile with a corresponding security risk use case; and,

associating the corresponding security risk use case with a corresponding security vulnerability scenario.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the group of behaviors comprise at least one of a user entity behavior and a non-user entity behavior.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein:

each behavior of the group of behaviors has an associated attribute, the associated attribute comprising at least one of a user entity attribute associated with the user entity behavior and a non-user entity attribute associated with the non-user entity behavior.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the entity behavior catalog comprises an entity behavior catalog repository, the entity behavior catalog repository comprising at least one of a security vulnerability scenarios repository, a risk use cases repository, an entity behavior profiles repository, an entity attributes repository, an entity behaviors repository, an activities repository and an observables repository.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the group of behaviors are stored within at least one of the security vulnerability scenarios repository, the risk use cases repository, the entity behavior profiles repository, the entity attributes repository, the entity behaviors repository, the activities repository and the observables repository.

18. The non-transitory, computer-readable storage medium of claim 13 , wherein:

a behavior of the group of behaviors comprises at least one of a security vulnerability scenario, a risk use case, an entity behavior profile, an entity attribute, an entity behavior, an activities and an observable.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2020
From: ROSS, ALAN; MARTY, RAFFAEL; CUNNINGHAM, MARGARET; PANDEY, RUCHIKA
To: FORCEPOINT LLC
Reel/Frame 052024/0529 →
Continuity (2)
Provisional Application 62964372 · Jan 22, 2020
Related Publication 20210224395A1 · Jul 22, 2021
Cited By (1)
US 12,278,834