IP Library Granted Patent US 11,080,109
Granted Patent B1
US 11,080,109 · App. 16/802,969 · Granted Aug 3, 2021

Dynamically reweighting distributions of event observations

Inventors: Christopher Poirel (Baltimore, MD); William Renner (Baltimore, MD); Eduardo Luiggi (Ellicott City, MD)
Assignee: Forcepoint LLC
G06F9/542G06F9/4837G06F16/215G06F16/242G06F16/24534
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,080,109
App. No.
16/802,969
Granted
Aug 3, 2021
Kind
B1
Abstract

A system, method, and computer-readable medium are disclosed for performing a distribution of interrelated event features operation. The distribution of interrelated event features includes: receiving a stream of events, the stream of events comprising a plurality of events; extracting features from the plurality of events; constructing a distribution of the features from the plurality of events; analyzing the distribution of the features from the plurality of events; and, dynamically reweighting the distribution of the features to scale a number of events contained within the distribution.

Claims (65)

1. A computer-implementable method for constructing a distribution of interrelated event features, comprising:

receiving a stream of events, the stream of events comprising a plurality of events;

extracting features from the plurality of events;

constructing a distribution of the features from the plurality of events, the distribution of the features comprising a probability density function distribution of features over a series of time windows;

analyzing the distribution of the features from the plurality of events;

dynamically reweighting the distribution of the features to scale a number of events contained within the distribution; and,

enriching data associated with each of the plurality of events prior to extracting features from the plurality of events; and wherein

the enriching data comprises at least one of

validating event data associated with at least some of the plurality of events,

disclaiming certain event data associated with at least some of the plurality of events;

deduplicating at least some of the plurality of events;

performing an entity resolution operation on at least some of the plurality of events;

performing an attachment enrichment operation on data associated with at least some of the plurality of events; and,

performing a domain enrichment on at least some of the plurality of events.

2. The method of claim 1 , further comprising:

labeling at least some of the plurality of events prior to extracting features from the plurality of events.

3. The method of claim 1 , wherein:

the extracting features comprises performing transformation operations on certain features associated with an event to generate a smaller set of derived features.

4. The method of claim 1 , further comprising:

processing a query relating to the plurality of events, the processing the query being performed via a streaming query framework.

5. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

receiving a stream of events, the stream of events comprising a plurality of events;

extracting features from the plurality of events;

constructing a distribution of the features from the plurality of events, the distribution of the features comprising a probability density function distribution of features over a series of time windows;

analyzing the distribution of the features from the plurality of events:

dynamically reweighting the distribution of the features to scale a number of events contained within the distribution; and,

enriching data associated with each of the plurality of events prior to extracting features from the plurality of events; and wherein

the enriching data comprises at least one of

validating event data associated with at least some of the plurality of events,

disclaiming certain event data associated with at least some of the plurality of events;

deduplicating at least some of the plurality of events;

performing an entity resolution operation on at least some of the plurality of events;

performing an attachment enrichment operation on data associated with at least some of the plurality of events; and,

performing a domain enrichment on at least some of the plurality of events.

6. The system of claim 5 , wherein the instructions are further configured for:

labeling at least some of the plurality of events prior to extracting features from the plurality of events.

7. The system of claim 5 , wherein:

the extracting features comprises performing transformation operations on certain features associated with an event to generate a smaller set of derived features.

8. The system of claim 5 , wherein the instructions are further configured for:

processing a query relating to the plurality of events, the processing the query being performed via a streaming query framework.

9. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

receiving a stream of events, the stream of events comprising a plurality of events;

extracting features from the plurality of events;

constructing a distribution of the features from the plurality of events, the distribution of the features comprising a probability density function distribution of features over a series of time windows;

analyzing the distribution of the features from the plurality of events;

dynamically reweighting the distribution of the features to scale a number of events contained within the distribution; and,

enriching data associated with each of the plurality of events prior to extracting features from the plurality of events; and wherein

the enriching data comprises at least one of

validating event data associated with at least some of the plurality of events,

disclaiming certain event data associated with at least some of the plurality of events;

deduplicating at least some of the plurality of events;

performing an entity resolution operation on at least some of the plurality of events;

performing an attachment enrichment operation on data associated with at least some of the plurality of events; and,

performing a domain enrichment on at least some of the plurality of events.

10. The non-transitory, computer-readable storage medium of claim 9 , wherein the computer executable instructions are further configured for:

labeling at least some of the plurality of events prior to extracting features from the plurality of events.

11. The non-transitory, computer-readable storage medium of claim 9 , wherein:

the extracting features comprises performing transformation operations on certain features associated with an event to generate a smaller set of derived features.

12. The non-transitory, computer-readable storage medium of claim 9 , wherein the computer executable instructions are further configured for:

processing a query relating to the plurality of events, the processing the query being performed via a streaming query framework.

13. The non-transitory, computer-readable storage medium of claim 9 , wherein the computer executable instructions are deployable to a client system from a server system at a remote location.

14. The non-transitory, computer-readable storage medium of claim 9 , wherein the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (5)
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0524 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 27, 2020
From: POIREL, CHRISTOPHER; RENNER, WILLIAM; LUIGGI, EDUARDO
To: FORCEPOINT LLC
Reel/Frame 051949/0644 →