IP Library Granted Patent US 11,537,668
Granted Patent B2
US 11,537,668 · App. 16/846,696 · Granted Dec 27, 2022

Using a machine learning system to process a corpus of documents associated with a user to determine a user-specific and/or process-specific consequence index

Inventors: Daniel Wallace Rapp (Highland, UT); Brian Sanford Jones (Cary, NC); Spencer Bror Koehler (Sandy, UT)
Assignee: Proofpoint, Inc.
G06F16/93G06N20/20G06Q50/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,537,668
App. No.
16/846,696
Granted
Dec 27, 2022
Kind
B2
Abstract

Aspects of the disclosure relate to using a machine learning system to process a corpus of documents associated with a user to determine a user-specific consequence index. A computing platform may load a corpus of documents associated with a user. Subsequently, the computing platform may create a first plurality of smart groups based on the corpus of documents, and then may generate a first user interface comprising a representation of the first plurality of smart groups. Next, the computing platform may receive user input applying one or more labels to a plurality of documents associated with at least one smart group. Subsequently, the computing platform may create a second plurality of smart groups based on the corpus of documents and the received user input. Then, the computing platform may generate a second user interface comprising a representation of the second plurality of smart groups.

Claims (62)

1. A computing platform, comprising:

at least one processor;

a communication interface; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

load a corpus of documents associated with a particular user;

create a first plurality of smart groups based on the corpus of documents associated with the particular user;

generate a first user interface comprising a representation of the first plurality of smart groups;

receive user input applying one or more labels to a plurality of documents associated with at least one smart group of the first plurality of smart groups;

create a second plurality of smart groups based on the corpus of documents associated with the particular user and the user input applying the one or more labels to the plurality of documents associated with the at least one smart group of the first plurality of smart groups;

generate a second user interface comprising a representation of the second plurality of smart groups;

receive, via the second user interface, user input applying a sensitivity value to one or more documents associated with at least one smart group of the second plurality of smart groups, the sensitivity value indicating a sensitivity of a respective document of the one or more documents associated with the at least one smart group of the second plurality of smart groups;

calculate a person-centric consequence index for the particular user associated with the corpus of documents based on the user input applying the sensitivity value to the one or more documents associated with the at least one smart group of the second plurality of smart groups;

output the person-centric consequence index calculated for the particular user associated with the corpus of documents to an enterprise risk classification system; and

update an attacked persons list based on the person-centric consequence index for the particular user associated with the corpus of documents in the enterprise risk classification system, the attacked persons list identifying users of an enterprise organization at risk of being targeted in cybersecurity attacks.

2. The computing platform of claim 1 , wherein loading the corpus of documents associated with the particular user comprises receiving a plurality of email messages associated with the user from an enterprise communications computer system.

3. The computing platform of claim 1 , wherein creating the first plurality of smart groups based on the corpus of documents associated with the particular user comprises executing multiple unsupervised machine-learning algorithms to produce the first plurality of smart groups.

4. The computing platform of claim 3 , wherein executing the multiple unsupervised machine-learning algorithms to produce the first plurality of smart groups comprises executing one or more clustering algorithms.

5. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

monitor user interactions involving the one or more smart groups of the first plurality of smart groups and one or more smart groups of the second plurality of smart groups; and

assign at least one priority value to a first set of smart groups of the one or more smart groups of the first plurality of smart groups and the one or more smart groups of the second plurality of smart groups based on the monitored user interactions.

6. The computing platform of claim 1 , wherein creating the second plurality of smart groups based on the corpus of documents associated with the particular user and the user input applying the one or more labels to the plurality of documents associated with the at least one smart group of the first plurality of smart groups comprises creating one or more smart groups of the second plurality of smart groups using a supervised machine learning mechanism.

7. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

output data associated with the second plurality of smart groups to an e-discovery platform application.

8. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

output data associated with the second plurality of smart groups to a compliance supervision application.

9. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

output data associated with the second plurality of smart groups to a malicious object or event labeling application.

10. The computing platform of claim 1 , further including instructions that, when executed, cause the computing platform to:

filter one or more email messages sent to or from the user associated with the corpus of documents based on the person-centric consequence index for the user associated with the corpus of documents.

11. The computing platform of claim 1 , further including instructions that, when executed, cause the computing platform to:

identify cybersecurity training for the particular user based on the person-centric consequence index of the particular user associated with the corpus of documents; and

provide the identified cybersecurity training to the particular user associated with the corpus of documents.

12. A method, comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

loading, by the at least one processor, a corpus of documents associated with a particular user;

creating, by the at least one processor, a first plurality of smart groups based on the corpus of documents associated with the particular user;

generating, by the at least one processor, a first user interface comprising a representation of the first plurality of smart groups;

receiving, by the at least one processor, user input applying one or more labels to a plurality of documents associated with at least one smart group of the first plurality of smart groups;

creating, by the at least one processor, a second plurality of smart groups based on the corpus of documents associated with the particular user and the user input applying the one or more labels to the plurality of documents associated with the at least one smart group of the first plurality of smart groups;

generating, by the at least one processor, a second user interface comprising a representation of the second plurality of smart groups;

receiving, by the at least one processor and via the second user interface, user input applying a sensitivity value to one or more documents associated with at least one smart group of the second plurality of smart groups, the sensitivity value indicating a sensitivity of a respective document of the one or more documents associated with the at least one smart group of the second plurality of smart groups;

calculating, by the at least one processor, a person-centric consequence index for the particular user associated with the corpus of documents based on the user input applying the sensitivity value to the one or more documents associated with the at least one smart group of the second plurality of smart groups;

outputting, by the at least one processor, the person-centric consequence index calculated for the particular user associated with the corpus of documents to an enterprise risk classification system; and

updating, by the at least one processor, an attacked persons list based on the person-centric consequence index for the particular user associated with the corpus of documents in the enterprise risk classification system, the attacked persons list identifying users of an enterprise organization at risk of being targeted in cybersecurity attacks.

13. The method of claim 12 , wherein loading the corpus of documents associated with the particular user comprises receiving a plurality of email messages associated with the user from an enterprise communications computer system.

14. The method of claim 12 , wherein creating the first plurality of smart groups based on the corpus of documents associated with the particular user comprises executing multiple unsupervised machine-learning algorithms to produce the first plurality of smart groups.

15. The method of claim 14 , wherein executing the multiple unsupervised machine-learning algorithms to produce the first plurality of smart groups comprises executing one or more clustering algorithms.

16. The method of claim 12 , comprising:

monitoring, by the at least one processor, user interactions involving the one or more smart groups of the first plurality of smart groups and one or more smart groups of the second plurality of smart groups; and

assigning, by the at least one processor, at least one priority value to a first set of smart groups of the one or more smart groups of the first plurality of smart groups and the one or more smart groups of the second plurality of smart groups based on the monitored user interactions.

17. The method of claim 12 , wherein creating the second plurality of smart groups based on the corpus of documents associated with the particular user and the user input applying the one or more labels to the plurality of documents associated with the at least one smart group of the first plurality of smart groups comprises creating one or more smart groups of the second plurality of smart groups using a supervised machine learning mechanism.

18. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

load a corpus of documents associated with a particular user;

create a first plurality of smart groups based on the corpus of documents associated with the particular user;

generate a first user interface comprising a representation of the first plurality of smart groups;

receive user input applying one or more labels to a plurality of documents associated with at least one smart group of the first plurality of smart groups;

create a second plurality of smart groups based on the corpus of documents associated with the particular user and the user input applying the one or more labels to the plurality of documents associated with the at least one smart group of the first plurality of smart groups;

generate a second user interface comprising a representation of the second plurality of smart groups;

receive, via the second user interface, user input applying a sensitivity value to one or more documents associated with at least one smart group of the second plurality of smart groups, the sensitivity value indicating a sensitivity of a respective document of the one or more documents associated with the at least one smart group of the second plurality of smart groups;

calculate a person-centric consequence index for the particular user associated with the corpus of documents based on the user input applying the sensitivity value to the one or more documents associated with the at least one smart group of the second plurality of smart groups;

output the person-centric consequence index calculated for the particular user associated with the corpus of documents to an enterprise risk classification system; and

update an attacked persons list based on the person-centric consequence index for the particular user associated with the corpus of documents in the enterprise risk classification system, the attacked persons list identifying users of an enterprise organization at risk of being targeted in cybersecurity attacks.

Assignments (5)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Mar 21, 2024
From: GOLDMAN SACHS BANK USA, AS AGENT
To: PROOFPOINT, INC.
Reel/Frame 066865/0648 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0615 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0642 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2020
From: RAPP, DANIEL WALLACE; JONES, BRIAN SANFORD; KOEHLER, SPENCER BROR
To: PROOFPOINT, INC.
Reel/Frame 052378/0382 →