IP Library Granted Patent US 11,250,158
Granted Patent B2
US 11,250,158 · App. 16/864,980 · Granted Feb 15, 2022

Session-based security information

Inventors: Richard A. Ford (Austin, TX); Ann Irvine (Baltimore, MD); Russell Snyder (Baltimore, MD); Adam Reeve (Redmond, WA)
Assignee: Forcepoint, LLC
G06F21/6245G06F11/3438G06F21/552G06F21/577G06F21/602G06F21/6254G06F21/84H04L63/1408H04L63/1425H04L63/1433H04L63/1441H04L67/025H04L67/141H04L67/146H04L67/22H04L67/306G06F2221/031G06F2221/032G06F2221/034H04L63/20H04L67/289H04L2209/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,250,158
App. No.
16/864,980
Granted
Feb 15, 2022
Kind
B2
Abstract

A method, system and computer-usable medium for generating session-based security information. Generating the session-based security information includes the steps of monitoring user behavior between an enactor and an entity; detecting user behavior data associated with the user behavior; generating a session using the user behavior data, the session relating to an entity discrete interaction of the enactor; and, associating the session and the session-based security information with the user profile.

Claims (78)

1. A computer-implementable method for generating session-based security information, comprising:

monitoring user behavior between an enactor and an entity via a protected endpoint, the protected endpoint comprising an endpoint agent used in combination with an endpoint device, the endpoint agent executing on a hardware processor of the endpoint device;

detecting user behavior data associated with the user behavior;

generating a session using the user behavior data, the session relating to an entity discrete interaction of the enactor;

generating a session-based fingerprint, the session-based fingerprint comprising a unique identifier of the enactor associated with the session;

associating the session, the session-based security information and the session-based fingerprint with a user profile;

using the session-based security information and the user profile to detect anomalous, abnormal, unexpected or malicious behavior via a security analytics system, the security analytics system executing on a hardware processor of an information handling system; and,

mitigating a risk associated with the anomalous, abnormal, unexpected or malicious behavior, the mitigating the risk being performed via one of the protected endpoint and a security analytics system, the security analytics system executing on a hardware processor of an information handling system.

2. The method of claim 1 , further comprising:

generating a fingerprint, the fingerprint comprising a collection of information providing a distinctive, characteristic indicator of an identify of the enactor; and,

generating the session-based fingerprint using the fingerprint.

3. The method of claim 2 , wherein:

the collection of information comprises a user profile element.

4. The method of claim 1 , wherein:

the session comprises at least one of a plurality of session characteristics, the session characteristics comprising

two sessions being contiguous;

two sessions being associated but noncontiguous;

the session being associated with other sessions;

the session being a subset of another session; and,

the interval of time of the session overlapping with an interval of time of another session.

5. The method of claim 1 , wherein:

the user behavior enacted during the session is associated with an event.

6. The method of claim 1 , further comprising:

using the session-based fingerprint to perform security analytics operations.

7. A system comprising:

a hardware processor;

a data bus coupled to the hardware processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the hardware processor and configured for:

monitoring user behavior between an enactor and an entity via a protected endpoint, the protected endpoint comprising an endpoint agent used in combination with an endpoint device, the endpoint agent executing on a hardware processor of the system;

detecting user behavior data associated with the user behavior;

generating a session using the user behavior data, the session relating to an entity discrete interaction of the enactor;

generating a session-based fingerprint, the session-based fingerprint comprising a unique identifier of the enactor associated with the session;

associating the session, the session-based security information and the session-based fingerprint with a user profile;

using the session-based security information and the user profile to detect anomalous, abnormal, unexpected or malicious behavior via a security analytics system, the security analytics system executing on a hardware processor of an information handling system; and,

mitigating a risk associated with the anomalous, abnormal, unexpected or malicious behavior, the mitigating the risk being performed via one of the protected endpoint and a security analytics system, the security analytics system executing on a hardware processor of an information handling system.

8. The system of claim 7 , wherein the instructions executable by the processor are further configured for:

generating a fingerprint, the fingerprint comprising a collection of information providing a distinctive, characteristic indicator of an identify of the enactor; and,

generating the session-based fingerprint using the fingerprint.

9. The system of claim 8 , wherein:

the collection of information comprises a user profile element.

10. The system of claim 7 , wherein:

the session comprises at least one of a plurality of session characteristics, the session characteristics comprising

two sessions being contiguous;

two sessions being associated but noncontiguous;

the session being associated with other sessions;

the session being a subset of another session; and,

the interval of time of the session overlapping with an interval of time of another session.

11. The system of claim 7 , wherein:

the user behavior enacted during the session is associated with an event.

12. The system of claim 7 , wherein the instructions executable by the processor are further configured for:

using the session-based fingerprint to perform security analytics operations.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring user behavior between an enactor and an entity via a protected endpoint, the protected endpoint comprising an endpoint agent used in combination with an endpoint device, the endpoint agent executing on a hardware processor of the endpoint device;

detecting user behavior data associated with the user behavior;

generating a session using the user behavior data, the session relating to an entity discrete interaction of the enactor;

associating the session, the session-based security information and the session-based fingerprint with a user profile;

using the session-based security information and the user profile to detect anomalous, abnormal, unexpected or malicious behavior via a security analytics system, the security analytics system executing on a hardware processor of an information handling system; and,

mitigating a risk associated with the anomalous, abnormal, unexpected or malicious behavior, the mitigating the risk being performed via one of the protected endpoint and a security analytics system, the security analytics system executing on a hardware processor of an information handling system.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

generating a fingerprint, the fingerprint comprising a collection of information providing a distinctive, characteristic indicator of an identify of the enactor; and,

generating the session-based fingerprint using the fingerprint.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein:

the collection of information comprises a user profile element.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the session comprises at least one of a plurality of session characteristics, the session characteristics comprising

two sessions being contiguous;

two sessions being associated but noncontiguous;

the session being associated with other sessions;

the session being a subset of another session; and,

the interval of time of the session overlapping with an interval of time of another session.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the user behavior enacted during the session is associated with an event.

18. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

using the session-based fingerprint to perform security analytics operations.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 1, 2020
From: FORD, RICHARD A.; IRVINE, ANN; SNYDER, RUSSELL; REEVE, ADAM
To: FORCEPOINT, LLC
Reel/Frame 052551/0671 →
Cited By (3)
US 12,299,094 US 12,621,129 US 12,671,702