IP Library Granted Patent US 11,799,890
Granted Patent B2
US 11,799,890 · App. 16/948,779 · Granted Oct 24, 2023

Detecting anomalous downloads

Inventors: Kave Eshghi (Los Altos, CA); Victor De Vansa Vikramaratne (Sunnyvale, CA)
Assignee: Box, Inc.
H04L63/1425H04L63/1416H04L63/20H04L67/1097H04L67/535G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,799,890
App. No.
16/948,779
Granted
Oct 24, 2023
Kind
B2
Abstract

Disclosed is an improved systems, methods, and computer program products that performs user behavior analysis to identify malicious behavior in a computing system. The approach may be implemented by generating feature vectors for two time periods, performing scoring, and then performing anomaly detection.

Claims (39)

1. A computer-implemented method, comprising: capturing interaction data pertaining to user to file interactions from a plurality of signals, wherein the plurality of signals pertaining to the user to file interactions is detected at an input device and is received at a network link of a content collaboration system, and the interaction data comprises user identification data of a plurality of users and object identification data of a plurality of content objects on which at least some of the plurality of users collaborate; storing a first ordered list of first entries into first respective fields in memory for a first vector, wherein the first vector is generated for a first time period of the interaction data; storing a second ordered list of second entries into second respective fields in the memory for a second vector, wherein the second vector is generated for a second time period of the interaction data, and a first respective field or a second respective field stores information pertaining to the user identification data; retrieving the first vector from the first respective fields and the second vector from the second respective fields in the memory to compute a score, wherein the score is determined based at least in part upon an analysis of the first and second vectors; and sending an electronic message over the network link from a first network location to a second network location, wherein the electronic message comprises an alert that is generated based at least in part upon a determination that the positive score is indicative of an anomalous access.

2. The method of claim 1 , wherein the first or the second vector is generated by:

generating file clusters;

weighting the user to file interactions;

calculating an interaction weight between a user and a single file cluster of the file clusters; and

generating the first or the second vector based at least in part upon the interaction weight.

3. The method of claim 2 , the wherein the first or the second vector corresponds to an n-dimensional vector corresponding to multiple interaction weights for the file clusters.

4. The method of claim 1 , wherein the score is generated by comparing magnitudes of the first and second vectors, and the score corresponds to a difference between the first and second vectors.

5. The method of claim 1 , wherein a weight is applied to at least one of the user to file interactions with respect to a file cluster.

6. The method of claim 5 , wherein the weight is based at least in part upon at least one of a file location, a pathname, a file type, a file size, file content, or a sensitivity label.

7. The method of claim 5 , wherein a learning process is applied to determine the weight.

8. The method of claim 1 , further comprising another analysis stage based at least in part on the analysis of the second vector for the second time period.

9. The method of claim 8 , wherein an entropy function is applied for the analysis of the second vector to identify a distribution of weights for the second time period.

10. A non-transitory computer readable medium having stored thereon a sequence of instructions which, which when executed by a processor, causes the processor to perform a set of acts, the set of acts comprising: capturing interaction data pertaining to user to file interactions from a plurality of signals, wherein the plurality of signals pertaining to the user to file interactions is detected at an input device and is received at a network link of a content collaboration system, and the interaction data comprises user identification data of a plurality of users and object identification data of a plurality of content objects on which at least some of the plurality of users collaborate; storing a first ordered list of first entries into first respective fields in memory for a first vector, wherein the first vector is generated for a first time period of the interaction data; storing a second ordered list of second entries into second respective fields in the memory for a second vector, wherein the second vector is generated for a second time period of the interaction data, and a first respective field or a second respective field stores information pertaining to the user identification data; retrieving the first vector from the first respective fields and the second vector from the second respective fields in the memory to compute a score, wherein the score is determined based at least in part upon an analysis of the first and second vectors; and sending an electronic message over the network link from a first network location to a second network location, wherein the electronic message comprises an alert that is generated based at least in part upon a determination that the positive score is indicative of an anomalous access, the first vector is determined using the user identification data in the first time period, and the second vector is determined using the user identification data in the second time period.

11. The non-transitory computer readable medium of claim 10 , wherein the first or the second vector is generated by:

generating file clusters;

weighting the user to file interactions;

calculating an interaction weight between a user and a single file cluster of the file clusters; and

generating the first or the second vector based at least in part upon the interaction weight.

12. The non-transitory computer readable medium of claim 11 , the wherein the vector corresponds to an n-dimensional vector corresponding to multiple interaction weights for the file clusters.

13. The non-transitory computer readable medium of claim 10 , wherein the score is generated by comparing magnitudes of the first and second vectors, and the score corresponds to a difference between the first and second vectors.

14. The non-transitory computer readable medium of claim 10 , wherein a weight is applied to at least one of the user to file interactions with respect to a file cluster.

15. The non-transitory computer readable medium of claim 14 , wherein the weight is based at least in part upon at least one of a file location, a pathname, a file type, a file size, file content, or a sensitivity label.

16. The non-transitory computer readable medium of claim 14 , wherein a learning process is applied to determine the weight.

17. The non-transitory computer readable medium of claim 10 , further comprising another analysis stage based at least in part on the analysis of the second vector for the second time period.

18. The non-transitory computer readable medium of claim 17 , wherein an entropy function is applied for the analysis of the second vector to identify a distribution of weights for the second time period.

19. A computing system comprising: a memory to hold a set of instructions; a computer processor to execute the set of instructions, which when executed cause the computer processor to perform a set of acts, the set of acts comprising: capturing interaction data pertaining to user to file interactions from a plurality of signals, wherein the plurality of signals pertaining to the user to file interactions is detected at an input device and is received at a network link of a content collaboration system, and the interaction data comprises user identification data of a plurality of users and object identification data of a plurality of content objects on which at least some of the plurality of users collaborate; storing a first ordered list of first entries into first respective fields in memory for a first vector, wherein the first vector is generated for a first time period of the interaction data; storing a second ordered list of second entries into second respective fields in the memory for a second vector, wherein the second vector is generated for a second time period of the interaction data, and a first respective field or a second respective field stores information pertaining to the user identification data; retrieving the first vector from the first respective fields and the second vector from the second respective fields in the memory to compute a score, wherein the score is determined based at least in part upon an analysis of the first and second vectors; and sending an electronic message over the network link from a first network location to a second network location, wherein the electronic message comprises an alert that is generated based at least in part upon a determination that the positive score is indicative of an anomalous download event.

20. The system of claim 19 , wherein a vector is generated by the computer processor executing the set of instructions, which when executed by the computer processor, further causes the computer processor to perform a set of acts, the set of acts further comprising:

generating file clusters;

weighting the user to file interactions;

calculating an interaction weight between a user and a single file cluster of the file clusters; and

generating the first or the second vector based at least in part upon the interaction weight.

21. The system of claim 20 , the wherein the first or the second vector corresponds to a n-dimensional vector corresponding to multiple interaction weights for the file clusters.

22. The system of claim 19 , wherein the score is generated by comparing magnitudes of the first and second vectors, and the score corresponds to a difference between the first and second vectors.

23. The system of claim 19 , wherein a weight is applied to at least one of the user to file interactions with respect to a file cluster.

24. The system of claim 23 , wherein the weight is based at least in part upon at least one of a file location, a pathname, a file type, a file size, file content, or a sensitivity label.

25. The system of claim 23 , wherein a learning process is applied to determine the weight.

26. The system of claim 19 , further comprising another analysis stage based at least in part on the analysis of the second vector for the second time period.

27. The system of claim 26 , wherein an entropy function is applied for the analysis of the second vector to identify a distribution of weights for the second time period.

Assignments (2)
SECURITY INTEREST Recorded Jul 26, 2023
From: BOX, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 064389/0686 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 22, 2022
From: ESHGHI, KAVE; VIKRAMARATNE, VICTOR DE VANSA
To: BOX, INC.
Reel/Frame 061859/0246 →
Continuity (2)
Provisional Application 62909121 · Oct 1, 2019
Related Publication 20210099475A1 · Apr 1, 2021