IP Library › Granted Patent US 11,516,238
Granted Patent B2
US 11,516,238 · App. 16/989,497 · Granted Nov 29, 2022

Systems and methods for monitoring user activities

Inventor: Razieh Niazi (Toronto, CA)
Assignee: BANK OF MONTREAL
H04L63/1425G06F16/182
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,516,238
App. No.
16/989,497
Granted
Nov 29, 2022
Kind
B2
Abstract

Disclosed herein are embodiments of systems, methods, and products comprises a server for monitoring and tracking user activities based on different events in a security log. The server may retrieve the security log and parse the security log to identify a set of predetermined events for a user based on the event IDs, including logon events, logoff events, and privileged events. Based on the time point when privileged events occur at least partially during the pattern of having more logon events than logoff events, the server may determine when the user starts to work. Based on the time point when the logoff events and logon event starts to show the pattern that there are more logoff events than logon events and the difference increasing into a threshold, the server may determine when the user stops working. The server may generate a heat map indicating different users' work time length.

Claims (51)

1. A method comprising:

periodically intercepting, by a server, data packets communicated between a computer of a user and a file server of an entity to generate a security log associated with interactions between the computer of the user and the file server;

identifying, by the server, a set of predetermined events for the user from the security log by parsing the security log based on event identifiers, the set of predetermined events corresponding to logon events, logoff events, and privileged events of operations on a privileged object in the file server;

determining, by the server, one or more patterns for the set of predetermined events during different time periods,

where a first pattern corresponds to a number of the logon events being greater than a number of the logoff events during a first time period, a number of the privileged events occurring at least partially during the first pattern of the number of logon events being greater than the number of logoff events during the first period, and a first maximum difference between the number of the logon events and the number of the logoff events satisfying a first threshold, and

where a second pattern corresponds to the number of the logoff events being greater than the number of the logon events during a second time period and a second maximum difference between the number of the logoff events and the number of the logon events satisfying a second threshold;

determining, by the server, a starting point of the user's work time as a first time when the number of the privileged events satisfying a third threshold occur at least partially during the first pattern of the number of logon events being greater than the number of logoff events during the first period;

determining, by the server, an end point of the user's work time as a second time when the logoff events and the logon events diverge into the second pattern;

calculating, by the server, a length of work time for the user based on the starting point and the ending point of the user's work time; and

dynamically populating, by the server, a heat map indicating the length of work time of the user in a predetermined time interval.

2. The method of claim 1 , further comprising:

retrieving, by the server, the security log from the file server, wherein the security log comprises records of security events on the file server.

3. The method of claim 1 , further comprising:

generating, by the server, the security log by checking at least one of headers and payloads of the data packets.

4. The method of claim 1 , wherein the file server generates the logoff events by closing logon sessions associated with the computer of the user after the user has been inactive for a predetermined period of time.

5. The method of claim 1 , wherein the security log includes the logon events and the logoff events generated from automatic system refreshing and ticket updating.

6. The method of claim 1 , wherein the privileged events indicate that the user is accessing shared folders in the file server.

7. The method of claim 1 , wherein the file server comprises a domain controller that grants access to a number of computer resources of the file server.

8. The method of claim 1 , further comprising:

determining, by the server, a correlation between user activities and the first and second patterns.

9. The method of claim 1 , further comprising:

determining, by the server, a number of each predetermined event at a particular time based on an identifier and a timestamp associated with the respective predetermined event.

10. The method of claim 1 , further comprising:

determining, by the server, project identifiers associated with the user during the user's work time.

11. A system comprising:

a computer of a user,

a file server of an entity,

a server in communication with the computer and the file server and configured to:

periodically intercept data packets communicated between the computer of the user and the file server of the entity to generate a security log associated with interactions between the computer of the user and the file server;

identify a set of predetermined events for the user from the security log by parsing the security log based on event identifiers, the set of predetermined events correspond to logon events, logoff events, and privileged events of operations on a privileged object in the file server;

determine one or more patterns for the set of predetermined events during different time periods,

where a first pattern corresponds to a number of the logon events being greater than a number of the logoff events during a first time period, a number of the privileged events occurring at least partially during the first pattern of the number of logon events being greater than the number of logoff events during the first period, and a first maximum difference between the number of the logon events and the number of the logoff events satisfying a first threshold, and

where a second pattern corresponds to the number of the logoff events being greater than the number of the logon events during a second time period and a second maximum difference between the number of the logoff events and the number of the logon events satisfying a second threshold;

determine a starting point of the user's work time as a first time when the number of the privileged events satisfying a third threshold occur at least partially during the first pattern of the number of logon events being greater than the number of logoff events during the first period; and

determine an ending point of the user's work time as a second time when the logoff events and the logon events diverge into the second pattern;

calculate a length of work time for the user based on the starting point and the ending point of the user's work time; and

dynamically populate a heat map indicating the length of work time of the user in a predetermined time interval.

12. The system of claim 11 , wherein the server is further configured to:

retrieve the security log from the file server, wherein the security log comprises records of security events on the file server.

13. The system of claim 11 , wherein the server is further configured to:

generate the security log by checking at least one of headers and payloads of the data packets.

14. The system of claim 11 , wherein the file server generates the logoff events by closing logon sessions associated with the computer of the user after the user has been inactive for a predetermined period of time.

15. The system of claim 11 , wherein the security log includes the logon events and the logoff events generated from automatic system refreshing and ticket updating.

16. The system of claim 11 , wherein the privileged events indicate that the user is accessing shared folders in the file server.

17. The system of claim 11 , wherein the file server comprises a domain controller that grants access to a number of computer resources of the file server.

18. The system of claim 11 , wherein the server is further configured to:

determine a correlation between user activities and the first and second patterns.

19. The system of claim 11 , wherein the server is further configured to:

determine a number of each predetermined event at a particular time based on an identifier and a timestamp associated with the respective predetermined event.

20. The system of claim 11 , wherein the server is further configured to:

determine project identifiers associated with the user during the user's work time.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 10, 2020
From: NIAZI, RAZIEH
To: BANK OF MONTREAL
Reel/Frame 053447/0618 →
Continuity (2)
Provisional Application 62887365 · Aug 15, 2019
Related Publication 20210051166A1 · Feb 18, 2021