IP Library › Granted Patent US 11,824,832
Granted Patent B2
US 11,824,832 · App. 16/995,929 · Granted Nov 21, 2023

Prevention of malicious use of endpoint devices

Inventors: Karan Jayant Dalvi (Pompano Beach, FL); Joseph L. Freedman (Parkland, FL); Jose Angel Lago Graveran (Boca Raton, FL)
H04L63/0236G06N20/00H04L63/101H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,824,832
App. No.
16/995,929
Filed
Aug 18, 2020
Granted
Nov 21, 2023
Kind
B2
Art Unit
2496
USPC
726/11
Abstract

Methods and systems for preventing malicious use of endpoint devices are described herein. A computing device may receive data indicative of usage of the computing device by a user. The computing device may compare the received data with other data (indicative of how an authorized user for the computing device uses the computing device) stored on the computing device to identify instances of abnormal usage of the computing device. The computing device may detect unauthorized use of the computing device based on the number of instances of abnormal usage exceeding a threshold. The computing device may prevent access to a computing environment with use of the computing device in response to detection of unauthorized use.

Claims (75)

1. A computing device comprising:

at least one processor;

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing device to:

receive data indicative of usage of the computing device by a user;

compare the received data with other data corresponding to one or more metrics stored on the computing device to identify instances of abnormal usage of the computing device, the other data indicative of how an authorized user for that computing device uses the computing device, wherein the one or more metrics comprise one or more of: location data or information indicating interactions of the authorized user with an application on the computing device;

detect unauthorized use of the computing device based on the number of instances of abnormal usage exceeding a threshold, wherein detecting the unauthorized use of the computing device comprises:

identifying, for each metric of the one or more metrics and based on the comparison of the received data with the other data, whether the received data for the corresponding metric indicates unauthorized use of the computing device;

computing, using negative weighted values for metrics indicating possible unauthorized use of the computing device, a first set of weighted metric scores;

computing, using positive weighted values for metrics indicating authorized use of the computing device, a second set of weighted metric scores;

computing, by adding the first set of weighted metric scores and the second set of weighted metric scores, a weighted security score, wherein a nonnegative weighted security score indicates authorized use of the computing device and a negative weighted security score indicates unauthorized use of the computing device; and

in response to determining that the weighted security score is a negative value, determining that the computing device is being used in an unauthorized manner; and

prevent access to a computing environment with use of the computing device in response to detection of unauthorized use.

2. The computing device of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, further cause the computing device to:

receive the other data, wherein receiving the other data comprises receiving data corresponding to the one or more metrics.

3. The computing device of claim 2 , wherein the one or more metrics are selected based on a job title of the authorized user of the computing device.

4. The computing device of claim 2 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, further cause the computing device to:

train, using the other data stored on the computing device, a machine learning model, wherein training the machine learning model configures the machine learning model to distinguish use of the computing device by the authorized user of the computing device from use of the computing device by an unauthorized user of the computing device.

5. The computing device of claim 4 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing device to train the machine learning model by:

computing, for the one or more metrics, weighted values indicating how relevant each of the one or more metrics is to identifying unauthorized access to the computing device.

6. The computing device of claim 5 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing device to compute the weighted values by:

computing, for a first metric of the one or more metrics and based on a first average deviation value of initial data corresponding to the first metric, a first weighted value; and

computing, for a second metric of the one or more metrics and based on a second average deviation value of initial data corresponding to the second metric, a second weighted value, and wherein:

the first average deviation value is lower than the second average deviation value, and

the first weighted value is larger than the second weighted value.

7. The computing device of claim 5 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, further cause the computing device to:

compare the weighted values to a predetermined metric selection threshold;

determine that a subset of the weighted values do not exceed the predetermined metric selection threshold; and

remove, from the machine learning model, initial data corresponding to metrics affiliated with the subset of the weighted values.

8. The computing device of claim 4 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing device to train the machine learning model by:

establishing, based on the other data and for the one or more metrics, one or more metric thresholds that separate other data corresponding to each of the one or more metrics into subgroups for the corresponding one or more metrics, and

wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing device to compare the received data to the other data by:

filtering the received data based on the one or more metric thresholds; and

comparing the received data for each of the one or more metric thresholds with the other data for the corresponding metric thresholds of the one or more metric thresholds.

9. The computing device of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing device to prevent access to the computing environment with the use of the computing device by performing one or more of: deleting data from the computing device, disabling an authentication token, or prompting for re-authentication.

10. The computing device of claim 9 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing device to prevent access to the computing environment in response to determining that a connection between the computing device and an enterprise server is unavailable for communication.

11. A method comprising:

receiving, by a computing device, data indicative of usage of the computing device by a user;

comparing the received data with other data corresponding to one or more metrics stored on the computing device to identify instances of abnormal usage of the computing device, the other data indicative of how an authorized user for that computing device uses the computing device, wherein the one or more metrics comprise one or more of: location data or information indicating interactions of the authorized user with an application on the computing device;

detecting unauthorized use of the computing device based on the number of instances of abnormal usage exceeding a threshold, wherein detecting the unauthorized use of the computing device comprises:

identifying, for each metric of the one or more metrics and based on the comparison of the received data with the other data, whether the received data for the corresponding metric indicates unauthorized use of the computing device;

computing, using negative weighted values for metrics indicating possible unauthorized use of the computing device, a first set of weighted metric scores;

computing, using positive weighted values for metrics indicating authorized use of the computing device, a second set of weighted metric scores;

computing, by adding the first set of weighted metric scores and the second set of weighted metric scores, a weighted security score, wherein a nonnegative weighted security score indicates authorized use of the computing device and a negative weighted security score indicates unauthorized use of the computing device; and

in response to determining that the weighted security score is a negative value, determining that the computing device is being used in an unauthorized manner; and

preventing access to a computing environment with use of the computing device in response to detection of unauthorized use.

12. The method of claim 11 , further comprising:

receiving the other data, wherein receiving the other data comprises receiving data corresponding to the one or more metrics.

13. The method of claim 12 , wherein the one or more metrics are selected based on a job title of the authorized user of the computing device.

14. The method of claim 12 , further comprising:

training, using the other data stored on the computing device, a machine learning model, wherein training the machine learning model configures the machine learning model to distinguish use of the computing device by the authorized user of the computing device from use of the computing device by an unauthorized user of the computing device.

15. The method of claim 14 , wherein training the machine learning model comprises:

computing, for the one or more metrics, weighted values indicating how relevant each of the one or more metrics is to identifying unauthorized access to the computing device.

16. The method of claim 15 , wherein computing the weighted values comprises:

computing, for a first metric of the one or more metrics and based on a first average deviation value of initial data corresponding to the first metric, a first weighted value; and

computing, for a second metric of the one or more metrics and based on a second average deviation value of initial data corresponding to the second metric, a second weighted value, and wherein:

the first average deviation value is lower than the second average deviation value, and

the first weighted value is larger than the second weighted value.

17. The method of claim 15 , further comprising:

comparing the weighted values to a predetermined metric selection threshold;

determining that a subset of the weighted values do not exceed the predetermined metric selection threshold; and

removing, from the machine learning model, initial data corresponding to metrics affiliated with the subset of the weighted values.

18. The method of claim 14 , wherein training the machine learning model comprises establishing, based on the other data and for the one or more metrics, one or more metric thresholds that separate other data corresponding to each of the one or more metrics into subgroups for the corresponding one or more metrics, and

wherein comparing the received data to the other data comprises:

filtering the received data based on the one or more metric thresholds; and

comparing the received data for each of the one or more metric thresholds with the other data for the corresponding metric thresholds of the one or more metric thresholds.

19. One or more non-transitory computer-readable media storing instructions that, when executed by a computing device comprising at least one processor, a communication interface, and memory, cause the computing device to:

receive data indicative of usage of the computing device by a user;

compare the received data with other data corresponding to one or more metrics stored on the computing device to identify instances of abnormal usage of the computing device, the other data indicative of how an authorized user for that computing device uses the computing device, wherein the one or more metrics comprise one or more of: location data or information indicating interactions of the authorized user with an application on the computing device;

detect unauthorized use of the computing device based on the number of instances of abnormal usage exceeding a threshold, wherein detecting the unauthorized use of the computing device comprises:

identifying, for each metric of the one or more metrics and based on the comparison of the received data with the other data, whether the received data for the corresponding metric indicates unauthorized use of the computing device;

computing, using negative weighted values for metrics indicating possible unauthorized use of the computing device, a first set of weighted metric scores;

computing, using positive weighted values for metrics indicating authorized use of the computing device, a second set of weighted metric scores;

computing, by adding the first set of weighted metric scores and the second set of weighted metric scores, a weighted security score, wherein a nonnegative weighted security score indicates authorized use of the computing device and a negative weighted security score indicates unauthorized use of the computing device; and

in response to determining that the weighted security score is a negative value, determining that the computing device is being used in an unauthorized manner; and

prevent access to a computing environment with use of the computing device in response to detection of unauthorized use.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2020
From: DALVI, KARAN JAYANT; FREEDMAN, JOSEPH L.; GRAVERAN, JOSE ANGEL LAGO
To: CITRIX SYSTEMS, INC.
Reel/Frame 053522/0558 →
Continuity (1)
Related Publication 20220060446A1 · Feb 24, 2022