IP Library Granted Patent US 11,463,453
Granted Patent B2
US 11,463,453 · App. 17/089,776 · Granted Oct 4, 2022

Using a story when generating inferences using an adaptive trust profile

Inventor: Richard A. Ford (Austin, TX)
Assignee: Forcepoint, LLC
H04L63/14G06F21/554G06F21/57G06F21/604G06F21/6218G06N5/04H04L9/3239H04L63/102H04L63/1408H04L63/1425H04L63/205H04L67/306H04L67/535G06F2221/2101G06F2221/2141H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,463,453
App. No.
17/089,776
Granted
Oct 4, 2022
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for monitoring actions of an entity. In various embodiments the monitoring includes: monitoring a plurality of electronically-observable actions of the entity, the plurality of electronically-observable actions of the entity corresponding to a plurality of events enacted by the entity; associating the plurality of events enacted by the entity with a story; and, using the story to derive an inference regarding the entity.

Claims (71)

1. A computer-implementable method for monitoring actions of an entity, comprising:

monitoring a plurality of electronically-observable actions of the entity, the plurality of electronically-observable actions of the entity corresponding to a plurality of events enacted by the entity;

defining a story, the story being used to describe expected behaviors of the entity;

associating a set of events from the plurality of events enacted by the entity with the story, the associating being based upon the set of events from the plurality of events;

performing a meaning derivation operation using the story, the meaning derivation operation including implying an intent of the entity from an action of the entity;

using the story and the intent of the entity to derive an inference regarding the entity;

performing a security analytics operation via a security analytics system, the security analytics system executing on a hardware processor of an information handling system, the security analytics operation using the inference regarding the entity to determine whether a particular event is of analytic utility, the particular event being of analytic utility indicating the action of the entity represents a security risk; and,

mitigating the security risk via the security analytics system based upon the inference when the particular event is of analytic utility.

2. The method of claim 1 , further comprising:

monitoring a plurality of electronically-observable actions of another entity, the plurality of electronically-observable actions of the another entity corresponding to a plurality of events enacted by the another entity; and,

associating the plurality of events enacted by the another entity with the story.

3. The method of claim 2 , wherein:

at least one of the plurality of events enacted by the entity and the events enacted by the another entity represent an interaction between the entity and the another entity; and,

the story is used to derive an inference regarding the interaction between the entity and the another entity.

4. The method of claim 1 , wherein:

the plurality of events enacted by the entity comprise the set of events enacted by the entity; and,

the set of events enacted by the entity comprise events of analytic utility.

5. The method of claim 1 , wherein:

the associating the plurality of events enacted by the entity with the story comprises generating the story based upon the plurality of events enacted by the entity.

6. The method of claim 1 , wherein:

the associating the plurality of events enacted by the entity with the story comprises selecting the story from a set of predefined stories based upon the plurality of events enacted by the entity.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code for monitoring actions of an entity, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring a plurality of electronically-observable actions of the entity, the plurality of electronically-observable actions of the entity corresponding to a plurality of events enacted by the entity;

defining a story, the story being used to describe expected behaviors of the entity;

associating a set of events from the plurality of events enacted by the entity with the story, the associating being based upon the set of events from the plurality of events;

performing a meaning derivation operation using the story, the meaning derivation operation including implying an intent of the entity from an action of the entity;

using the story and the intent of the entity to derive an inference regarding the entity;

performing a security analytics operation via a security analytics system, the security analytics system executing on a hardware processor of an information handling system, the security analytics operation using the inference regarding the entity to determine whether a particular event is of analytic utility, the particular event being of analytic utility indicating the action of the entity represents a security risk; and,

mitigating the security risk via the security analytics system based upon the inference when the particular event is of analytic utility.

8. The system of claim 7 , wherein the instructions executable by the processor are further configured for:

monitoring a plurality of electronically-observable actions of another entity, the plurality of electronically-observable actions of the another entity corresponding to a plurality of events enacted by the another entity; and,

associating the plurality of events enacted by the another entity with the story.

9. The system of claim 8 , wherein:

at least one of the plurality of events enacted by the entity and the events enacted by the another entity represent an interaction between the entity and the another entity; and,

the story is used to derive an inference regarding the interaction between the entity and the another entity.

10. The system of claim 7 , wherein:

the plurality of events enacted by the entity comprise the set of events enacted by the entity; and,

the set of events enacted by the entity comprise events of analytic utility.

11. The system of claim 7 , wherein:

the associating the plurality of events enacted by the entity with the story comprises generating the story based upon the plurality of events enacted by the entity.

12. The system of claim 7 , wherein:

the associating the plurality of events enacted by the entity with the story comprises selecting the story from a set of predefined stories based upon the plurality of events enacted by the entity.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring a plurality of electronically-observable actions of the entity, the plurality of electronically-observable actions of the entity corresponding to a plurality of events enacted by the entity;

defining a story, the story being used to describe expected behaviors of the entity;

associating a set of events from the plurality of events enacted by the entity with the story, the associating being based upon the set of events from the plurality of events;

performing a meaning derivation operation using the story, the meaning derivation operation including implying an intent of the entity from an action of the entity;

using the story and the intent of the entity to derive an inference regarding the entity;

performing a security analytics operation via a security analytics system, the security analytics system executing on a hardware processor of an information handling system, the security analytics operation using the inference regarding the entity to determine whether a particular event is of analytic utility, the particular event being of analytic utility indicating the action of the entity represents a security risk; and,

mitigating the security risk via the security analytics system based upon the inference when the particular event is of analytic utility.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

monitoring a plurality of electronically-observable actions of another entity, the plurality of electronically-observable actions of the another entity corresponding to a plurality of events enacted by the another entity; and,

associating the plurality of events enacted by the another entity with the story.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein:

at least one of the plurality of events enacted by the entity and the events enacted by the another entity represent an interaction between the entity and the another entity;

and,

the story is used to derive an inference regarding the interaction between the entity and the another entity.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the plurality of events enacted by the entity comprise the set of events enacted by the entity; and,

the set of events enacted by the entity comprise events of analytic utility.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the associating the plurality of events enacted by the entity with the story comprises generating the story based upon the plurality of events enacted by the entity.

18. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the associating the plurality of events enacted by the entity with the story comprises selecting the story from a set of predefined stories based upon the plurality of events enacted by the entity.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2020
From: FORD, RICHARD A.
To: FORCEPOINT, LLC
Reel/Frame 054280/0345 →