IP Library Granted Patent US 11,575,685
Granted Patent B2
US 11,575,685 · App. 17/106,674 · Granted Feb 7, 2023

User behavior profile including temporal detail corresponding to user interaction

Inventors: Richard Anthony Ford (Austin, TX); Brandon L. Swafford (Stamford, CT)
Assignee: Forcepoint LLC
H04L63/14H04L9/3236H04L63/1433H04L67/306H04L9/50H04L2209/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,575,685
App. No.
17/106,674
Granted
Feb 7, 2023
Kind
B2
Abstract

A system, method, and computer-usable medium are disclosed for generating a cyber behavior profile comprising monitoring user interactions between a user and an information handling system; converting the user interactions into electronic information representing the user interactions, the electronic information representing the user interactions comprising temporal detail corresponding to the user interaction; and generating a user behavior profile based upon the electronic information representing the user interactions, the generating the user profile including a layer of detail corresponding to the temporal detail corresponding to the user interaction.

Claims (52)

1. A computer-implementable method for generating a cyber behavior profile, comprising:

monitoring electronically-observable user behavior;

converting the electronically-observable user behavior into electronic information representing the electronically-observable user behavior, the electronic information representing the user behavior comprising temporal detail corresponding to the user interaction, the temporal detail corresponding to a plurality of temporal user behavior factors associated with the user interaction, at least one temporal user behavior factor being implemented as an ontological time user behavior factor, the ontological time user behavior factor referring to how one instant in time relates to another instant in time in a chronological sense, at least one temporal user behavior factor being implemented as a societal time user behavior factor, the societal time user behavior factor referring to how a user interaction at a particular instant in time correlates to another user interaction at another particular instant in time;

generating a user behavior profile based upon the electronic information representing the electronically-observable user behavior, the generating the user behavior profile including information relating to the temporal detail corresponding to the user interaction, the user behavior profile comprising a date/time/frequency user behavior element, the date/time/frequency user behavior element comprising information regarding at least one of the ontological time user behavior factor and the societal time user behavior factor; and,

using the user behavior profile with the date/time/frequency user behavior element to perform a detection operation via a user behavior monitoring system.

2. The method of claim 1 , further comprising:

notifying a security administrator of a result of the detection operation.

3. The method of claim 1 , wherein:

the detection operation determines whether a particular user behavior is at least one of acceptable, unacceptable, anomalous and malicious.

4. The method of claim 1 , wherein:

the plurality of temporal user behavior factors comprise a date/time/frequency user behavior factor.

5. The method of claim 1 , wherein:

a temporal user behavior factor of the plurality of user behavior factors comprises information regarding access of a particular file.

6. The method of claim 1 , wherein:

the user behavior monitoring system decays a risk associated with a user according to an amount of ontological time that has lapsed since a last observed policy violation.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring electronically-observable user behavior;

converting the electronically-observable user behavior into electronic information representing the electronically-observable user behavior, the electronic information representing the user behavior comprising temporal detail corresponding to the user interaction, the temporal detail corresponding to a plurality of temporal user behavior factors associated with the user interaction, at least one temporal user behavior factor being implemented as an ontological time user behavior factor, the ontological time user behavior factor referring to how one instant in time relates to another instant in time in a chronological sense, at least one temporal user behavior factor being implemented as a societal time user behavior factor, the societal time user behavior factor referring to how a user interaction at a particular instant in time correlates to another user interaction at another particular instant in time;

generating a user behavior profile based upon the electronic information representing the electronically-observable user behavior, the generating the user behavior profile including information relating to the temporal detail corresponding to the user interaction, the user behavior profile comprising a date/time/frequency user behavior element, the date/time/frequency user behavior element comprising information regarding at least one of the ontological time user behavior factor and the societal time user behavior factor; and,

using the user behavior profile with the date/time/frequency user behavior element to perform a detection operation via a user behavior monitoring system.

8. The system of claim 7 , wherein the instructions executable by the processor are further configured for:

notifying a security administrator of a result of the detection operation.

9. The system of claim 7 , wherein:

the detection operation determines whether a particular user behavior is at least one of acceptable, unacceptable, anomalous and malicious.

10. The system of claim 7 , wherein:

the plurality of temporal user behavior factors comprise a date/time/frequency user behavior factor.

11. The system of claim 7 , wherein:

a temporal user behavior factor of the plurality of user behavior factors comprises information regarding access of a particular file.

12. The system of claim 7 , wherein:

the user behavior monitoring system decays a risk associated with a user according to an amount of ontological time that has lapsed since a last observed policy violation.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring electronically-observable user behavior;

converting the electronically-observable user behavior into electronic information representing the electronically-observable user behavior, the electronic information representing the user behavior comprising temporal detail corresponding to the user interaction, the temporal detail corresponding to a plurality of temporal user behavior factors associated with the user interaction, at least one temporal user behavior factor being implemented as an ontological time user behavior factor, the ontological time user behavior factor referring to how one instant in time relates to another instant in time in a chronological sense, at least one temporal user behavior factor being implemented as a societal time user behavior factor, the societal time user behavior factor referring to how a user interaction at a particular instant in time correlates to another user interaction at another particular instant in time;

generating a user behavior profile based upon the electronic information representing the electronically-observable user behavior, the generating the user behavior profile including information relating to the temporal detail corresponding to the user interaction, the user behavior profile comprising a date/time/frequency user behavior element, the date/time/frequency user behavior element comprising information regarding at least one of the ontological time user behavior factor and the societal time user behavior factor; and,

using the user behavior profile with the date/time/frequency user behavior element to perform a detection operation via a user behavior monitoring system.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

notifying a security administrator of a result of the detection operation.

15. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the detection operation determines whether a particular user behavior is at least one of acceptable, unacceptable, anomalous and malicious.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the plurality of temporal user behavior factors comprise a date/time/frequency user behavior factor.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

a temporal user behavior factor of the plurality of user behavior factors comprises information regarding access of a particular file.

18. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the user behavior monitoring system decays a risk associated with a user according to an amount of ontological time that has lapsed since a last observed policy violation.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
Continuity (5)
Continuation 16434579 · Jun 7, 2019
Continuation 15978905 · May 14, 2018
Continuation 15867960 · Jan 11, 2018
Provisional Application 62506300 · May 15, 2017
Related Publication 20210367953A1 · Nov 25, 2021
Cited By (1)
US 12,437,042