IP Library Granted Patent US 11,888,863
Granted Patent B2
US 11,888,863 · App. 17/131,015 · Granted Jan 30, 2024

Maintaining user privacy via a distributed framework for security analytics

Inventors: Lawrence Bruce Huston, III (Ann Arbor, MI); David Coffey (Austin, TX)
Assignee: Forcepoint LLC
H04L63/04G06F21/566G06F21/577H04L63/102H04L63/1416H04L63/1425H04L63/1433H04L63/205H04L67/306G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,888,863
App. No.
17/131,015
Granted
Jan 30, 2024
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for performing a security operation. The security operation includes: monitoring a plurality of actions of an entity, the plurality of actions of the entity corresponding to a plurality of events enacted by the entity; maintaining information relating to the monitoring within a user edge component; identifying an event of analytic utility; analyzing the event of analytic utility at the user edge component, the analyzing generating a security risk assessment; and, providing the security risk assessment to a network edge component.

Claims (55)

1. A computer-implementable method for performing a security operation, comprising:

monitoring a plurality of actions of an entity, the plurality of actions of the entity corresponding to a plurality of events enacted by the entity;

maintaining information relating to the monitoring within a user edge component;

identifying an event of analytic utility;

analyzing the event of analytic utility at the user edge component, the analyzing generating a security risk assessment, the analyzing being performed by a hardware processor of the user edge component;

providing the security risk assessment to a network edge component;

anonymizing the information relating to the monitoring to provide anonymized information; and,

providing the anonymized information to the network edge component; and wherein

the network edge component performs a security operation using the anonymized information relating to the monitoring; and,

the network edge component requests de-anonymized information from the user edge component when the security operation generates an indication of a security risk of the entity.

2. The method of claim 1 , wherein:

the anonymized information is provided to the network edge component when the security risk indication exceeds a predetermined threshold.

3. The method of claim 1 , wherein:

the security operation comprises a meaning derivation operation, the meaning derivation operation deriving a meaning relating to the event of analytic utility.

4. The method of claim 1 , wherein:

the user edge component comprises a protected endpoint, the protected endpoint comprising an endpoint device and an endpoint agent, the endpoint agent comprising a security policy system and a distributed data management system.

5. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring a plurality of actions of an entity, the plurality of actions of the entity corresponding to a plurality of events enacted by the entity;

maintaining information relating to the monitoring within a user edge component;

identifying an event of analytic utility;

analyzing the event of analytic utility at the user edge component, the analyzing generating a security risk assessment, the analyzing being performed by a hardware processor of the user edge component;

providing the security risk assessment to a network edge component;

anonymizing the information relating to the monitoring to provide anonymized information; and,

providing the anonymized information to the network edge component; and wherein

the network edge component performs a security operation using the anonymized information relating to the monitoring; and,

the network edge component requests de-anonymized information from the user edge component when the security operation generates an indication of a security risk of the entity.

6. The system of claim 5 , wherein

the anonymized information is provided to the network edge component when the security risk indication exceeds a predetermined threshold.

7. The system of claim 5 , wherein:

the security operation comprises a meaning derivation operation, the meaning derivation operation deriving a meaning relating to the event of analytic utility.

8. The system of claim 5 , wherein:

the user edge component comprises a protected endpoint, the protected endpoint comprising an endpoint device and an endpoint agent, the endpoint agent comprising a security policy system and a distributed data management system.

9. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring a plurality of actions of an entity, the plurality of actions of the entity corresponding to a plurality of events enacted by the entity;

maintaining information relating to the monitoring within a user edge component;

identifying an event of analytic utility;

analyzing the event of analytic utility at the user edge component, the analyzing generating a security risk assessment, the analyzing being performed by a hardware processor of the user edge component;

providing the security risk assessment to a network edge component;

anonymizing the information relating to the monitoring to provide anonymized information; and

providing the anonymized information to the network edge component; and wherein

the network edge component performs a security operation using the anonymized information relating to the monitoring; and,

the network edge component requests de-anonymized information from the user edge component when the security operation generates an indication of a security risk of the entity.

10. The non-transitory, computer-readable storage medium of claim 9 , wherein

the anonymized information is provided to the network edge component when the security risk indication exceeds a predetermined threshold.

11. The non-transitory, computer-readable storage medium of claim 9 , wherein:

the security operation comprises a meaning derivation operation, the meaning derivation operation deriving a meaning relating to the event of analytic utility.

12. The non-transitory, computer-readable storage medium of claim 9 , wherein:

the user edge component comprises a protected endpoint, the protected endpoint comprising an endpoint device and an endpoint agent, the endpoint agent comprising a security policy system and a distributed data management system.

13. The non-transitory, computer-readable storage medium of claim 9 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

14. The non-transitory, computer-readable storage medium of claim 9 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 3, 2022
From: HUSTON, LAWRENCE BRUCE, III
To: FORCEPOINT, LLC
Reel/Frame 060092/0905 →
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
Continuity (12)
Continuation 16557560 · Aug 30, 2019
Continuation In Part 16415726 · May 17, 2019
Continuation In Part 16162655 · Oct 17, 2018
Continuation 15963729 · Apr 26, 2018
Continuation In Part 15878898 · Jan 24, 2018
Continuation 15720788 · Sep 29, 2017
Provisional Application 63119116 · Nov 30, 2020
Provisional Application 63017400 · Apr 29, 2020
Provisional Application 62964372 · Jan 22, 2020
Provisional Application 62839060 · Apr 26, 2019
Provisional Application 62506300 · May 15, 2017
Related Publication 20210112077A1 · Apr 15, 2021
Cited By (2)
US 12,192,192 US 12,619,781