IP Library Granted Patent US 11,902,293
Granted Patent B2
US 11,902,293 · App. 17/131,023 · Granted Feb 13, 2024

Using an entity behavior catalog when performing distributed security operations

Inventors: Lawrence Bruce Huston, III (Ann Arbor, MI); Nicolas Christian Fischbach (Uitikon, CH); Raffael Marty (Austin, TX)
Assignee: Forcepoint LLC
H04L63/04G06F21/566G06F21/577H04L63/102H04L63/1416H04L63/1425H04L63/1433H04L63/205H04L67/306G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,902,293
App. No.
17/131,023
Granted
Feb 13, 2024
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for performing a security operation. The security operation includes: monitoring an entity, the monitoring observing at least one electronically-observable data source; identifying a security related activity of the entity, the security related activity being of analytic utility; accessing an entity behavior catalog based upon the security related activity, the entity behavior catalog providing an inventory of entity behaviors; and performing a security operation via a distributed security analytics environment, the security operation using entity behavior catalog data stored within the entity behavior catalog based upon the security related activity.

Claims (58)

1. A computer-implementable method for performing a security operation, comprising:

monitoring an entity, the monitoring observing at least one electronically-observable data source;

identifying a security related activity of the entity, the security related activity being of analytic utility;

accessing an entity behavior catalog based upon the security related activity, the entity behavior catalog storing entity behavior catalog data, the entity behavior catalog data comprising an inventory of entity behaviors and a human-centric risk modeling framework, the human-centric risk modeling framework enabling quantification of a human-centric factor associated with the entity, the human-centric factor comprising a motivation factor, a stressor factor and an organizational dynamics stressor factor, the human-centric factor having an associated effect on the entity, the motivation factor representing a user entity behavior that provides an indication of a motivation for enacting the user entity behavior, the stressor factor representing an issue influencing the user entity behavior, the organizational stressor factor representing an event occurring within an organization affecting the user entity behavior; and

performing a security operation via a distributed security analytics environment, the security operation being performed by at least one of an entity edge component and a security analytics system, the entity edge component executing the security operation on a hardware processor associated with the entity edge component, the security analytics system executing the security operation on a hardware processor associated with the security analytics system, the security operation using the entity behavior catalog data stored within the entity behavior catalog based upon the security related activity.

2. The method of claim 1 , wherein:

the entity behaviors comprise at least one of a user entity behavior and a non-user entity behavior.

3. The method of claim 2 , wherein:

an entity behavior has an associated attribute, the associated attribute comprising at least one of a user entity attribute associated with the user entity behavior and a non-user entity attribute associated with the non-user entity behavior.

4. The method of claim 1 , wherein:

the distributed security analytics environment comprises the entity edge component, a network edge component and a back-end edge component;

the back-end edge component maintains the entity behavior catalog; and,

the entity edge component comprises an endpoint device entity behavior catalog data repository and the network edge component comprises an edge device entity behavior catalog data repository.

5. The method of claim 1 , wherein:

the security operation uses the entity behavior catalog to determine whether an event is of analytic utility.

6. The method of claim 5 , wherein:

the security analytics system comprises an analytic detection module, the analytic detection module determining whether the event is of analytic utility.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring an entity, the monitoring observing at least one electronically-observable data source;

identifying a security related activity of the entity, the security related activity being of analytic utility;

accessing an entity behavior catalog based upon the security related activity, the entity behavior catalog storing entity behavior catalog data, the entity behavior catalog data comprising an inventory of entity behaviors and a human-centric risk modeling framework, the human-centric risk modeling framework enabling quantification of a human-centric factor associated with the entity, the human-centric factor comprising a motivation factor, a stressor factor and an organizational dynamics stressor factor, the human-centric factor having an associated effect on the entity, the motivation factor representing a user entity behavior that provides an indication of a motivation for enacting the user entity behavior, the stressor factor representing an issue influencing the user entity behavior, the organizational stressor factor representing an event occurring within an organization affecting the user entity behavior; and

performing a security operation via a distributed security analytics environment, the security operation being performed by at least one of an entity edge component and a security analytics system, the entity edge component executing the security operation on a hardware processor associated with the entity edge component, the security analytics system executing the security operation on a hardware processor associated with the security analytics system, the security operation using the entity behavior catalog data stored within the entity behavior catalog based upon the security related activity.

8. The system of claim 7 , wherein:

the entity behaviors comprise at least one of a user entity behavior and a non-user entity behavior.

9. The system of claim 8 , wherein:

an entity behavior has an associated attribute, the associated attribute comprising at least one of a user entity attribute associated with the user entity behavior and a non-user entity attribute associated with the non-user entity behavior.

10. The system of claim 7 , wherein:

the distributed security analytics environment comprises the entity edge component, a network edge component and a back-end edge component;

the back-end edge component maintains the entity behavior catalog; and,

the entity edge component comprises an endpoint device entity behavior catalog data repository and the network edge component comprises an edge device entity behavior catalog data repository.

11. The system of claim 7 , wherein:

the security operation uses the entity behavior catalog to determine whether an event is of analytic utility.

12. The system of claim 11 , wherein:

the security analytics system comprises an analytic detection module, the analytic detection module determining whether the event is of analytic utility.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring an entity, the monitoring observing at least one electronically-observable data source;

identifying a security related activity of the entity, the security related activity being of analytic utility;

accessing an entity behavior catalog based upon the security related activity, the entity behavior catalog storing entity behavior catalog data, the entity behavior catalog data comprising an inventory of entity behaviors and a human-centric risk modeling framework, the human-centric risk modeling framework enabling quantification of a human-centric factor associated with the entity, the human-centric factor comprising a motivation factor, a stressor factor and an organizational dynamics stressor factor, the human-centric factor having an associated effect on the entity, the motivation factor representing a user entity behavior that provides an indication of a motivation for enacting the user entity behavior, the stressor factor representing an issue influencing the user entity behavior, the organizational stressor factor representing an event occurring within an organization affecting the user entity behavior; and

performing a security operation via a distributed security analytics environment, the security operation being performed by at least one of an entity edge component and a security analytics system, the entity edge component executing the security operation on a hardware processor associated with the entity edge component, the security analytics system executing the security operation on a hardware processor associated with the security analytics system, the security operation using the entity behavior catalog data stored within the entity behavior catalog based upon the security related activity.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the entity behaviors comprise at least one of a user entity behavior and a non-user entity behavior.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein:

an entity behavior has an associated attribute, the associated attribute comprising at least one of a user entity attribute associated with the user entity behavior and a non-user entity attribute associated with the non-user entity behavior.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the distributed security analytics environment comprises the entity edge component, a network edge component and a back-end edge component;

the back-end edge component maintains the entity behavior catalog; and,

the entity edge component comprises an endpoint device entity behavior catalog data repository and the network edge component comprises an edge device entity behavior catalog data repository.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the security operation uses the entity behavior catalog to determine whether an event is of analytic utility.

18. The non-transitory, computer-readable storage medium of claim 17 , wherein:

the security analytics system comprises an analytic detection module, the analytic detection module determining whether the event is of analytic utility.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF ASSIGNEE PREVIOUSLY RECORDED AT REEL: 066073 FRAME: 0824. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 11, 2024
From: HUSTON, LAWRENCE BRUCE, III; FISCHBACH, NICOLAS CHRISTIAN; MARTY, RAFFAEL
To: FORCEPOINT LLC
Reel/Frame 066270/0694 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2023
From: HUSTON, LAWRENCE BRUCE, III; FISCHBACH, NICOLAS CHRISTIAN; MARTY, RAFFAEL
To: LLC, FORCEPOINT
Reel/Frame 066073/0824 →
PATENT SECURITY AGREEMENT Recorded Aug 31, 2021
From: FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS THE COLLATERAL AGENT
Reel/Frame 057651/0150 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 056294/0618 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0204 →
Continuity (12)
Continuation 16557560 · Aug 30, 2019
Continuation In Part 16415726 · May 17, 2019
Continuation In Part 16162655 · Oct 17, 2018
Continuation 15963729 · Apr 26, 2018
Continuation In Part 15878898 · Jan 24, 2018
Continuation 15720788 · Sep 29, 2017
Provisional Application 63119116 · Nov 30, 2020
Provisional Application 63017400 · Apr 29, 2020
Provisional Application 62964372 · Jan 22, 2020
Provisional Application 62839060 · Apr 26, 2019
Provisional Application 62506300 · May 15, 2017
Related Publication 20210152567A1 · May 20, 2021