IP Library Granted Patent US 12,652,290
Granted Patent B2
US 12,652,290 · App. 17/187,169 · Granted Jun 9, 2026

Cyber security for software-as-a-service factoring risk

Inventors: John Anthony Boyer (Cambridge, GB); Clément Wen-Ho André Robin (Cambridgeshire, GB); Holly Louisa Birch (Cambridgeshire, GB)
Assignee: Darktrace Holdings Limited
H04L63/1416H04L63/1425H04L63/1433H04L63/1441G06N3/08G06N20/00H04L63/145
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,652,290
App. No.
17/187,169
Filed
Feb 26, 2021
Granted
Jun 9, 2026
Kind
B2
Art Unit
2439
USPC
726/23
Abstract

A cyber threat defense system can incorporate data from multiple Software-as-a-Service (SaaS) applications hosted by multiple third-party platforms to identify cyber threats across platforms. The system can collect third-party event data describing an administrative event of a SaaS application hosted by an associated third-party platform. The system can identify a user associated with the third-party event data based on a composite user profile constructed from user context data collected across the multiple SaaS applications to identify the user across multiple third-party platforms. The system can associate the user with a user risk profile based on the composite user profile. The system can identify whether the third-party event data corresponds to a cyber threat partially based on the user risk profile. The system can execute an autonomous response in response to the cyber threat using an autonomous response module factoring in the user risk profile.

Claims (45)

1 . A method for a cyber threat defense system incorporating data across multiple Software-as-a-Service (SaaS) applications hosted by multiple third-party platforms to identify a cyber threat related to that SaaS application, comprising:

collecting at one or more SaaS modules, from one or more network devices that utilizes one or more SaaS applications, third-party event data describing an administrative event of a SaaS application hosted by an associated third-party platform;

identifying a user associated with the third-party event data based on a composite user profile constructed from user context data collected across the multiple SaaS applications to identify the user across multiple third-party platforms;

associating the user with a user risk profile based on the composite user profile;

identifying whether the third-party event data corresponds to a cyber threat partially based on the user risk profile;

using a user specific profile module to construct the composite user profile describing the user based on the user context data collected from multiple SaaS applications to associate with third-party event data from the one or more SaaS modules, wherein the user specific profile module applies a fuzzy classifier to the user context data from a context gatherer to match with separate user context data by generating an adjustable confidence score for a match between the user context data and the separate user context data and adjusting the confidence score based on the third-party event data from the one or more SaaS modules;

using a cyber threat module that references one or more machine learning models that are trained on a normal behavior of associated with the user and at least their SaaS activity, where the cyber threat module determines a threat risk parameter that factors in ‘what is a likelihood of a chain of two or more unusual behaviors of i) SaaS activity, ii) network activity, iii) user activity and iv) any combinations of these three, under analysis, that fall outside of being the normal behavior associated with the user;’ and thus, are likely malicious behavior indicative of the cyber threat; and

executing an autonomous response in response to the cyber threat using an autonomous response module factoring in the user risk profile.

2 . The method for the cyber threat defense system of claim 1 , further comprising:

assigning a user importance score to the user risk profile of the user based on the composite user profile to indicate a potential sphere of influence of the user.

3 . The method for the cyber threat defense system of claim 2 , further comprising:

assessing the potential sphere of influence of the user based on at least one of administrative permissions, lateral movement, action persistence, and file access.

4 . The method for the cyber threat defense system of claim 2 , further comprising:

generating a vulnerability score based on the third-party event data.

5 . The method for the cyber threat defense system of claim 4 , further comprising:

factoring the user importance score and the vulnerability score into the user risk profile to calculate a degree of damage.

6 . The method for the cyber threat defense system of claim 1 , further comprising:

adjusting a normal behavior benchmark based on the user risk profile.

7 . The method for the cyber threat defense system of claim 1 , further comprising:

registering creation of a virtual device by the user on the third-party platform with a virtual device sensor.

8 . The method for the cyber threat defense system of claim 1 , further comprising:

representing in a graphical user interface the third-party event data with a user interface module.

9 . The method for the cyber threat defense system of claim 1 , further comprising:

collecting user context data from multiple third-party platforms executing one or more of the SaaS applications to identify the user.

10 . A non-transitory computer readable medium comprising computer readable code operable, when executed by one or more processing apparatuses in the cyber threat defense system to instruct a computing device to perform the method of claim 1 .

11 . An apparatus for a cyber threat defense system, comprising:

a coordinator module configured to contextualize third-party event data from one or more software-as-a-service (SaaS) modules with probe data from one or more probe modules to create a combined data set for analysis;

a context gatherer for one or more SaaS modules configured to collect user context data from multiple third-party platforms executing SaaS applications to identify a user, which is used in creating a composite user profile;

a risk profile module configured to associate the user with a user risk profile based on the composite user profile;

a user specific profile module configured to construct the composite user profile describing the user based on the user context data collected from multiple SaaS applications to associate with third-party event data from the one or more SaaS modules, wherein the user specific profile module is configured to apply a fuzzy classifier to the user context data from the context gatherer to match with separate user context data by generating an adjustable confidence score for a match between the user context data and the separate user context data and adjust the confidence score based on the third-party event data from the one or more SaaS modules;

a cyber threat module that is configured to reference one or more machine learning models that are trained on a normal behavior of associated with the user and at least their SaaS activity, where the cyber threat module determines a threat risk parameter that factors in ‘what is a likelihood of a chain of two or more unusual behaviors of i) SaaS activity, ii) network activity, iii) user activity and iv) any combinations of these three, under analysis that fall outside of being the normal behavior;’ and thus, are likely malicious behavior indicative of a cyber threat; and

an autonomous response module configured to execute at least one autonomous response to the cyber threat identified by the cyber threat module, wherein a first autonomous response factors in the user risk profile from the risk profile module.

12 . The apparatus for the cyber threat defense system of claim 11 , further comprising:

one or more ports to connect to one or more probes monitoring multiple network devices that utilize third-party SaaS applications each hosted by a third-party platform,

wherein the one or more SaaS modules are configured to connect to one or more SaaS connectors, with each SaaS module configured to collect third-party event data describing an administrative event in a given third-party SaaS application, and

wherein the context gatherer is configured to at least one of actively request and passively receive the user context data from a first third-party platform via an application programming interface;

one or more probe modules configured to collect, from the one or more probes, probe data describing network-administrated activity, external to the given third-party SaaS application, executed by the user.

13 . The apparatus for the cyber threat defense system of claim 11 , further comprising:

where the cyber threat module is further configured to identify whether a breach state corresponds to the cyber threat based on the user risk profile.

14 . The apparatus for the cyber threat defense system of claim 13 , wherein the user specific profile module is configured to match the user context data from the context gatherer with separate internal user context data from other context gatherers at internal service modules associated with other applications.

15 . The apparatus for the cyber threat defense system of claim 13 , wherein the user specific profile module is configured to match the user context data from the context gatherer with separate external user context data from a second context gatherer for a second SaaS module associated with a second SaaS application.

16 . The apparatus for the cyber threat defense system of claim 13 , wherein the user specific profile module is configured to generate a confidence score for a match between the user context data from the context gatherer with separate user context data from another context gatherer for an application module associated with another application.

17 . The apparatus for the cyber threat defense system of claim 16 , wherein the user specific profile module is configured to adjust the confidence score based on the third-party event data from one or more individual SaaS modules.

18 . The apparatus for the cyber threat defense system of claim 11 , wherein the user context data includes at least one of a user name, a display name, a full name, a language setting, work group, a job title, a role, license information, an authorized application, a registered device, a permissions level, a file access list, a click profile describing tendency to click on suspicious links, and a platform user risk assessment performed on the user by a third-party platform operator.

19 . The apparatus for the cyber threat defense system of claim 11 , wherein a first SaaS module is configured to monitor a user instruction to a resource controlled by a SaaS application and the user specific profile module is configured to confirm a user identity based on a comparison of the third-party event data to the user instruction.

Assignments (3)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2021
From: BOYER, JOHN ANTHONY; ROBIN, CLEMENT WEN-HO ANDRE; BIRCH, HOLLY LOUISA
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 058009/0620 →
Continuity (3)
Provisional Application 63078092 · Sep 14, 2020
Provisional Application 62983307 · Feb 28, 2020
Related Publication 20210273957A1 · Sep 2, 2021
References Cited (135)
US 6154844A · Touboul et al. · 2000 [cited by applicant]
US 6965968B1 · Touboul · 2005 [cited by applicant]
US 7307999B1 · Donaghey · 2007 [cited by applicant]
US 7418731B2 · Touboul · 2008 [cited by applicant]
US 7448084B1 · Apap et al. · 2008 [cited by applicant]
US 7890869B1 · Mayer et al. · 2011 [cited by applicant]
US 8312540B1 · Kahn et al. · 2012 [cited by applicant]
US 8661538B2 · Cohen-Ganor et al. · 2014 [cited by applicant]
US 8819803B1 · Richards et al. · 2014 [cited by applicant]
US 8879803B2 · Ukil et al. · 2014 [cited by applicant]
US 8966036B1 · Asgekar et al. · 2015 [cited by applicant]
US 9043905B1 · Allen et al. · 2015 [cited by applicant]
US 9106687B1 · Sawhney et al. · 2015 [cited by applicant]
US 9185095B1 · Moritz et al. · 2015 [cited by applicant]
US 9213990B2 · Adjaoute · 2015 [cited by applicant]
US 9348742B1 · Brezinski · 2016 [cited by applicant]
US 9401925B1 · Guo et al. · 2016 [cited by applicant]
US 9516039B1 · Yen et al. · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9641544B1 · Treat et al. · 2017 [cited by applicant]
US 9712548B2 · Shmuell et al. · 2017 [cited by applicant]
US 9727723B1 · Kondaveeti et al. · 2017 [cited by applicant]
US 10237298B1 · Nguyen et al. · 2019 [cited by applicant]
US 10268821B2 · Stockdale · 2019 [cited by applicant]
US 10419466B2 · Ferguson · 2019 [cited by applicant]
US 10516693B2 · Stockdale et al. · 2019 [cited by applicant]
US 10701093B2 · Dean · 2020 [cited by applicant]
US 20020174217A1 · Anderson et al. · 2002 [cited by applicant]
US 20020186698A1 · Ceniza · 2002 [cited by applicant]
US 20030070003A1 · Chong et al. · 2003 [cited by applicant]
US 20040083129A1 · Herz · 2004 [cited by applicant]
US 20040167893A1 · Matsunaga et al. · 2004 [cited by applicant]
US 20050065754A1 · Schaf et al. · 2005 [cited by applicant]
US 20070118909A1 · Hertzog et al. · 2007 [cited by applicant]
US 20070294187A1 · Scherrer · 2007 [cited by applicant]
US 20080005137A1 · Surendran et al. · 2008 [cited by applicant]
US 20080077358A1 · Marvasti · 2008 [cited by applicant]
US 20080109730A1 · Coffman et al. · 2008 [cited by applicant]
US 20090106174A1 · Battisha et al. · 2009 [cited by applicant]
US 20090132395A1 · Lam · 2009 [cited by examiner]
US 20090254971A1 · Herz et al. · 2009 [cited by applicant]
US 20100009357A1 · Nevins et al. · 2010 [cited by applicant]
US 20100095374A1 · Gillum et al. · 2010 [cited by applicant]
US 20100107254A1 · Elland et al. · 2010 [cited by applicant]
US 20100125908A1 · Kudo · 2010 [cited by applicant]
US 20100235908A1 · Eynon et al. · 2010 [cited by applicant]
US 20100299292A1 · Collazo · 2010 [cited by applicant]
US 20110093428A1 · Wisse · 2011 [cited by applicant]
US 20110213742A1 · Lemmond et al. · 2011 [cited by applicant]
US 20110261710A1 · Chen et al. · 2011 [cited by applicant]
US 20120096549A1 · Amini et al. · 2012 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120209575A1 · Barbat et al. · 2012 [cited by applicant]
US 20120210388A1 · Kolishchak · 2012 [cited by applicant]
US 20120284791A1 · Miller et al. · 2012 [cited by applicant]
US 20120304288A1 · Wright et al. · 2012 [cited by applicant]
US 20130091539A1 · Khurana et al. · 2013 [cited by applicant]
US 20130198119A1 · Eberhardt, III et al. · 2013 [cited by applicant]
US 20130198840A1 · Drissi et al. · 2013 [cited by applicant]
US 20130254885A1 · Devost · 2013 [cited by applicant]
US 20140007237A1 · Wright et al. · 2014 [cited by applicant]
US 20140074762A1 · Campbell · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140215618A1 · Amit · 2014 [cited by applicant]
US 20140325643A1 · Bart et al. · 2014 [cited by applicant]
US 20150067835A1 · Chari et al. · 2015 [cited by applicant]
US 20150081431A1 · Akahoshi et al. · 2015 [cited by applicant]
US 20150161394A1 · Ferragut et al. · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150180893A1 · Im et al. · 2015 [cited by applicant]
US 20150213358A1 · Shelton et al. · 2015 [cited by applicant]
US 20150281287A1 · Gill et al. · 2015 [cited by applicant]
US 20150286819A1 · Coden et al. · 2015 [cited by applicant]
US 20150310195A1 · Bailor et al. · 2015 [cited by applicant]
US 20150319185A1 · Kirti et al. · 2015 [cited by applicant]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150363699A1 · Nikovski · 2015 [cited by applicant]
US 20150379110A1 · Marvasti et al. · 2015 [cited by applicant]
US 20160062950A1 · Brodersen et al. · 2016 [cited by applicant]
US 20160078365A1 · Baumard · 2016 [cited by applicant]
US 20160149941A1 · Thakur et al. · 2016 [cited by applicant]
US 20160164902A1 · Moore · 2016 [cited by applicant]
US 20160173509A1 · Ray et al. · 2016 [cited by applicant]
US 20160241576A1 · Rathod et al. · 2016 [cited by applicant]
US 20160352768A1 · Lefebvre et al. · 2016 [cited by applicant]
US 20160359695A1 · Yadav et al. · 2016 [cited by applicant]
US 20160373476A1 · Dell'Anno et al. · 2016 [cited by applicant]
US 20160373477A1 · Moyle et al. · 2016 [cited by applicant]
US 20170054745A1 · Zhang et al. · 2017 [cited by applicant]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170118239A1 · Most · 2017 [cited by examiner]
US 20170169360A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170270422A1 · Sorakado · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180167402A1 · Scheidler et al. · 2018 [cited by applicant]
US 20180375886A1 · Kirti et al. · 2018 [cited by applicant]
US 20190036948A1 · Appel et al. · 2019 [cited by applicant]
US 20190044963A1 · Rajasekharan et al. · 2019 [cited by applicant]
US 20190251260A1 · Stockdale et al. · 2019 [cited by applicant]
US 20200090171A1 · Bajpai · 2020 [cited by examiner]
US 20200244673A1 · Stockdale · 2020 [cited by applicant]
US 20200259852A1 · Wolff · 2020 [cited by examiner]
US 20200280575A1 · Dean et al. · 2020 [cited by applicant]
US 20210120027A1 · Dean et al. · 2021 [cited by applicant]
US 20210157919A1 · Stockdale et al. · 2021 [cited by applicant]
US 20210194911A1 · Hecht · 2021 [cited by examiner]
US 20210226982A1 · Marty · 2021 [cited by examiner]
US 20210273958A1 · McLean · 2021 [cited by applicant]
EP 2922268A1 · 2015 [cited by applicant]
WO 2001031420A2 · 2001 [cited by applicant]
WO 2008121945A2 · 2008 [cited by applicant]
WO 2013053407A1 · 2013 [cited by applicant]
WO 2014088912A1 · 2014 [cited by applicant]
WO 2015027828A1 · 2015 [cited by applicant]
WO 2016020660A1 · 2016 [cited by applicant]
WO 2019243579A1 · 2019 [cited by applicant]
WO 2020021100A1 · 2020 [cited by applicant]
International Search Authority, The International Search Report and the Written Opinion of the International Searching Authority, or the Declaration, 156 pages. [cited by applicant]
Abdallah Abbey Sebyala et al., “Active Platform Security through Intrusion Detection Using Naive Bayesian Network for Anomaly Detection,” Department of Electronic and Electrical Engineering, 5 pages, University College … [cited by applicant]
Marek Zachara et al., “Detecting Unusual User Behavior to Identify Hijacked Internet Auctions Accounts, ” Lecture Notes in Computer Science, 2012, vol. 7465, Springer, Berlin, Heidelberg, Germany. [cited by applicant]
Gharan, Shayan Oveis, “Lecture 11; Clustering and the Spectral Partitioning Algorithm” May 2, 2016, 6 pages. [cited by applicant]
Nikolystylfw, “Can Senseon beat Darktrace at its very own game with its ‘An I triangulation’ modern technology?” Dec. 22, 2018, nikolystylfw. [cited by applicant]
Lunden, Ingrid, “Senseon raises $6.4M to tackle cybersecurity threats with an AI ‘triangulation’ approach” Feb. 19, 2019, Tech Crunch. [cited by applicant]
Senseon Tech Ltd., “The State of Cyber Security SME Report 2019” Jun. 3, 2019, 16 pages. [cited by applicant]
Caithness, Neil, “Supervised/unsupervised cross-over method for autonomous anomaly classification,” Oct. 25, 2019, CAMLIS 2019. [cited by applicant]
Senseon Tech Ltd., “Technology,” * please see the statement filed herewith. [cited by applicant]
Senseon Tech Ltd., “Senseon & You,” * please see the statement filed herewith. [cited by applicant]
Senseon Tech Ltd., “Technology Overview,” * please see the statement filed herewith. [cited by applicant]
Senseon Tech Ltd., “Senseon Enterprise,” * please see the statement filed herewith. [cited by applicant]
Senseon Tech Ltd., “Senseon Pro,” * please see the statement filed herewith. [cited by applicant]
Senseon Tech Ltd., “Senseon Reflex,” * please see the statement filed herewith. [cited by applicant]
European Patent Office, “Communication pursuant to Article 94(3) EPC,” 7pp., Mar. 24, 2025. [cited by applicant]