IP Library Granted Patent US 11,544,273
Granted Patent B2
US 11,544,273 · App. 17/195,688 · Granted Jan 3, 2023

Constructing event distributions via a streaming scoring operation

Inventors: Christopher Poirel (Baltimore, MD); William Renner (Baltimore, MD); Eduardo Luiggi (Ellicott City, MD); Phillip Bracikowski (Indianapolis, IN)
Assignee: Forcepoint LLC
G06F16/24568G06F7/14G06F16/285
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,544,273
App. No.
17/195,688
Granted
Jan 3, 2023
Kind
B2
Abstract

A method, system and computer-usable medium for performing a streaming scoring operation, comprising: receiving a stream of events, the stream of events comprising a plurality of events; ingesting the plurality of events; extracting features from the plurality of events to provide extracted features; and, generating a streaming scoring value based upon the extracted features.

Claims (71)

1. A computer-implementable method for performing a streaming scoring operation, comprising:

receiving a stream of events, the stream of events comprising a plurality of events, each of the plurality of events referring to an occurrence of an action performed by an entity;

ingesting the plurality of events into a streaming query framework;

extracting features from the plurality of events to provide extracted features via the streaming query framework;

generating a streaming scoring value based upon the extracted features via the streaming query framework; and,

using the streaming scoring value to generate a risk score for the entity, the risk score representing a relative security risk of the entity.

2. The method of claim 1 , further comprising:

performing a probability distribution operation on the extracted features when generating the streaming scoring value, the statistical distribution operation determining probability distributions of the extracted features.

3. The method of claim 1 , further comprising:

generating a scoring container, and wherein

when extracting features from the plurality of events using the scoring container to identify any outliers from the plurality of extracted features.

4. The method of claim 3 , wherein:

the scoring container is one of a plurality of scoring containers; and further comprising

merging the plurality of scoring containers by combining scoring containers across a plurality of time intervals.

5. The method of claim 1 , further comprising:

determining whether an event matches a query associated with a particular feature;

applying the query to the stream of events; and

classifying a plurality of ingested events based upon whether the plurality of ingested events match the query.

6. The method of claim 5 , wherein:

the query is included within a set of queries;

the set of queries comprise a set of defined queries, each of the set of defined queries comprising an associated feature; and,

applying the set of queries to the stream of events results in categorization of each event with respect to features associated with a subset of queries for which each event matches.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

receiving a stream of events, the stream of events comprising a plurality of events, each of the plurality of events referring to an occurrence of an action performed by an entity;

ingesting the plurality of events into a streaming query framework;

extracting features from the plurality of events to provide extracted features via the streaming query framework;

generating a streaming scoring value based upon the extracted features via the streaming query framework; and,

using the streaming scoring value to generate a risk score for the entity, the risk score representing a relative security risk of the entity.

8. The system of claim 7 , wherein the instructions are further configured for:

performing a statistical distribution operation on the extracted features when generating the streaming scoring value, the statistical distribution operation determining statistical distributions of the matching features.

9. The system of claim 7 , wherein the instructions are further configured for:

generating a scoring container, and wherein

when extracting features from the plurality of events using the scoring container to identify any outliers from the plurality of events.

10. The system of claim 9 , wherein:

the scoring container is one of a plurality of scoring containers; and further comprising

merging the plurality of scoring containers by combining scoring containers across a plurality of time intervals.

11. The system of claim 7 , wherein:

determining whether an event matches a query associated with a particular feature;

applying the query to the stream of events; and

classifying a plurality of ingested events based upon whether the plurality of ingested events match the query.

12. The system of claim 11 , wherein:

the query is included within a set of queries;

the set of queries comprise a set of defined queries, each of the set of defined queries comprising an associated feature; and,

applying the set of queries to the stream of events results in categorization of each event with respect to features associated with a subset of queries for which each event matches.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

receiving a stream of events, the stream of events comprising a plurality of events, each of the plurality of events referring to an occurrence of an action performed by an entity;

ingesting the plurality of events into a streaming query framework;

extracting features from the plurality of events to provide extracted features via the streaming query framework;

generating a streaming scoring value based upon the extracted features via the streaming query framework; and,

using the streaming scoring value to generate a risk score for the entity, the risk score representing a relative security risk of the entity.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

performing a probability distribution operation on the extracted features when generating the streaming scoring value, the statistical distribution operation determining probability distributions of the extracted features.

15. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

generating a scoring container, and wherein

when extracting features from the plurality of events using the scoring container to identify any outliers from the plurality of events.

16. The non-transitory, computer-readable storage medium of claim 15 , wherein:

the scoring container is one of a plurality of scoring containers; and further comprising

merging the plurality of scoring containers by combining scoring containers across a plurality of time intervals.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

determining whether an event matches a query associated with a particular feature;

applying the query to the stream of events; and

classifying a plurality of ingested events based upon whether the plurality of ingested events match the query.

18. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the query is included within a set of queries;

the set of queries comprise a set of defined queries, each of the set of defined queries comprising an associated feature; and,

applying the set of queries to the stream of events results in categorization of each event with respect to features associated with a subset of queries for which each event matches.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (5)
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0524 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2023
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 063446/0418 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2023
From: POIREL, CHRISTOPHER; RENNER, WILLIAM; LUIGGI, EDUARDO; BRACIKOWSKI, PHILLIP
To: FORCEPOINT LLC
Reel/Frame 063365/0835 →
Continuity (2)
Continuation 16033770 · Jul 12, 2018
Related Publication 20210224282A1 · Jul 22, 2021