IP Library Granted Patent US 11,949,700
Granted Patent B2
US 11,949,700 · App. 17/226,698 · Granted Apr 2, 2024

Using content stored in an entity behavior catalog in combination with an entity risk score

Inventors: Assaf Almaz (Ra'anana, IL); Ofir Arkin (Tel Aviv, IL); Nicolas Christian Fischbach (Uitikon, CH); Raffael Marty (Austin, TX)
Assignee: Forcepoint LLC
H04L63/1425H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,949,700
App. No.
17/226,698
Granted
Apr 2, 2024
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for performing a security operation. The security operation includes monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the monitoring comprising monitoring the plurality of electronically-observable actions via a protected endpoint; converting the plurality of electronically-observable actions of the entity to electronic information representing the plurality of actions of the entity; generating a representation of occurrences of a particular event from the plurality of events enacted by the entity; and performing an anomaly detection operation based upon the representation of occurrences of the particular event from the plurality of events enacted by the entity, the anomaly detection operation determining when the representation of occurrences of the particular event exceeds a predetermined threshold.

Claims (67)

1. A computer-implementable method for performing a security operation, comprising:

monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity;

identifying a security related activity of the entity from the plurality of events enacted by the entity, the security related activity being of analytic utility;

generating an event severity risk score based upon the security related activity of the entity;

generating an entity risk severity score for the entity, the generating using the event risk severity score;

accessing an entity behavior catalog based upon the security related activity, the entity behavior catalog providing an inventory of entity behaviors; and,

performing the security operation via a security analytics system, the security operation using the entity risk severity score entity and the behavior catalog data stored within the entity behavior catalog based upon the security related activity, the security analytics system executing on a hardware processor.

2. The method of claim 1 , wherein:

the event risk severity score comprises an initial event risk severity score, the initial event risk severity score comprising an initial event risk severity score value; and,

the initial event risk severity score value is modified to provide a current event risk severity score by application of a reduction function to the initial event risk severity score value.

3. The method of claim 2 , wherein:

the reduction function comprises at least one of a flat reduction function, a gradual reduction function, a flat then gradual reduction function and a step reduction function.

4. The method of claim 2 , wherein:

the reduction function comprises an associated longevity interval, the risk reduction function being applied to the initial event risk severity score for the associated longevity interval.

5. The method of claim 2 , wherein:

the initial event security risk score value is modified to provide a current event risk severity score by application of a plurality of reduction functions to the initial event security risk score value.

6. The method of claim 5 , wherein:

the plurality of events enacted by the entity comprise a plurality of anomalous events;

each of the plurality of reduction functions is applied to a respective anomalous event of the plurality of anomalous events to provide a plurality of event risk severity scores; and,

the entity risk severity score is generated using the plurality of event risk severity scores, the entity risk severity score represents a risk associated with the plurality of anomalous events.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code for performing a security operation, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity;

identifying a security related activity of the entity from the plurality of events enacted by the entity, the security related activity being of analytic utility;

generating an event severity risk score based upon the security related activity of the entity;

generating an entity risk severity score for the entity, the generating using the event risk severity score;

accessing an entity behavior catalog based upon the security related activity, the entity behavior catalog providing an inventory of entity behaviors; and,

performing the security operation via a security analytics system, the security operation using the entity risk severity score entity and the behavior catalog data stored within the entity behavior catalog based upon the security related activity, the security analytics system executing on a hardware processor.

8. The system of claim 7 , wherein:

the event risk severity score comprises an initial event risk severity score, the initial event risk severity score comprising an initial event risk severity score value; and,

the initial event risk severity score value is modified to provide a current event risk severity score by application of a reduction function to the initial event risk severity score value.

9. The system of claim 8 , wherein:

the reduction function comprises at least one of a flat reduction function, a gradual reduction function, a flat then gradual reduction function and a step reduction function.

10. The system of claim 8 , wherein:

the reduction function comprises an associated longevity interval, the risk reduction function being applied to the initial event risk severity score for the associated longevity interval.

11. The system of claim 8 , wherein:

the initial event security risk score value is modified to provide a current event risk severity score by application of a plurality of reduction functions to the initial event security risk score value.

12. The system of claim 11 , wherein:

the plurality of events enacted by the entity comprise a plurality of anomalous events;

each of the plurality of reduction functions is applied to a respective anomalous event of the plurality of anomalous events to provide a plurality of event risk severity scores; and,

the entity risk severity score is generated using the plurality of event risk severity scores, the entity risk severity score represents a risk associated with the plurality of anomalous events.

13. A non-transitory, computer-readable storage medium embodying computer program code for performing a security operation, the computer program code comprising computer executable instructions configured for:

monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity;

identifying a security related activity of the entity from the plurality of events enacted by the entity, the security related activity being of analytic utility;

generating an event severity risk score based upon the security related activity of the entity;

generating an entity risk severity score for the entity, the generating using the event risk severity score;

accessing an entity behavior catalog based upon the security related activity, the entity behavior catalog providing an inventory of entity behaviors; and,

performing the security operation via a security analytics system, the security operation using the entity risk severity score entity and the behavior catalog data stored within the entity behavior catalog based upon the security related activity, the security analytics system executing on a hardware processor.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the event risk severity score comprises an initial event risk severity score, the initial event risk severity score comprising an initial event risk severity score value; and,

the initial event risk severity score value is modified to provide a current event risk severity score by application of a reduction function to the initial event risk severity score value.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein:

the reduction function comprises at least one of a flat reduction function, a gradual reduction function, a flat then gradual reduction function and a step reduction function.

16. The non-transitory, computer-readable storage medium of claim 14 , wherein:

the reduction function comprises an associated longevity interval, the risk reduction function being applied to the initial event risk severity score for the associated longevity interval.

17. The non-transitory, computer-readable storage medium of claim 14 , wherein:

the initial event security risk score value is modified to provide a current event risk severity score by application of a plurality of reduction functions to the initial event security risk score value.

18. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

the plurality of events enacted by the entity comprise a plurality of anomalous events;

each of the plurality of reduction functions is applied to a respective anomalous event of the plurality of anomalous events to provide a plurality of event risk severity scores; and,

the entity risk severity score is generated using the plurality of event risk severity scores, the entity risk severity score represents a risk associated with the plurality of anomalous events.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2022
From: ALMAZ, ASSAF; ARKIN, OFIR; FISCHBACH, NICOLAS CHRISTIAN; MARTY, RAFFAEL
To: FORCEPOINT, LLC
Reel/Frame 060053/0462 →
Continuity (13)
Continuation 16923723 · Jul 8, 2020
Continuation 16557560 · Aug 30, 2019
Continuation In Part 16415726 · May 17, 2019
Continuation In Part 16162655 · Oct 17, 2018
Continuation 15963729 · Apr 26, 2018
Continuation In Part 15878898 · Jan 24, 2018
Continuation 15720788 · Sep 29, 2017
Provisional Application 63119116 · Nov 30, 2020
Provisional Application 63072563 · Aug 31, 2020
Provisional Application 63017400 · Apr 29, 2020
Provisional Application 62839060 · Apr 26, 2019
Provisional Application 62506300 · May 15, 2017
Related Publication 20210226976A1 · Jul 22, 2021