IP Library Granted Patent US 12,001,563
Granted Patent B2
US 12,001,563 · App. 17/226,722 · Granted Jun 4, 2024

Generating an entity behavior profile based upon sessions

Inventors: Alan Ross (Austin, TX); Raffael Marty (Austin, TX); Nicolas Christian Fischbach (Uitikon, CH)
Assignee: Forcepoint LLC
G06F21/577G06F21/552G06F21/554G06F21/566G06F21/6227G06N5/04G06N20/00H04L63/102H04L63/1425H04L63/1433H04L63/1441G06F2221/033G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,001,563
App. No.
17/226,722
Granted
Jun 4, 2024
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for performing an entity behavior cataloging operation. The entity behavior cataloging operation includes: identifying a security related activity, the security related activity being based upon an observable from an electronic data source; analyzing the security related activity, the analyzing identifying an event of analytic utility associated with the security related activity; generating entity behavior catalog data based upon the event of analytic utility associated with the security related activity; and, storing the entity behavior catalog data within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation.

Claims (61)

1. A computer-implementable method for performing a security operation, comprising:

monitoring an entity, the monitoring observing at least one electronically-observable data source, the monitoring comprising monitoring at least one of a plurality of electronically-observable actions via a protected endpoint;

deriving an observable based upon the monitoring of the electronically-observable data source;

identifying a security related activity of the entity, the security related activity being based upon the observable derived from the electronic data source, the security related activity being of analytic utility;

associating the security related activity with a session;

processing an entity behavior profile of the entity and contextual information relating to the entity to generate an inference regarding the entity;

generating an entity behavior profile element based upon the security related activity and the session; and,

performing the security operation via the protected endpoint and a security analytics system, the security operation using the entity behavior entity behavior profile element and the inference regarding the entity, the security analytics system executing on a security analytics system hardware processor.

2. The method of claim 1 , wherein:

the entity comprises at least one of a user entity and a non-user entity.

3. The method of claim 1 , further comprising:

associating the entity behavior profile element with the entity behavior profile.

4. The method of claim 3 , wherein:

the entity behavior profile comprises user profile attributes, user behavior factors, a user entity profile and a user entity mindset profile.

5. The method of claim 3 , wherein:

the security operation uses the entity behavior profile to determine whether an event is of analytic utility.

6. The method of claim 5 , wherein:

the security analytics system comprises an analytic utility detection module, the analytic utility detection module determining whether the event is of analytic utility.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring an entity, the monitoring observing at least one electronically-observable data source, the monitoring comprising monitoring at least one of a plurality of electronically-observable actions via a protected endpoint;

deriving an observable based upon the monitoring of the electronically-observable data source;

identifying a security related activity of the entity, the security related activity being based upon the observable derived from the electronic data source, the security related activity being of analytic utility;

associating the security related activity with a session;

processing an entity behavior profile of the entity and contextual information relating to the entity to generate an inference regarding the entity;

generating an entity behavior profile element based upon the security related activity and the session; and

performing the security operation via the protected endpoint and a security analytics system, the security operation using the entity behavior entity behavior profile element and the inference regarding the entity, the security analytics system executing on a security analytics system hardware processor.

8. The system of claim 7 , wherein:

the entity comprises at least one of a user entity and a non-user entity.

9. The system of claim 7 , wherein the instructions executable by the processor are further configured for:

associating the entity behavior profile element with the entity behavior profile.

10. The system of claim 9 , wherein:

the entity behavior profile comprises user profile attributes, user behavior factors, a user entity profile and a user entity mindset profile.

11. The system of claim 7 , wherein:

the security operation uses the entity behavior profile to determine whether an event is of analytic utility.

12. The system of claim 11 , wherein:

the security analytics system comprises an analytic utility detection module, the analytic utility detection module determining whether the event is of analytic utility.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring an entity, the monitoring observing at least one electronically-observable data source, the monitoring comprising monitoring at least one of a plurality of electronically-observable actions via a protected endpoint;

deriving an observable based upon the monitoring of the electronically-observable data source;

identifying a security related activity of the entity, the security related activity being based upon the observable derived from the electronic data source, the security related activity being of analytic utility;

associating the security related activity with a session;

processing an entity behavior profile of the entity and contextual information relating to the entity to generate an inference regarding the entity;

generating an entity behavior profile element based upon the security related activity and the session; and,

performing the security operation via the protected endpoint and a security analytics system, the security operation using the entity behavior entity behavior profile element and the inference regarding the entity, the security analytics system executing on a security analytics system hardware processor.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the entity comprises at least one of a user entity and a non-user entity.

15. The non-transitory, computer-readable storage medium of claim 13 , wherein the computer executable instructions are further configured for:

associating the entity behavior profile element with an entity behavior profile.

16. The non-transitory, computer-readable storage medium of claim 15 , wherein:

the entity behavior profile comprises user profile attributes, user behavior factors, a user entity profile and a user entity mindset profile.

17. The non-transitory, computer-readable storage medium of claim 15 , wherein:

the security operation uses the entity behavior profile to determine whether an event is of analytic utility.

18. The non-transitory, computer-readable storage medium of claim 17 , wherein:

the security system comprises an analytic utility detection module, the analytic utility detection module determining whether the event is of analytic utility.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2021
From: ROSS, ALAN; MARTY, RAFFAEL; FISCHBACH, NICOLAS CHRISTIAN
To: FORCEPOINT, LLC
Reel/Frame 056988/0170 →