IP Library Granted Patent US 12,603,822
Granted Patent B2
US 12,603,822 · App. 17/323,853 · Granted Apr 14, 2026

Software as a service (SaaS) user interface (UI) for displaying user activities in an artificial intelligence (AI)-based cyber threat defense system

Inventors: John Anthony Boyer (Cambridge, GB); Constance Alice Chapman (Cambridge, GB); Matthew Charles Sherwin (Cambridge, GB); Jack Benjamin Stockdale (Cambridge, GB)
Assignee: Darktrace Holdings Limited
H04L41/5045G06F18/214G06N20/00G06V10/762G06V10/774H04L41/22H04L63/1416H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,603,822
App. No.
17/323,853
Granted
Apr 14, 2026
Kind
B2
Abstract

A Software as a Service (SaaS) console can retrieve data from one or more application programming interfaces (APIs) hosted by one or more SaaS platforms in order to identify cyber threats in a cyber threat defense system. The SaaS console can use customizable generic templates to provide a regular i) polling service, ii) data retrieval service, and iii) any combination of both, as well as a universal way to obtain data from the one or more APIs hosted by one or more SaaS platforms to collect event-based activity data from the one or more APIs. Data fields of the one or more customizable generic template are configured to be populated with data incorporated from a first user of a first SaaS platform for a first API for the first SaaS platform.

Claims (39)

1 . An apparatus, comprising:

a processor; and

a non-transitory computer readable medium including

a Software as a Service (SaaS) console that, when executed by the processor, configured to retrieves data from one or more application programming interfaces (APIs) hosted by one or more SaaS platforms in order to identify a cyber threat in a cyber threat defense system, the SaaS console is further configured to conduct a regular i) polling service, ii) data retrieval service, and iii) any combination of both and obtain data from the one or more APIs hosted by one or more SaaS platforms to collect event-based activity data from the one or more APIs, wherein the SaaS console is further configured to generate a plurality of SaaS user interfaces (UIs) for visually displaying the collected event-based activity data including at least a SaaS UI used to display a visual representation of the SaaS user activities illustrated as one or more paths interconnecting a series of nodes, where each node represents a file, folder or other storage resource and each of the one or more paths is assigned (i) a color representing normal or anomalous user activity and (ii) a line thickness representing a frequency of use,

a cyber threat module that, when executed by the processor, configured to detects the cyber threat based on at least a determination whether the event-based activity data identifies behaviors that are different from normal behavior associated with the activity as determined by machine learning models accessible by the cyber threat module, and

an autonomous response module communicatively coupled to the cyber threat module, the autonomous response module that, when executed by the processor, is configured to generate an autonomous action itself; rather than a human, in response to the cyber threats, where the autonomous response module is configured to cause one or more autonomous actions to be taken to contain the cyber threat when a threat risk parameter determined by and provided from the cyber threat module is equal to or above an actionable threshold, where the cyber threat module is configured to cooperate with the autonomous response module, to cause the one or more autonomous actions to be taken to contain the cyber threat by limiting an impact of the cyber threat from consuming unauthorized CPU cycles, memory space, and power consumption in a computing device via responding to the cyber threat without waiting for some human intervention.

2 . The apparatus of claim 1 , wherein the SaaS console is configured to cooperate with one or more machine-learning models trained on a normal benign behavior of an entity to compare at least one or more of the collected event-based activity data from the incorporated data to one or more machine-learning models trained on a normal benign behavior of that entity in relation to the SaaS environment using a normal behavior benchmark.

3 . The apparatus of claim 1 , wherein the generate a plurality of SaaS UIs are generated for visually displaying the collected event-based activity data to a second user operating the first SaaS console.

4 . The apparatus of claim 3 , wherein the SaaS console with the plurality of SaaS UIs is further configured to visually display the event-based activity data with multiple user interfaces, where each user interface is configured to display a particular type of SaaS event-based activity data, where the event-based activity data can include one or more of event anomaly data, location anomaly data, and action anomaly data in a SaaS environment.

5 . The apparatus of claim 4 , wherein the SaaS console is further configured to produce a first SaaS UI having a first window cooperating with a first classifier, where the first SaaS UI is configured to visually display one or more locational anomalies for the entity on a geographical map as well as the first classifier is trained to generate a kind of anomaly detected in the first window corresponding to the visual representation of the locational anomalies on the first SaaS UI.

6 . The apparatus of claim 4 , wherein the SaaS console is further configured to produce the SaaS UI used to visually display the user activity anomaly in a SaaS and/or Cloud environment with the visual representation of a tree-like structure that allows a user-based investigation of a large amount of user events occurring over a long timeframe to be reviewed by a human investigator, and a third SaaS UI having multiple windows that are configured to cooperate with one or more artificial intelligence trained classifiers, and one or more trained machine learning models to visually display overall user activity.

7 . The apparatus of claim 3 , wherein the SaaS console with the plurality of SaaS UIs is configured to use non-numeric shapes, symbols, and/or colors associated with the series of nodes to visually display different types of SaaS event-based activity data so that abnormal event-based activity data is quickly recognizable.

8 . The apparatus of claim 1 , wherein customizable generic templates are used to provide at least the data retrieval services and are configured to be capable of being shared and used by all of the users operating the SaaS console to provide the regular i) polling service, ii) data retrieval service, and iii) any combination of both, to obtain the data from the one or more APIs.

9 . The apparatus of claim 1 , wherein the cyber threat module in cooperation with one or more machine learning models trained on a normal benign behavior of that entity in relation to the SaaS environment is configured to determine whether the entity is in a breach state of a normal behavior benchmark.

10 . The apparatus of claim 1 , wherein the cyber threat module in cooperation with one or more machine learning models trained on cyber threats is configured to identify whether a determined breach state of a normal behavior benchmark in conjunction with a chain of relevant behavioral parameters are deviating from a normal benign behavior of that entity correspond to a cyber threat.

11 . A method for a Software as a Service (SaaS) console, comprising:

retrieving, by configuring the SaaS console, to retrieve data from one or more application programming interfaces (APIs) hosted by one or more SaaS platforms in order to identify cyber threats in a cyber threat defense system;

utilizing, by configuring the SaaS console, to use customizable generic templates to conduct a regular i) polling service, ii) data retrieval service, and iii) any combination of both and obtain data from the one or more APIs hosted by one or more SaaS platforms to collect event-based activity data;

generating a plurality of SaaS user interfaces (UIs) for visually displaying the collected event-based activity data including at least a SaaS UI used to display a visual representation of the SaaS user activities illustrated as one or more paths interconnecting a series of nodes, where each node of the series of nodes represents a file, folder or other storage resource and each of the one or more paths is assigned (i) a color representing normal or anomalous user activity and (ii) a line thickness representing a frequency of use;

configuring a cyber threat module to detecting, by a cyber threat module, the cyber threat based at least a determination whether the event-based activity data identifies behaviors that are different from normal behavior associated with the activity as determined by machine learning models accessible by the cyber threat module;

generating configuring an autonomous response module to generate an autonomous action by an autonomous response module, itself; rather than a human, in response to the cyber threats;

causing, by configuring the autonomous response module, to cause one or more autonomous actions to be taken to contain the cyber threat when a threat risk parameter determined by and provided from the cyber threat module is equal to or above an actionable threshold; and

based on configuring where the cyber threat module cooperating to cooperate with the autonomous response module, causing to cause the one or more autonomous actions to be taken to contain the cyber threat by limiting an impact of the cyber threat from consuming unauthorized CPU cycles, memory space, and power consumption in a computing device via responding to the cyber threat without waiting for some human intervention.

12 . The method of claim 11 , further comprising:

comparing, by configuring the SaaS console cooperating to cooperate with one or more machine-learning models trained on a normal benign behavior of an entity, to compare at least one or more of the collected event-based activity data from the incorporated data to one or more machine-learning models trained on a normal benign behavior of that entity in relation to the SaaS environment using a normal behavior benchmark.

13 . The method of claim 11 , wherein the plurality of SaaS UIs are generated for visually displaying the collected event-based activity data to a second user operating the SaaS console.

14 . The method of claim 13 , further comprising:

visually displaying, by configuring the SaaS console with the plurality of SaaS UIs, to visually display the event-based activity data with multiple user interfaces, where each user interface is configured to display a particular type of SaaS event-based activity data, where the event-based activity data can include one or more of event anomaly data, location anomaly data, and action anomaly data in a SaaS environment.

15 . The method of claim 13 , further comprising:

producing, by configuring the SaaS console, to produce a first SaaS UI having a first window cooperating with a first classifier, where the first SaaS UI is configured to visually display one or more locational anomalies for the entity on a geographical map as well as the first classifier is trained to generate a kind of anomaly detected in the first window corresponding to the visual representation of the locational anomalies on the first SaaS UI.

16 . The method of claim 13 , further comprising:

producing, by configuring the SaaS console, to produce a second SaaS UI used to visually display a user activity anomaly in a SaaS and/or Cloud environment with a visual representation of a tree-like structure that allows a user-based investigation of a large amount of user events occurring over a long timeframe to be reviewed by a human investigator, and a third SaaS UI having multiple windows that are configured to cooperate with one or more artificial intelligence trained classifiers, and one or more trained machine learning models to visually display overall user activity.

17 . The method of claim 13 , further comprising: wherein

configuring the SaaS console with the plurality of SaaS UIs are is configured to use non-numeric shapes, symbols, and/or colors to visually display different types of SaaS event-based activity data so that abnormal event-based activity data is quickly recognizable by a human that some SaaS activity indicated on a display screen with the non-numeric shapes, symbols, and/or colors is different from a normal event-based activity data.

18 . The method of claim 11 , wherein further comprising:

configuring the customizable generic templates are configured to be capable of being shared and used by all of the users operating the SaaS console to provide the regular i) polling service, ii) data retrieval service, and iii) any combination of both, to obtain the data from the one or more APIs.

19 . The method of claim 11 , further comprising:

identifying, by configuring the cyber threat module in cooperation with one or more machine learning models trained on cyber threats, to identify whether a determined breach state of a normal behavior benchmark in conjunction with a chain of relevant behavioral parameters are deviating from a normal benign behavior of that entity correspond to a cyber threat.

20 . A non-transitory computer readable medium in a SaaS console, comprising: one or more computer readable codes operable, when executed by one or more processors in a computing device, to instruct the SaaS console to perform the method of claim 11 .

Assignments (3)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2022
From: BOYER, JOHN ANTHONY; CHAPMAN, CONSTANCE ALICE; SHERWIN, MATTHEW CHARLES; STOCKDALE, JACK BENJAMIN
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 059573/0602 →
Continuity (5)
Continuation In Part 17187169 · Feb 26, 2021
Provisional Application 63078092 · Sep 14, 2020
Provisional Application 63026446 · May 18, 2020
Provisional Application 62983307 · Feb 28, 2020
Related Publication 20210273973A1 · Sep 2, 2021
References Cited (138)
US 6154844A · Touboul et al. · 2000 [cited by applicant]
US 6965968B1 · Touboul · 2005 [cited by applicant]
US 7307999B1 · Donaghey · 2007 [cited by applicant]
US 7418731B2 · Touboul · 2008 [cited by applicant]
US 7448084B1 · Apap et al. · 2008 [cited by applicant]
US 7890869B1 · Mayer et al. · 2011 [cited by applicant]
US 8312540B1 · Kahn et al. · 2012 [cited by applicant]
US 8661538B2 · Cohen-Ganor et al. · 2014 [cited by applicant]
US 8819803B1 · Richards et al. · 2014 [cited by applicant]
US 8879803B2 · Ukil et al. · 2014 [cited by applicant]
US 8966036B1 · Asgekar et al. · 2015 [cited by applicant]
US 9043905B1 · Allen et al. · 2015 [cited by applicant]
US 9098333B1 · Obrecht · 2015 [cited by examiner]
US 9106687B1 · Sawhney et al. · 2015 [cited by applicant]
US 9185095B1 · Moritz et al. · 2015 [cited by applicant]
US 9213990B2 · Adjaoute · 2015 [cited by applicant]
US 9348742B1 · Brezinski · 2016 [cited by applicant]
US 9401925B1 · Guo et al. · 2016 [cited by applicant]
US 9516039B1 · Yen et al. · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9641544B1 · Treat et al. · 2017 [cited by applicant]
US 9712548B2 · Shmuell et al. · 2017 [cited by applicant]
US 9727723B1 · Kondaveeti et al. · 2017 [cited by applicant]
US 10237298B1 · Nguyen et al. · 2019 [cited by applicant]
US 10268821B2 · Stockdale · 2019 [cited by applicant]
US 10419466B2 · Ferguson · 2019 [cited by applicant]
US 10516693B2 · Stockdale et al. · 2019 [cited by applicant]
US 10701093B2 · Dean · 2020 [cited by applicant]
US 10908970B1 · Arivazhagan · 2021 [cited by examiner]
US 20020174217A1 · Anderson et al. · 2002 [cited by applicant]
US 20020186698A1 · Ceniza · 2002 [cited by applicant]
US 20030070003A1 · Chong et al. · 2003 [cited by applicant]
US 20040083129A1 · Herz · 2004 [cited by applicant]
US 20040167893A1 · Matsunaga et al. · 2004 [cited by applicant]
US 20050065754A1 · Schaf et al. · 2005 [cited by applicant]
US 20070118909A1 · Hertzog · 2007 [cited by examiner]
US 20070294187A1 · Scherrer · 2007 [cited by applicant]
US 20080005137A1 · Surendran et al. · 2008 [cited by applicant]
US 20080077358A1 · Marvasti · 2008 [cited by applicant]
US 20080109730A1 · Coffman et al. · 2008 [cited by applicant]
US 20090106174A1 · Battisha et al. · 2009 [cited by applicant]
US 20090254971A1 · Herz et al. · 2009 [cited by applicant]
US 20100009357A1 · Nevins et al. · 2010 [cited by applicant]
US 20100095374A1 · Gillum et al. · 2010 [cited by applicant]
US 20100107254A1 · Eiland et al. · 2010 [cited by applicant]
US 20100125908A1 · Kudo · 2010 [cited by applicant]
US 20100235908A1 · Eynon et al. · 2010 [cited by applicant]
US 20100299292A1 · Collazo · 2010 [cited by applicant]
US 20110093428A1 · Wisse · 2011 [cited by applicant]
US 20110213742A1 · Lemmond et al. · 2011 [cited by applicant]
US 20110261710A1 · Chen et al. · 2011 [cited by applicant]
US 20120096549A1 · Amini et al. · 2012 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120209575A1 · Barbat et al. · 2012 [cited by applicant]
US 20120210388A1 · Kolishchak · 2012 [cited by applicant]
US 20120284791A1 · Miller et al. · 2012 [cited by applicant]
US 20120304288A1 · Wright et al. · 2012 [cited by applicant]
US 20130091539A1 · Khurana et al. · 2013 [cited by applicant]
US 20130198119A1 · Eberhardt, III et al. · 2013 [cited by applicant]
US 20130198840A1 · Drissi et al. · 2013 [cited by applicant]
US 20130254885A1 · Devost · 2013 [cited by applicant]
US 20140007237A1 · Wright et al. · 2014 [cited by applicant]
US 20140074762A1 · Campbell · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140215618A1 · Amit · 2014 [cited by applicant]
US 20140325643A1 · Bart et al. · 2014 [cited by applicant]
US 20150052614A1 · Crowell · 2015 [cited by applicant]
US 20150067835A1 · Chari et al. · 2015 [cited by applicant]
US 20150081431A1 · Akahoshi et al. · 2015 [cited by applicant]
US 20150161394A1 · Ferragut et al. · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150180893A1 · Im et al. · 2015 [cited by applicant]
US 20150213358A1 · Shelton et al. · 2015 [cited by applicant]
US 20150281287A1 · Gill · 2015 [cited by applicant]
US 20150286819A1 · Coden et al. · 2015 [cited by applicant]
US 20150310195A1 · Bailor et al. · 2015 [cited by applicant]
US 20150319185A1 · Kirti et al. · 2015 [cited by applicant]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150363699A1 · Nikovski · 2015 [cited by applicant]
US 20150379110A1 · Marvasti et al. · 2015 [cited by applicant]
US 20160062950A1 · Brodersen et al. · 2016 [cited by applicant]
US 20160078365A1 · Baumard · 2016 [cited by applicant]
US 20160149941A1 · Thakur et al. · 2016 [cited by applicant]
US 20160164902A1 · Moore · 2016 [cited by applicant]
US 20160173509A1 · Ray et al. · 2016 [cited by applicant]
US 20160241576A1 · Rathod et al. · 2016 [cited by applicant]
US 20160352768A1 · Lefebvre et al. · 2016 [cited by applicant]
US 20160359695A1 · Yadav et al. · 2016 [cited by applicant]
US 20160373476A1 · Dell'Anno et al. · 2016 [cited by applicant]
US 20160373477A1 · Moyle et al. · 2016 [cited by applicant]
US 20170054745A1 · Zhang et al. · 2017 [cited by applicant]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170118239A1 · Most · 2017 [cited by examiner]
US 20170169360A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170270422A1 · Sorakado · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180167402A1 · Scheidler et al. · 2018 [cited by applicant]
US 20180234310A1 · Ingalls · 2018 [cited by examiner]
US 20180375886A1 · Kirti · 2018 [cited by applicant]
US 20190036948A1 · Appel et al. · 2019 [cited by applicant]
US 20190044963A1 · Rajasekharan et al. · 2019 [cited by applicant]
US 20190251260A1 · Stockdale et al. · 2019 [cited by applicant]
US 20200090171A1 · Bajpai · 2020 [cited by applicant]
US 20200244673A1 · Stockdale · 2020 [cited by applicant]
US 20200259852A1 · Wolff · 2020 [cited by examiner]
US 20200280575A1 · Dean et al. · 2020 [cited by applicant]
US 20210120027A1 · Dean et al. · 2021 [cited by applicant]
US 20210157919A1 · Stockdale et al. · 2021 [cited by applicant]
US 20210194911A1 · Hecht · 2021 [cited by applicant]
US 20210273958A1 · McLean · 2021 [cited by applicant]
EP 2922268A1 · 2015 [cited by applicant]
WO 2001031420A2 · 2001 [cited by applicant]
WO 2008121945A2 · 2008 [cited by applicant]
WO 2013053407A1 · 2013 [cited by applicant]
WO 2014088912A1 · 2014 [cited by applicant]
WO 2015027828A1 · 2015 [cited by applicant]
WO 2016020660A1 · 2016 [cited by applicant]
WO 2019243579A1 · 2019 [cited by applicant]
WO 2020021100A1 · 2020 [cited by applicant]
European Patent office Communication pursuant to Rules 161(1) and 162 EPC, Oct. 6, 2022, 3 pages. [cited by applicant]
International Search Authority, The International Preliminary Report on Patentability,Aug. 30, 2022, 10 pages. [cited by applicant]
Abdallah Abbey Sebyala et al., “Active Platform Security through Intrusion Detection Using Naive Bayesian Network for Anomaly Detection,” Department of Electronic and Electrical Engineering, 5 pages, University College … [cited by applicant]
Marek Zachara et al., “Detecting Unusual User Behavior to Identify Hijacked Internet Auctions Accounts,” Lecture Notes in Computer Science, 2012, vol. 7465, Springer, Berlin, Heidelberg, Germany. [cited by applicant]
Gharan, Shayan Oveis, “Lecture 11; Clustering and the Spectral Partitioning Algorithm” May 2, 2016, 6 pages. [cited by applicant]
Nikolystylfw, “Can Senseon beat Darktrace at its very own game with its ‘An I triangulation’ modern technology?” Dec. 22, 2018, nikolystylfw. [cited by applicant]
Lunden, Ingrid, “Senseon raises $6.4M to tackle cybersecurity threats with an AI ‘triangulation’ approach” Feb. 19, 2019, Tech Crunch. [cited by applicant]
Senseon Tech Ltd., “The State of Cyber Security SME Report 2019” Jun. 3, 2019, 16 pages. [cited by applicant]
Caithness, Neil, “Supervised/unsupervised cross-over method for autonomous anomaly classification,” Oct. 25, 2019, CAMLIS 2019. [cited by applicant]
Senseon Tech Ltd., “Technology,”. [cited by applicant]
Senseon Tech Ltd., “Senseon & You,”. [cited by applicant]
Senseon Tech Ltd., “Technology Overview,”. [cited by applicant]
Senseon Tech Ltd., “Senseon Enterprise,”. [cited by applicant]
Senseon Tech Ltd., “Senseon Pro,”. [cited by applicant]
Senseon Tech Ltd., “Senseon Reflex,”. [cited by applicant]
United States Patent and Trademark Office; Non-Final Office Action, Feb. 27, 2024; 39 pages. [cited by applicant]