IP Library Granted Patent US 11,704,437
Granted Patent B2
US 11,704,437 · App. 17/728,052 · Granted Jul 18, 2023

Gracefully handling endpoint feedback when starting to monitor

Inventors: Richard A. Ford (Austin, TX); Ann Irvine (Baltimore, MD); Adam Reeve (Redmond, WA); Russell Snyder (Baltimore, MD); Benjamin Shih (Baltimore, MD)
Assignee: Forcepoint Federal Holdings LLC
G06F21/6245G06F11/3438G06F21/552G06F21/577G06F21/602G06F21/6254G06F21/84H04L63/1408H04L63/1425H04L63/1433H04L63/1441H04L67/025H04L67/141H04L67/146H04L67/306H04L67/535G06F2221/031G06F2221/032G06F2221/034H04L63/20H04L67/289H04L2209/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,704,437
App. No.
17/728,052
Granted
Jul 18, 2023
Kind
B2
Abstract

A method, system and computer-usable medium for adaptively assessing risk associated with an endpoint, comprising: determining a risk level corresponding to an entity associated with an endpoint; selecting a frequency and a duration of an endpoint monitoring interval; collecting user behavior to collect user behavior associated with the entity for the duration of the endpoint monitoring interval via the endpoint; processing the user behavior to generate a current risk score for the entity; comparing the current risk score of the user to historical risk scores to determine whether a risk score of a user has changed; and changing the risk score of the user to the current risk score when the risk score of the user has changed.

Claims (55)

1. A computer-implementable method for adaptively assessing risk associated with an endpoint, comprising:

determining a risk level corresponding to an entity associated with an endpoint, the endpoint comprising an endpoint agent executing on a hardware processor of the endpoint;

selecting a frequency and a duration of an endpoint monitoring interval;

collecting user behavior associated with the entity for the duration of the endpoint monitoring interval via the endpoint;

processing the user behavior to generate a current risk score for the entity;

comparing the current risk score of the entity to a historical risk score of the entity to determine whether a risk score of the entity has changed;

changing the risk score of the entity to the current risk score when the risk score of the entity has changed;

decreasing the frequency of the endpoint monitoring interval when the current risk scores of the entity remain substantially the same over a plurality of endpoint monitoring intervals;

increasing the frequency of the endpoint monitoring interval when the current risk scores of the entity increase over a plurality of endpoint monitoring intervals; and,

remediating a risk associated with the entity, the remediating the risk being based upon the risk score of the entity, the remediating the risk being performed via one of the endpoint and a security analytics system, the security analytics system executing on a hardware processor of an information handling system.

2. The method of claim 1 , wherein:

the endpoint comprises a risk-adaptive feature pack.

3. The method of claim 2 , wherein:

the risk-adaptive feature pack comprises at least one of an event data detector module, an event data collector module and a risk-adaptive security policy.

4. The method of claim 1 , further comprising:

decreasing the duration of the endpoint monitoring interval when the current risk scores of the user decline over a plurality of endpoint monitoring intervals.

5. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

determining a risk level corresponding to an entity associated with an endpoint the endpoint comprising an endpoint agent executing on a hardware processor of the endpoint;

selecting a frequency and a duration of an endpoint monitoring interval;

collecting user behavior associated with the entity for the duration of the endpoint monitoring interval via the endpoint;

processing the user behavior to generate a current risk score for the entity;

comparing the current risk score of the entity to a historical risk score of the entity to determine whether a risk score of the entity has changed;

changing the risk score of the entity to the current risk score when the risk score of the entity has changed;

decreasing the frequency of the endpoint monitoring interval when the current risk scores of the entity remain substantially the same over a plurality of endpoint monitoring intervals;

increasing the frequency of the endpoint monitoring interval when the current risk scores of the entity increase over a plurality of endpoint monitoring intervals; and,

remediating a risk associated with the entity, the remediating the risk being based upon the risk score of the entity, the remediating the risk being performed via one of the endpoint and a security analytics system, the security analytics system executing on a hardware processor of an information handling system.

6. The system of claim 5 , wherein:

the endpoint comprises a risk-adaptive feature pack.

7. The system of claim 6 , wherein:

the risk-adaptive feature pack comprises at least one of an event data detector module, an event data collector module and a risk-adaptive security policy.

8. The system of claim 5 , wherein the instructions executable by the processor are further configured for:

decreasing the duration of the endpoint monitoring interval when the current risk scores of the user decline over a plurality of endpoint monitoring intervals.

9. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

determining a risk level corresponding to an entity associated with an endpoint;

selecting a frequency and a duration of an endpoint monitoring interval;

collecting user behavior associated with the entity for the duration of the endpoint monitoring interval via the endpoint, the endpoint comprising an endpoint agent executing on a hardware processor of the endpoint;

processing the user behavior to generate a current risk score for the entity;

comparing the current risk score of the entity to a historical risk score of the entity to determine whether a risk score of the entity has changed;

changing the risk score of the entity to the current risk score when the risk score of the entity has changed;

decreasing the frequency of the endpoint monitoring interval when the current risk scores of the entity remain substantially the same over a plurality of endpoint monitoring intervals;

increasing the frequency of the endpoint monitoring interval when the current risk scores of the entity increase over a plurality of endpoint monitoring intervals; and,

remediating a risk associated with the entity, the remediating the risk being based upon the risk score of the entity, the remediating the risk being performed via one of the endpoint and a security analytics system, the security analytics system executing on a hardware processor of an information handling system.

10. The non-transitory, computer-readable storage medium of claim 9 , wherein:

the endpoint comprises a risk-adaptive feature pack.

11. The non-transitory, computer-readable storage medium of claim 10 , wherein:

the risk-adaptive feature pack comprises at least one of an event data detector module, an event data collector module and a risk-adaptive security policy.

12. The non-transitory, computer-readable storage medium of claim 9 , wherein the computer executable instructions are further configured for:

decreasing the duration of the endpoint monitoring interval when the current risk scores of the user decline over a plurality of endpoint monitoring intervals.

13. The non-transitory, computer-readable storage medium of claim 9 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

14. The non-transitory, computer-readable storage medium of claim 9 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (5)
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070588/0074 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2023
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 063446/0418 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 25, 2022
From: FORD, RICHARD A.; IRVINE, ANN; REEVE, ADAM; SNYDER, RUSSELL; SHIH, BENJAMIN
To: FORCEPOINT, LLC
Reel/Frame 059695/0782 →