IP Library Granted Patent US 11,757,902
Granted Patent B2
US 11,757,902 · App. 17/959,378 · Granted Sep 12, 2023

Adaptive trust profile reference architecture

Inventor: Richard A. Ford (Austin, TX)
Assignee: Forcepoint LLC
H04L63/14G06F21/554G06F21/57G06F21/604G06F21/6218G06N5/04H04L9/3239H04L63/102H04L63/1408H04L63/1425H04L63/205H04L67/306H04L67/535G06F2221/2101G06F2221/2141H04L9/50
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,757,902
App. No.
17/959,378
Granted
Sep 12, 2023
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for monitoring actions of an entity. In various embodiments the monitoring includes: monitoring a plurality of electronically-observable actions of the entity, the plurality of electronically-observable actions of the entity corresponding to a plurality of events enacted by the entity; associating the plurality of events enacted by the entity with a story; and, using the story to derive an inference regarding the entity.

Claims (58)

1. A computer-implementable method for generating and managing an adaptive trust profile, comprising:

monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the entity comprising a user entity;

generating the adaptive trust profile based upon the plurality of actions of the entity, the adaptive trust profile being generated by an adaptive trust profile system, the adaptive trust profile comprising a collection of information describing an identity of the entity, the adaptive trust profile system executing on a hardware processor of an information handling system;

determining, via the adaptive trust profile system, whether an event of the plurality of events enacted by the entity is of analytic utility, the event being of analytic utility indicating an entity behavior associated with the event represents a security risk;

generating, via the adaptive trust profile system, contextual information about the event based upon an entity profile, the contextual information comprising information relating to a particular entity behavior;

deriving, via the adaptive trust profile system, a meaning from the contextual information associated with the event, the meaning including an inference of an intent of the entity associated with the event; and,

updating, via the adaptive trust profile system, the adaptive trust profile of the entity based upon the contextual information about the event and the intent of the entity associated with the event.

2. The method of claim 1 , wherein:

the adaptive trust profile system comprises an event enrichment module, the event enrichment module performing an event enrichment operation.

3. The method of claim 1 , wherein:

the adaptive trust profile system comprises a meaning derivation module, the meaning derivation module performing a meaning derivation operation, the meaning derivation operation deriving the meaning from the contextualized information.

4. The method of claim 1 , wherein:

the adaptive trust profile system comprises a contextualization module, the contextualization module performing a contextualization operation, the contextualization operation generating the contextual information.

5. The method of claim 1 , wherein:

the adaptive trust profile system comprises an anomaly detection module, the anomaly detection module performing an anomaly detection operation.

6. The method of claim 5 , wherein:

the anomaly detection operation determines whether the event of the plurality of events is of analytic utility.

7. A system comprising:

a hardware processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code for generating and managing an adaptive trust profile, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the entity comprising a user entity;

generating the adaptive trust profile based upon the plurality of actions of the entity, the adaptive trust profile being generated by an adaptive trust profile system, the adaptive trust profile comprising a collection of information describing an identity of the entity, the adaptive trust profile system executing on the hardware processor of the system;

determining, via the adaptive trust profile system, whether an event of the plurality of events enacted by the entity is of analytic utility, the event being of analytic utility indicating an entity behavior associated with the event represents a security risk;

generating, via the adaptive trust profile system, contextual information about the event based upon an entity profile, the contextual information comprising information relating to a particular entity behavior;

deriving, via the adaptive trust profile system, a meaning from the contextualized information associated with the event, the meaning including an inference of an intent of the entity associated with the event; and,

updating, via the adaptive trust profile system, the adaptive trust profile of the entity based upon the contextual information about the event and the intent of the entity associated with the event.

8. The system of claim 7 , wherein:

the adaptive trust profile system comprises an event enrichment module, the event enrichment module performing an event enrichment operation.

9. The system of claim 7 , wherein:

the adaptive trust profile system comprises a meaning derivation module, the meaning derivation module performing a meaning derivation operation, the meaning derivation operation deriving the meaning from the contextualized information.

10. The system of claim 7 , wherein:

the adaptive trust profile system comprises a contextualization module, the contextualization module performing a contextualization operation, the contextualization operation generating the contextual information.

11. The system of claim 7 , wherein:

the adaptive trust profile system comprises an anomaly detection module, the anomaly detection module performing an anomaly detection operation.

12. The system of claim 1 , wherein:

the anomaly detection operation determines whether the event of the plurality of events is of analytic utility.

13. A non-transitory, computer-readable storage medium embodying computer program code for generating and managing an adaptive trust profile, the computer program code comprising computer executable instructions configured for:

monitoring a plurality of electronically-observable actions of an entity, the plurality of electronically-observable actions of the entity corresponding to a respective plurality of events enacted by the entity, the entity comprising a user entity;

generating the adaptive trust profile based upon the plurality of actions of the entity, the adaptive trust profile being generated by an adaptive trust profile system, the adaptive trust profile comprising a collection of information describing an identity of the entity, the adaptive trust profile system executing on a hardware processor of an information handling system;

determining, via the adaptive trust profile system, whether an event of the plurality of events enacted by the entity is of analytic utility, the event being of analytic utility indicating an entity behavior associated with the event represents a security risk;

generating, via the adaptive trust profile system, contextual information about the event based upon an entity profile, the contextual information comprising information relating to a particular entity behavior;

deriving, via the adaptive trust profile system, a meaning from the contextualized information associated with the event, the meaning including an inference of an intent of the entity associated with the event; and,

updating, via the adaptive trust profile system, the adaptive trust profile of the entity based upon the contextual information about the event and the intent of the entity associated with the event.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the adaptive trust profile system comprises an event enrichment module, the event enrichment module performing an event enrichment operation.

15. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the adaptive trust profile system comprises a meaning derivation module, the meaning derivation module performing a meaning derivation operation, the meaning derivation operation deriving the meaning from the contextualized information.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the adaptive trust profile system comprises a contextualization module, the contextualization module performing a contextualization operation, the contextualization operation generating the contextual information.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the adaptive trust profile system comprises an anomaly detection module, the anomaly detection module performing an anomaly detection operation.

18. The non-transitory, computer-readable storage medium of claim 17 , wherein:

the anomaly detection operation determines whether the event of the plurality of events is of analytic utility.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2022
From: FORD, RICHARD A.
To: FORCEPOINT LLC
Reel/Frame 061297/0802 →
Continuity (8)
Continuation 17089776 · Nov 5, 2020
Continuation 16428815 · May 31, 2019
Division 16162655 · Oct 17, 2018
Continuation 15963729 · Apr 26, 2018
Continuation In Part 15878898 · Jan 24, 2018
Continuation 15720788 · Sep 29, 2017
Provisional Application 62506300 · May 15, 2017
Related Publication 20230021936A1 · Jan 26, 2023