IP Library Granted Patent US 12,189,783
Granted Patent B2
US 12,189,783 · App. 17/991,022 · Granted Jan 7, 2025

Security analytics system for performing a risk analysis operation taking into account social behavior peer grouping

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,189,783
App. No.
17/991,022
Granted
Jan 7, 2025
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for performing entity interaction risk analysis operation. The entity interaction risk analysis operation includes: monitoring an entity, the monitoring observing an electronically-observable data source; identifying an interaction between the entity and another entity based upon the monitoring; analyzing the interaction between the entity and the another entity; and, performing a security operation in response to the analyzing the interaction.

Claims (58)

1. A computer-implementable method for performing an entity interaction risk analysis operation, comprising:

monitoring an entity, the monitoring observing an electronically-observable data source;

identifying a security related activity associated with the entity, the security related activity comprising a concerning behavior, the concerning behavior comprising a corresponding concerning behavior score,

identifying an interaction between the entity and another entity based upon the monitoring;

analyzing the interaction between the entity and the another entity;

generating a user behavior score based upon the corresponding concerning behavior score and the analyzing the interaction between the entity and the another entity; and,

performing a security operation via a security analytics system based upon the user behavior score, the security operation being performed by at least one of an endpoint device and the security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing the security operation on a hardware processor associated with the security analytics system.

2. The method of claim 1 , wherein:

the analyzing includes generating an interaction factor based upon the interaction between the entity and the another entity and the security related activity.

3. The method of claim 1 , wherein:

the analyzing includes generating an amplification factor based upon the interaction between the entity and the another entity and the security related activity.

4. The method of claim 1 , wherein:

the analyzing includes generating a social interaction factor based upon the interaction between the entity and the another entity and the security related activity.

5. The method of claim 1 , wherein:

the interaction between the entity and the another entity is identified based upon a type of interaction between the entity and the another entity.

6. The method of claim 5 , wherein:

the type of interaction includes at least one of a collaboration interaction, a team interaction, a parallel peer interaction and a geographic interaction.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring an entity, the monitoring observing an electronically-observable data source;

identifying a security related activity associated with the entity, the security related activity comprising a concerning behavior, the concerning behavior comprising a corresponding concerning behavior score,

identifying an interaction between the entity and another entity based upon the monitoring;

analyzing the interaction between the entity and the another entity;

generating a user behavior score based upon the corresponding concerning behavior score and the analyzing the interaction between the entity and the another entity; and,

performing a security operation via a security analytics system based upon the user behavior score, the security operation being performed by at least one of an endpoint device and the security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing the security operation on a hardware processor associated with the security analytics system.

8. The system of claim 7 , wherein:

the analyzing includes generating an interaction factor based upon the interaction between the entity and the another entity and the security related activity.

9. The system of claim 7 , wherein:

the analyzing includes generating an amplification factor based upon the interaction between the entity and the another entity and the security related activity.

10. The system of claim 7 , wherein:

the analyzing includes generating a social interaction factor based upon the interaction between the entity and the another entity and the security related activity.

11. The system of claim 10 , wherein:

the interaction between the entity and the another entity is identified based upon a type of interaction between the entity and the another entity.

12. The system of claim 11 , wherein:

the type of interaction includes at least one of a collaboration interaction, a team interaction, a parallel peer interaction and a geographic interaction.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring an entity, the monitoring observing an electronically-observable data source;

identifying a security related activity associated with the entity, the security related activity comprising a concerning behavior, the concerning behavior comprising a corresponding concerning behavior score,

identifying an interaction between the entity and another entity based upon the monitoring;

analyzing the interaction between the entity and the another entity;

generating a user behavior score based upon the corresponding concerning behavior score and the analyzing the interaction between the entity and the another entity; and,

performing a security operation via a security analytics system based upon the user behavior score, the security operation being performed by at least one of an endpoint device and the security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing the security operation on a hardware processor associated with the security analytics system.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the analyzing includes generating an interaction factor based upon the interaction between the entity and the another entity and the security related activity.

15. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the analyzing includes generating an amplification factor based upon the interaction between the entity and the another entity and the security related activity.

16. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the analyzing includes generating a social interaction factor based upon the interaction between the entity and the another entity and the security related activity.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the interaction between the entity and the another entity is identified based upon a type of interaction between the entity and the another entity.

18. The non-transitory, computer-readable storage medium of claim 17 , wherein:

the type of interaction includes at least one of a collaboration interaction, a team interaction, a parallel peer interaction and a geographic interaction.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (5)
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070588/0074 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2023
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 063446/0418 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2022
From: CUNNINGHAM, MARGARET; STEWART, PETER L
To: FORCEPOINT LLC
Reel/Frame 061839/0635 →