IP Library Granted Patent US 12,192,225
Granted Patent B2
US 12,192,225 · App. 17/991,025 · Granted Jan 7, 2025

Security analytics system for performing a non-sanctioned entity interaction analysis operation when determining entity risk

Inventors: Margaret Cunningham (Austin, TX); Peter Lochlan Stewart (Rowlett, TX)
Assignee: Forcepoint Federal Holdings LLC
H04L63/1433G06F40/30H04L63/102H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,225
App. No.
17/991,025
Granted
Jan 7, 2025
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for performing entity interaction risk analysis operation. The entity interaction risk analysis operation includes: monitoring an entity, the monitoring observing an electronically-observable data source; identifying an interaction between the entity and another entity based upon the monitoring; analyzing the interaction between the entity and the another entity; determining whether the interaction between the entity and the another entity is non-sanctioned; and, performing a security operation in response to the analyzing the interaction and the determining whether the interaction is non-sanctioned.

Claims (55)

1. A computer-implementable method for performing an entity interaction risk analysis operation, comprising:

monitoring an entity, the monitoring observing an electronically-observable data source;

identifying an interaction between the entity and another entity based upon the monitoring, the entity being included within a first entity group;

analyzing the interaction between the entity and the another entity;

determining whether the interaction between the entity and the another entity is a non-sanctioned entity interaction, the non-sanctioned entity interaction comprising an interaction between the entity and the another entity whose enactment does not comply with a policy instituted by the first entity group; and,

performing a security operation via a security analytics system in response to the analyzing the interaction when the interaction is non-sanctioned, the security operation being performed by at least one of an endpoint device and the security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing the security operation on a hardware processor associated with the security analytics system.

2. The method of claim 1 , wherein:

the another entity comprises an information source.

3. The method of claim 2 , wherein:

the analyzing includes identifying a trending topic and determining whether the information source includes the trending topic.

4. The method of claim 3 , wherein:

the analyzing includes generating an amplification factor based upon whether the information source includes the trending topic.

5. The method of claim 1 , wherein:

the analyzing includes determining an affect associated with the interaction between the entity and the another entity.

6. The method of claim 5 , wherein:

the affect is determined using at least one of a sentiment analysis operation and a pattern analysis operation.

7. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

monitoring an entity, the monitoring observing an electronically-observable data source, the entity being included within a first entity group;

identifying an interaction between the entity and another entity based upon the monitoring;

analyzing the interaction between the entity and the another entity;

determining whether the interaction between the entity and the another entity is a non-sanctioned entity interaction, the non-sanctioned entity interaction comprising an interaction between the entity and the another entity whose enactment does not comply with a policy instituted by the first entity group; and,

performing a security operation via a security analytics system in response to the analyzing the interaction when the interaction is non-sanctioned, the security operation being performed by at least one of an endpoint device and the security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing the security operation on a hardware processor associated with the security analytics system.

8. The system of claim 7 , wherein:

the another entity comprises an information source.

9. The system of claim 8 , wherein:

the analyzing includes identifying a trending topic and determining whether the information source includes the trending topic.

10. The system of claim 9 , wherein:

the analyzing includes generating an amplification factor based upon whether the information source includes the trending topic.

11. The system of claim 7 , wherein:

the analyzing includes determining an affect associated with the interaction between the entity and the another entity.

12. The system of claim 11 , wherein:

the affect is determined using at least one of a sentiment analysis operation and a pattern analysis operation.

13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

monitoring an entity, the monitoring observing an electronically-observable data source;

identifying an interaction between the entity and another entity based upon the monitoring, the entity being included within a first entity group;

analyzing the interaction between the entity and the another entity;

determining whether the interaction between the entity and the another entity is a non-sanctioned entity interaction, the non-sanctioned entity interaction comprising an interaction between the entity and the another entity whose enactment does not comply with a policy instituted by the first entity group; and,

performing a security operation via a security analytics system in response to the analyzing the interaction when the interaction is non-sanctioned, the security operation being performed by at least one of an endpoint device and the security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing the security operation on a hardware processor associated with the security analytics system.

14. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the another entity comprises an information source.

15. The non-transitory, computer-readable storage medium of claim 14 , wherein:

the analyzing includes identifying a trending topic and determining whether the information source includes the trending topic.

16. The non-transitory, computer-readable storage medium of claim 15 , wherein:

the analyzing includes generating an amplification factor based upon whether the information source includes the trending topic.

17. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the analyzing includes determining an affect associated with the interaction between the entity and the another entity.

18. The non-transitory, computer-readable storage medium of claim 17 , wherein:

the affect is determined using at least one of a sentiment analysis operation and a pattern analysis operation.

19. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

20. The non-transitory, computer-readable storage medium of claim 13 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (5)
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070588/0074 →
PARTIAL PATENT RELEASE AND REASSIGNMENT AT REEL/FRAME 055052/0302 Recorded Oct 3, 2023
From: CREDIT SUISSE, AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
To: FORCEPOINT FEDERAL HOLDINGS LLC (F/K/A FORCEPOINT LLC)
Reel/Frame 065103/0147 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2023
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 063446/0418 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2022
From: CUNNINGHAM, MARGARET; STEWART, PETER LOCHLAN
To: FORCEPOINT LLC
Reel/Frame 061839/0672 →
Continuity (2)
Provisional Application 63294992 · Dec 30, 2021
Related Publication 20230216877A1 · Jul 6, 2023
References Cited (11)
US 9589245B2 · Coden · 2017 [cited by examiner]
US 11559747B1 · Hirsch · 2023 [cited by examiner]
US 11651313B1 · Fridakis · 2023 [cited by examiner]
US 12095778B2 · Thomas · 2024 [cited by examiner]
US 20150373043A1 · Wang · 2015 [cited by examiner]
US 20160065603A1 · Dekel · 2016 [cited by examiner]
US 20170034179A1 · Carames · 2017 [cited by examiner]
US 20190036971A1 · Ford · 2019 [cited by examiner]
US 20200220885A1 · Will · 2020 [cited by examiner]
US 20200329066A1 · Kirti · 2020 [cited by examiner]
US 20210084063A1 · Triantafillos · 2021 [cited by examiner]