IP Library Granted Patent US 12,513,172
Granted Patent B2
US 12,513,172 · App. 18/194,181 · Granted Dec 30, 2025

Systems and methods for identity management

Inventors: Avi Chesla (Tel Aviv, IL); Sivan Omer (Tel Aviv, IL)
Assignee: Cybereason Inc.
H04L63/1425H04L63/1416H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,172
App. No.
18/194,181
Granted
Dec 30, 2025
Kind
B2
Abstract

Disclosed is a computer-implemented method for correlating user information can include receiving, from a user device, a login log associated with a user; receiving an intrusion detection system (IDS) log; receiving a domain name system (DNS) log; receiving, from a computing device, a log; enriching at least one of the login log, the IDS log, or the DNS log; and correlating an identity with one or more of the login log, the IDS log, and the DNS log. In some embodiments, correlating the identity with one or more of the login log, the IDS log, and the DNS log can include generating a graph representation and saving the graph representation as a sparse graph representation.

Claims (37)

1 . A computer-implemented method for correlating user information comprising:

receiving, from a user device, a login log associated with a user;

receiving an intrusion detection system (IDS) log;

receiving a domain name system (DNS) log;

receiving, from a computing device, an application log;

enriching at least one of the login log, the IDS log, or the DNS log, wherein enriching at least one of the login log, the IDS log, or the DNS log comprises enriching the application log with a hostname associated with the DNS log, a first IP address associated with the IDS log, and a second IP address associated with the DNS log;

correlating an identity with one or more of the login log, the IDS log, and the DNS log; and

executing a response action via at least one of a network device, an identity management system, an email system, or a cloud workspace application to address a detected threat associated with the correlated identity.

2 . The computer-implemented method of claim 1 , wherein correlating the identity with one or more of the login log, the IDS log, and the DNS log comprises generating a graph representation and saving the graph representation as a sparse graph representation.

3 . The computer-implemented method of claim 2 , wherein receiving the login log comprises receiving at least one of a username and an internet protocol (IP) address.

4 . The computer-implemented method of claim 3 , wherein receiving the IDS log comprises receiving at least one of an IP address and the hostname.

5 . The computer-implemented method of claim 4 , wherein the IP address is the first IP address and receiving the DNS log comprises receiving the hostname and the second IP address.

6 . The computer-implemented method of claim 5 , wherein receiving the log comprises receiving at least one of an email address and the username.

7 . The computer-implemented method of claim 6 , wherein enriching at least one of the login log, the IDS log, or the DNS log comprises enriching the IDS log with the username.

8 . The computer-implemented method of claim 5 , wherein the graph representation comprises a plurality of nodes, wherein each node is associated with one of the identity, the first IP address, the second IP address, the username, the hostname, and the email address.

9 . The computer-implemented method of claim 1 comprising:

receiving at least one of keystroke information, ad analysis information, and browser fingerprinting information; and

correlating the at least one of keystroke information, ad analysis information, and browser fingerprinting information with the identity.

10 . A computer-implemented method for correlating user information comprising:

receiving, from a user device, a login log associated with a user;

receiving an intrusion detection system (IDS) log;

receiving a domain name system (DNS) log;

receiving, from the user device, an application log;

enriching at least one of the login log, the IDS log, or the DNS log, wherein enriching at least one of the login log, the IDS log, or the DNS log comprises enriching the application log with a hostname associated with the DNS log, a first IP address associated with the IDS log, and a second IP address associated with the DNS log;

receiving a second DNS log;

correlating an identity with one or more of the login log, the IDS log, and the DNS log; and

executing a response action via at least one of a network device, an identity management system, an email system, or a cloud workspace application to address a detected threat associated with the correlated identity.

11 . The computer-implemented method of claim 10 , wherein correlating the identity with one or more of the login log, the IDS log, and the DNS log comprises generating a graph representation and saving the graph representation as a sparse graph representation.

12 . The computer-implemented method of claim 10 , wherein receiving the login log comprises receiving at least one of a username and an internet protocol (IP) address.

13 . The computer-implemented method of claim 12 , wherein receiving the IDS log comprises receiving at least one of an IP address and the hostname.

14 . The computer-implemented method of claim 13 , wherein the IP address is the first IP address and receiving the DNS log comprises receiving the hostname and the second IP address.

15 . The computer-implemented method of claim 14 , wherein receiving the application log comprises receiving at least one of an email address and the username.

16 . The computer-implemented method of claim 15 , wherein enriching at least one of the login log, the IDS log, or the DNS log comprises enriching the IDS log with the username.

17 . The computer-implemented method of claim 14 , wherein receiving the second DNS log comprises receiving a second hostname and the second IP address.

18 . The computer-implemented method of claim 10 comprising:

receiving at least one of keystroke information, ad analysis information, and browser fingerprinting information; and

correlating the at least one of keystroke information, ad analysis information, and browser fingerprinting information with the identity.

Assignments (3)
SECURITY INTEREST Recorded Apr 9, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: ANKURA TRUST COMPANY, LLC
Reel/Frame 075375/0297 →
SECURITY INTEREST Recorded Apr 7, 2026
From: CYBEREASON INC.; ALERT LOGIC, LLC
To: AT&T ENTERPRISES, LLC
Reel/Frame 075377/0304 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2023
From: CHESLA, AVI; OMER, SIVAN
To: CYBEREASON INC.
Reel/Frame 064847/0650 →
Continuity (2)
Provisional Application 63362271 · Mar 31, 2022
Related Publication 20230319088A1 · Oct 5, 2023
References Cited (19)
US 12086808B1 · Shahidzadeh · 2024 [cited by examiner]
US 12095794B1 · Karaje · 2024 [cited by examiner]
US 12095796B1 · Godefroid · 2024 [cited by examiner]
US 12099492B1 · Bagga · 2024 [cited by examiner]
US 12126643B1 · Skarphedinsson · 2024 [cited by examiner]
US 12130878B1 · Nanduri · 2024 [cited by examiner]
US 20020083343A1 · Crosbie · 2002 [cited by examiner]
US 20170344318A1 · Kawasaki · 2017 [cited by examiner]
US 20200004957A1 · Chamaraju · 2020 [cited by examiner]
US 20200336508A1 · Srivastava · 2020 [cited by examiner]
US 20210084071A1 · Mandrychenko · 2021 [cited by examiner]
US 20220400130A1 · Kapoor · 2022 [cited by examiner]
US 20230239313A1 · Peters · 2023 [cited by examiner]
US 20230254330A1 · Singh · 2023 [cited by examiner]
US 20240273158A1 · Kol · 2024 [cited by examiner]
US 20240314169A1 · Azad · 2024 [cited by examiner]
US 20240356986A1 · Crabtree · 2024 [cited by examiner]
US 20240430328A1 · Robinson · 2024 [cited by examiner]
US 20250016202A1 · Crabtree · 2025 [cited by examiner]