IP Library Granted Patent US 12,657,309
Granted Patent B2
US 12,657,309 · App. 18/346,156 · Granted Jun 16, 2026

Delivering augmented threat assessment values to a security threat management facility

Inventors: Areg Alimian (Woodland Hills, CA); Ryan Matthew Knotts (San Jose, CA); Kanav Gandhi (Mountain View, CA)
Assignee: Box, Inc.
G06F21/577H04L63/1425H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,657,309
App. No.
18/346,156
Granted
Jun 16, 2026
Kind
B2
Abstract

Methods, systems, and computer program products for content management systems. Multiple components are operatively interconnected to carry out operations for content management systems. A security threat management facility (STMF) is identified. The STMF contains a database of threat assessment values in addition to further information pertaining to one or more users. Concurrent with operation of the STMF, a content management system (CMS) tracks user-initiated content object interaction events. Based on analysis of the tracked user-initiated content object interaction events, a further threat assessment value is generated by the CMS. Such a further threat assessment is determined based on one or more user-to-user relationships or one or more user-to-file relationships as determined at the content management system. An augmented threat assessment is formed using both the threat assessment values of the STMF with the further threat assessment value from the CMS. The augmented threat assessment is then provided to the STMF.

Claims (34)

1 . A method for augmenting a database of threat assessment values, the method comprising:

identifying a database of threat assessment values at a security threat management facility (STMF), wherein the threat assessment values include at least information pertaining to one or more users;

operating a content management system (CMS) that tracks user-initiated content object interaction events;

generating a further threat assessment value at the content management system, wherein the further threat assessment value is determined based at least in part on one of at least one of (A) one or more user-to-user relationships or (B) one or more user-to-file relationships as determined at the content management system; and

establishing an augmented threat assessment using both the threat assessment values of the STMF with the further threat assessment value from the content management system, wherein the augmented threat assessment is increased if a suspect user has a scheduled termination date.

2 . The method of claim 1 , further comprising, providing the augmented threat assessment to the STMF.

3 . The method of claim 1 , wherein the user-to-user relationships are based on user-to-file interaction events by two or more user devices.

4 . The method of claim 3 , wherein at least one of the two or more user devices participates in an anomalous download.

5 . The method of claim 3 , wherein the STMF comprises a third-party application, or wherein the STMF comprises a module within the content management system.

6 . The method of claim 1 , wherein the STMF is separate from the content management system.

7 . The method of claim 1 , wherein the augmented threat assessment is increased if a suspect user is accessing the same files as a user from a different department.

8 . A non-transitory computer readable medium having stored thereon a sequence of instructions which, when stored in memory and executed by one or more processors causes the one or more processors to perform a set of acts for augmenting a database of threat assessment values, the set of acts comprising:

identifying a database of threat assessment values at a security threat management facility (STMF), wherein the threat assessment values include at least information pertaining to one or more users;

operating a content management system (CMS) that tracks user-initiated content object interaction events;

generating a further threat assessment value at the content management system, wherein the further threat assessment value is determined based at least in part on one of at least one of (A) one or more user-to-user relationships or (B) one or more user-to-file relationships as determined at the content management system; and

establishing an augmented threat assessment using both the threat assessment values of the STMF with the further threat assessment value from the content management system, wherein the augmented threat assessment is increased if a suspect user has a scheduled termination date.

9 . The non-transitory computer readable medium of claim 8 , further comprising instructions which, when stored in memory and executed by the one or more processors causes the one or more processors to perform acts of, providing the augmented threat assessment to the STMF.

10 . The non-transitory computer readable medium of claim 8 , wherein the user-to-user relationships are based on user-to-file interaction events by two or more user devices.

11 . The non-transitory computer readable medium of claim 10 , wherein at least one of the two or more user devices participates in an anomalous download.

12 . The non-transitory computer readable medium of claim 10 , wherein the STMF comprises a third-party application, or wherein the STMF comprises a module within the content management system.

13 . The non-transitory computer readable medium of claim 8 , wherein the STMF is separate from the content management system.

14 . The non-transitory computer readable medium of claim 8 , wherein the augmented threat assessment is increased if a suspect user is accessing the same files as a user from a different department.

15 . A system for augmenting a database of threat assessment values, the system comprising:

a storage medium having stored thereon a sequence of instructions; and

one or more processors that execute the sequence of instructions to cause the one or more processors to perform a set of acts, the set of acts comprising,

identifying a database of threat assessment values at a security threat management facility (STMF), wherein the threat assessment values include at least information pertaining to one or more users;

operating a content management system (CMS) that tracks user-initiated content object interaction events;

generating a further threat assessment value at the content management system, wherein the further threat assessment value is determined based at least in part on one of at least one of (A) one or more user-to-user relationships or (B) one or more user-to-file relationships as determined at the content management system; and

establishing an augmented threat assessment using both the threat assessment values of the STMF with the further threat assessment value from the content management system, wherein the augmented threat assessment is increased if a suspect user has a scheduled termination date.

16 . The system of claim 15 , further comprising, providing the augmented threat assessment to the STMF.

17 . The system of claim 15 , wherein the user-to-user relationships are based on user-to-file interaction events by two or more user devices.

18 . The system of claim 17 , wherein at least one of the two or more user devices participates in an anomalous download.

19 . The system of claim 17 , wherein the STMF comprises a third-party application, or wherein the STMF comprises a module within the content management system.

20 . The system of claim 15 , wherein the STMF is separate from the content management system.

Continuity (2)
Provisional Application 63413210 · Oct 4, 2022
Related Publication 20240111877A1 · Apr 4, 2024
References Cited (18)
US 10686816B1 · Shintre · 2020 [cited by examiner]
US 11483386B1 · Huang et al. · 2022 [cited by applicant]
US 20100063868A1 · Bird et al. · 2010 [cited by applicant]
US 20160191465A1 · Thomas et al. · 2016 [cited by applicant]
US 20200089892A1 · Ojha · 2020 [cited by applicant]
US 20240111877A1 · Ian et al. · 2024 [cited by applicant]
US 20240114056A1 · Alim et al. · 2024 [cited by applicant]
EP 3854047B1 · 2024 [cited by examiner]
Crowdstrike, 2023 Global Threat Report, dated 2023. [cited by applicant]
Kaspersky, “Machine Learning for Malware Detection”, Date retrieved from google, Nov. 17, 2017. [cited by applicant]
Kulkarni, “Taking Security to the Next Level: CrowdStrike Now Analyzes over 100 Billion Events Per Day”, Crowdstrike Blog, dated May 23, 2018. [cited by applicant]
Box Support, Introducing modifiable retention policies in Box Governance !. dated Jul. 14, 2022. [cited by applicant]
Box, The Content Cloud, Secure content management and collaboration, date found via Internet Archive as Feb. 2, 2023. [cited by applicant]
Foxit (When it Makes Sense to Watermark Your PDF Documents, May 31, 2019, 3 pages) (Year: 2019). [cited by applicant]
Non-Final Office Action dated Mar. 14, 2025 for related U.S. Appl. No. 18/346,137. [cited by applicant]
Final Office Action dated Jul. 3, 2025 for related U.S. Appl. No. 18/346,137. [cited by applicant]
Notice of Allowance date Sep. 23, 2025 for related U.S. Appl. No. 18/346,137. [cited by applicant]
Notice of Allowance dated Jan. 28, 2026 for related U.S. Appl. No. 18/346,137. [cited by applicant]