IP Library Patent Application 19019147
Patent Application
App. No. 19/019,147

INVESTIGATION OF THREATS USING QUERYABLE RECORDS OF BEHAVIOR

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/019,147
Abstract

Data of a digital communication account of a first user are parsed for one or more attributes of a series of digital activities including a first digital activity initially scored as non-malicious. Based on the parsed data, a searchable user communication digital profile is generated for the first user. The searchable user communication digital profile is searched based on a second digital activity and receiving a search result associated with the first digital activity. The first digital activity is rescored as malicious based on the search result. A security action associated with the rescored first digital activity is performed.

Claims (37)

1 . A system method comprising:

parsing data of a digital communication account of a first user for one or more attributes of a series of digital activities including a first digital activity initially scored as non-malicious;

based on the parsed data, generating a searchable user communication digital profile for the first user;

searching the searchable user communication digital profile based on a second digital activity and receiving a search result associated with the first digital activity;

rescoring the first digital activity as malicious based on the search result; and

performing a security action associated with the rescored first digital activity.

2 . The method of claim 1 , wherein the digital communication account is an email account associated with a collaboration suite.

3 . The method of claim 1 , wherein the digital communication account is an account associated with a messaging platform.

4 . The method of claim 1 , wherein the one or more attributes include at least one of: a source Internet Protocol (IP) address, a time of transmission, a geographical origin, a sender identity, a recipient identity, content, or presence of an attachment.

5 . The method of claim 1 , wherein generating the searchable user communication digital profile comprises training a machine learning model based on past digital activities associated with the first user to establish normal behavior for the first user.

6 . The method of claim 1 , wherein the searchable user communication digital profile includes records for digital activities initially scored as safe and digital activities initially scored as unsafe.

7 . The method of claim 1 , wherein the second digital activity comprises a third digital activity performed using the digital communication account or another digital communication account associated with the first user or a second user.

8 . The method of claim 1 , wherein rescoring the first digital activity as malicious is further based on input received from a security operations center (SOC) analyst interacting with an interface displaying the search result.

9 . The method of claim 1 , wherein the security action comprises at least one of: quarantining the first digital activity, deleting the first digital activity, notifying an administrator, restricting access for the digital communication account, resetting a password for the digital communication account, or terminating active sessions for the digital communication account.

10 . The method of claim 1 , wherein parsing data comprises obtaining the data via an Application Programming Interface (API) associated with the digital communication account.

11 . The method of claim 1 , wherein the search result identifies the first digital activity based on sharing one or more attributes with the second digital activity.

12 . A system comprising:

a processor configured to:

parse data of a digital communication account of a first user for one or more attributes of a series of digital activities including a first digital activity initially scored as non-malicious;

based on the parsed data, generate a searchable user communication digital profile for the first user;

search the searchable user communication digital profile based on a second digital activity and receiving a search result associated with the first digital activity;

rescore the first digital activity as malicious based on the search result; and

perform a security action associated with the rescored first digital activity; and

a memory coupled to the processor and configured to provide the processor with instructions.

13 . The system of claim 12 , wherein the digital communication account is an account associated with a messaging platform or a collaboration suite.

14 . The system of claim 12 , wherein the one or more attributes include at least one of: a source Internet Protocol (IP) address, a time of transmission, a geographical origin, a sender identity, a recipient identity, content, or presence of an attachment.

15 . The system of claim 12 , wherein generating the searchable user communication digital profile comprises training a machine learning model based on past digital activities associated with the first user to establish normal behavior for the first user.

16 . The system of claim 12 , wherein the searchable user communication digital profile includes records for digital activities initially scored as safe and digital activities initially scored as unsafe.

17 . The system of claim 12 , wherein the second digital activity comprises a third digital activity performed using the digital communication account or another digital communication account associated with the first user or a second user.

18 . The system of claim 12 , wherein rescoring the first digital activity as malicious is further based on input received from a security operations center (SOC) analyst interacting with an interface displaying the search result.

19 . The system of claim 12 , wherein the security action comprises at least one of: quarantining the first digital activity, deleting the first digital activity, notifying an administrator, restricting access for the digital communication account, resetting a password for the digital communication account, or terminating active sessions for the digital communication account.

20 . A computer program product, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

parsing data of a digital communication account of a first user for one or more attributes of a series of digital activities including a first digital activity initially scored as non-malicious;

based on the parsed data, generating a searchable user communication digital profile for the first user;

searching the searchable user communication digital profile based on a second digital activity and receiving a search result associated with the first digital activity;

rescoring the first digital activity as malicious based on the search result; and

performing a security action associated with the rescored first digital activity.