IP Library Patent Application 19034525
Patent Application
App. No. 19/034,525

AUTOMATIC TRIAGING OF NETWORK EVENTS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/034,525
Abstract

Automatically triaging network events such as data loss prevention (DLP) incidents is disclosed. A system can automatically triage or classify an incident using a prediction model. The prediction model can determine the classification based on similar incidents that were previously classified. Similar incidents are those incidents having profiles that match a profile of the incident. The profile can include one or more attributes that are representative of an incident. The system can arrive at a specific classification for the incident based on a classification of the similar incidents if the similar incidents satisfy one or more conditions.

Claims (54)

1 . A method for automatic classification of a network event, the method comprising:

collecting, by a processor, network event data comprising:

afflicting content of the network event representative of a user activity violating a policy; and

non-afflicting content comprising metadata associated with the network event but not directly indicative of a policy violation;

hashing, by the processor, at least a portion of the non-afflicting content so as to generate a hash value of the non-afflicting content;

generating, by the processor, a network event profile for the network event, the network event profile including (i) the hash value and (ii) one or more attributes representative of the network event; and

obtaining, by the processor, via a prediction model, a classification based on the network event profile, the classification based on whether the network event profile matches any reference profile associated with network events, the reference profile including a reference hash value and one or more reference attributes representative of the network event.

2 . The method according to claim 1 , further comprising:

determining whether two network events are similar, wherein the determining comprises:

generating a respective network event profile for each respective network event of the two network events, the respective network event profile including an attribute representative of the respective network event; and

determining whether network event profiles of the two network events match based on whether the attribute representative of one of the two network events matches the attribute representative of another one of the two network events.

3 . The method according to claim 1 , further comprising:

providing classification result information about the classification for the network event to the prediction model as a reference feedback for updating the prediction model.

4 . The method according to claim 3 , wherein, responsive to the reference feedback, the prediction model is operable to assess its predictions against the classification result information and update its configuration based on an assessment result.

5 . The method according to claim 3 , wherein the classification result information comprises a prediction model performance indicator indicating whether the classification for the network event is correct or incorrect.

6 . The method according to claim 1 , further comprising:

updating a status attribute based on the classification for the network event, wherein the status attribute is one of the one or more attributes.

7 . The method according to claim 1 , wherein the policy comprises a data access policy that specifies the user activity as a data breach.

8 . A system for automatic classification of a network event, the system comprising:

a processor;

a non-transitory computer-readable medium; and

instructions stored on the non-transitory computer-readable medium and translatable by the processor for:

collecting network event data comprising:

afflicting content of the network event representative of a user activity violating a policy; and

non-afflicting content comprising metadata associated with the network event but not directly indicative of a policy violation;

hashing at least a portion of the non-afflicting content so as to generate a hash value of the non-afflicting content;

generating a network event profile for the network event, the network event profile including (i) the hash value and (ii) one or more attributes representative of the network event; and

obtaining, via a prediction model, a classification based on the network event profile, the classification based on whether the network event profile matches any reference profile associated with network events, the reference profile including a reference hash value and one or more reference attributes representative of the network event.

9 . The system of claim 8 , wherein the instructions are further translatable by the processor for determining whether two network events are similar and wherein the determining comprises:

generating a respective network event profile for each respective network event of the two network events, the respective network event profile including an attribute representative of the respective network event; and

determining whether network event profiles of the two network events match based on whether the attribute representative of one of the two network events matches the attribute representative of another one of the two network events.

10 . The system of claim 8 , wherein the instructions are further translatable by the processor for

providing classification result information about the classification for the network event to the prediction model as a reference feedback for updating the prediction model.

11 . The system of claim 10 , wherein, responsive to the reference feedback, the prediction model is operable to assess its predictions against the classification result information and update its configuration based on an assessment result.

12 . The system of claim 10 , wherein the classification result information comprises a prediction model performance indicator indicating whether the classification for the network event is correct or incorrect.

13 . The system of claim 8 , wherein the instructions are further translatable by the processor for:

updating a status attribute based on the classification for the network event, wherein the status attribute is one of the one or more attributes.

14 . The system of claim 8 , wherein the policy comprises a data access policy that specifies the user activity as a data breach.

15 . A computer program product for automatic classification of a network event, the computer program product comprising a non-transitory computer-readable medium storing instructions translatable by a processor for:

collecting network event data comprising:

afflicting content of the network event representative of a user activity violating a policy; and

non-afflicting content comprising metadata associated with the network event but not directly indicative of a policy violation;

hashing at least a portion of the non-afflicting content so as to generate a hash value of the non-afflicting content;

generating a network event profile for the network event, the network event profile including (i) the hash value and (ii) one or more attributes representative of the network event; and

obtaining, via a prediction model, a classification based on the network event profile, the classification based on whether the network event profile matches any reference profile associated with network events, the reference profile including a reference hash value and one or more reference attributes representative of the network event.

16 . The computer program product of claim 15 , wherein the instructions are further translatable by the processor for determining whether two network events are similar and wherein the determining comprises:

generating a respective network event profile for each respective network event of the two network events, the respective network event profile including an attribute representative of the respective network event; and

determining whether network event profiles of the two network events match based on whether the attribute representative of one of the two network events matches the attribute representative of another one of the two network events.

17 . The computer program product of claim 15 , wherein the instructions are further translatable by the processor for:

providing classification result information about the classification for the network event to the prediction model as a reference feedback for updating the prediction model.

18 . The computer program product of claim 17 , wherein, responsive to the reference feedback, the prediction model is operable to assess its predictions against the classification result information and update its configuration based on an assessment result.

19 . The computer program product of claim 17 , wherein the classification result information comprises a prediction model performance indicator indicating whether the classification for the network event is correct or incorrect.

20 . The computer program product of claim 15 , wherein the policy comprises a data access policy that specifies the user activity as a data breach and wherein the instructions are further translatable by the processor for:

updating a status attribute based on the classification for the network event, wherein the status attribute is one of the one or more attributes.

Assignments (4)
INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Dec 9, 2025
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 073910/0027 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2025
From: ARMSTRONG, KYLE; BUTLER, SKYLER
To: INTELISECURE, INC.
Reel/Frame 070069/0011 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 31, 2025
From: INTELISECURE, INC.
To: PROOFPOINT, INC.
Reel/Frame 070069/0034 →