IP Library Granted Patent US 9,589,299
Granted Patent B2
US 9,589,299 · App. 15/151,904 · Granted Mar 7, 2017

Systems and user interfaces for dynamic and interactive investigation of bad actor behavior based on automatic clustering of related data in various data structures

Inventors: Alexander Visbal (New York, NY); James Thompson (San Francisco, CA); Marvin Sum (Sunnyvale, CA); Jason Ma (Mountain View, CA); Bing Jie Fu (Redwood City, CA); Ilya Nepomnyashchiy (Mountain View, CA); Devin Witherspoon (Palo Alto, CA); Victoria Lai (Palo Alto, CA); Steven Berler (Menlo Park, CA); Alexei Smaliy (Palo Alto, CA); Suchan Lee (Redwood City, CA)
Assignee: PALANTIR TECHNOLOGIES INC.
G06Q40/00G06F3/0482G06F3/04842G06F17/30601G06F12/1036G06F17/30716G06F17/30991G06K9/6218G06K9/6253
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,589,299
App. No.
15/151,904
Granted
Mar 7, 2017
Kind
B2
Abstract

Embodiments of the present disclosure relate to a data analysis system that may automatically generate memory-efficient clustered data structures, automatically analyze those clustered data structures, automatically tag and group those clustered data structures, and provide results of the automated analysis and grouping in an optimized way to an analyst. The automated analysis of the clustered data structures (also referred to herein as data clusters) may include an automated application of various criteria or rules so as to generate a tiled display of the groups of related data clusters such that the analyst may quickly and efficiently evaluate the groups of data clusters. In particular, the groups of data clusters may be dynamically re-grouped and/or filtered in an interactive user interface so as to enable an analyst to quickly navigate among information associated with various groups of data clusters and efficiently evaluate those data clusters in the context of, for example, a fraud investigation.

Claims (69)

1. A computer system comprising:

one or more non-transitory computer readable storage devices configured to store:

a plurality of computer executable instructions; and

a plurality of data clusters, each data cluster including a respective one or more data items and associated metadata, each data cluster further associated with a respective one or more tag types and a respective tag value for each of the one or more tag types; and

one or more hardware computer processors in communication with the one or more non-transitory computer readable storage devices and configured to execute the plurality of computer executable instructions in order to:

generate user interface data for rendering a user interface on a computing device, the user interface including one or more selectable elements useable by a user for indicating a tag type;

in response to receiving an indication of a first tag type, update the user interface data such that the user interface further includes a plurality of first tiles, wherein:

the plurality of first tiles are arranged across a portion of the user interface,

each of the first tiles represents a different tag value of the first tag type,

each of the first tiles displays a time-based graph showing events associated with data clusters associated with the respective tag values of the respective first tiles,

each of the time-based graphs of the first tiles includes at least one common axis and a common range for the at least one common axis; and

in response to selection of a tile of the plurality of first tiles, update the user interface data such that, in the user interface, the time-based graph associated with the selected tile is resized to be displayed entirely horizontally across the portion of the user interface while maintaining the common axis and common range previously displayed by the selected tile.

2. The computer system of claim 1 , wherein the one or more hardware computer processors are further configured to execute the plurality of computer executable instructions in order to:

for each data cluster of the plurality of data clusters:

determine a data cluster type associated with the data cluster;

associate one or more tag types with the data cluster based on data cluster tagging rules associated with the determined data cluster type; and

for each tag type of the one or more tags types, associate at least one tag value with the tag type based at least in part on one or more data items of the data cluster.

3. The computer system of claim 1 , wherein associating one or more tag types with the particular data cluster comprises:

determining one or more tag types associated with the data cluster type.

4. The computer system of claim 3 , wherein associating one or more tag types with the particular data cluster further comprises:

analyzing the particular data cluster to identify one or more tag values to associate with at least one of the one or more tag types.

5. The computer system of claim 1 , wherein each of the first tiles indicates a number of critical alerts associated with the respective first tiles.

6. The computer system of claim 1 , wherein the plurality of first tiles are arranged in the portion of the user interface in order of number of critical alerts.

7. The computer system of claim 1 , wherein the plurality of first tiles are colored to represent a tag value having more or fewer critical alerts.

8. The computer system of claim 1 , wherein the time-based graphs represent a merger or aggregation of a plurality of data items associated with data clusters associated with the respective tag values of the respective first tiles.

9. The computer system of claim 1 , wherein the interactive user interface further includes one or more selectable filter criteria, wherein the one or more hardware computer processors are further configured to execute the plurality of computer executable instructions in order to:

filter the plurality of data clusters based on one or more filter criteria.

10. The computer system of claim 9 , wherein the one or more hardware computer processors are further configured to execute the plurality of computer executable instructions in order to:

receive an indication of the one or more filter criteria via a user selection of at least one of the one or more selectable filter criteria.

11. The computer system of claim 9 , wherein the one or more selectable filter criteria include at least one of a tag value, a cluster type, or a state.

12. The computer system of claim 11 , wherein the one or more hardware computer processors are further configured to execute the plurality of computer executable instructions in order to:

further in response to receiving the indication of the first tag type:

identify one or more data clusters associated with the first tag type; and

generate a plurality of first groups of the one or more identified data clusters, wherein each of the first groups is associated with a different common tag value of the first tag type.

13. The computer system of claim 12 , wherein:

filtering the plurality of data clusters comprises determining a subset of data clusters of the plurality of data clusters satisfying the one or more filter criteria, and

generating the plurality of first groups of the plurality of data clusters is based on the subset of data clusters.

14. The computer system of claim 9 , wherein filter criteria of the one or more filter criteria of the same type are applied disjunctively when filtering the plurality of data clusters.

15. The computer system of claim 14 , wherein filter criteria of the one or more filter criteria of different types are applied conjunctively when filtering the plurality of data clusters.

16. The computer system of claim 1 , wherein the one or more hardware computer processors are further configured to execute the plurality of computer executable instructions in order to:

determine the one or more selectable elements based on one or more tag types associated with a type of investigation to be performed by the user.

17. The computer system of claim 1 , wherein the user interface further includes one or more selectable assignable states, wherein the one or more hardware computer processors are further configured to execute the plurality of computer executable instructions in order to:

receive an indication of one of the assignable states via a user selection of one of the one or more selectable assignable states;

associate one or more groups of data clusters with the indicated one of the assignable states.

18. A computer-implemented method comprising:

by one or more hardware processors executing computer executable instructions:

communicate with a data store configured to store a plurality of data clusters, each data cluster including a respective one or more data items and associated metadata, each data cluster further associated with a respective one or more tag types and a respective tag value for each of the one or more tag types;

generate user interface data for rendering a user interface on a computing device, the user interface including one or more selectable elements useable by a user for indicating a tag type;

in response to receiving an indication of a first tag type, update the user interface data such that the user interface further includes a plurality of first tiles, wherein:

the plurality of first tiles are arranged across a portion of the user interface,

each of the first tiles represents a different tag value of the first tag type,

each of the first tiles displays a time-based graph showing events associated with data clusters associated with the respective tag values of the respective first tiles,

each of the time-based graphs of the first tiles includes at least one common axis and a common range for the at least one common axis; and

in response to selection of a tile of the plurality of first tiles, update the user interface data such that, in the user interface, the time-based graph associated with the selected tile is resized to be displayed entirely horizontally across the portion of the user interface while maintaining the common axis and common range previously displayed by the selected tile.

19. The computer-implemented method of claim 18 further comprising:

by one or more hardware processors executing computer executable instructions:

for each data cluster of the plurality of data clusters:

determine a data cluster type associated with the data cluster;

associate one or more tag types with the data cluster based on data cluster tagging rules associated with the determined data cluster type; and

for each tag type of the one or more tags types, associate at least one tag value with the tag type based at least in part on one or more data items of the data cluster.

20. A non-transitory computer-readable storage medium having program instructions embodied therewith, the program instructions executable by one or more processors to cause the one or more processors to:

communicate with a data store configured to store a plurality of data clusters, each data cluster including a respective one or more data items and associated metadata, each data cluster further associated with a respective one or more tag types and a respective tag value for each of the one or more tag types;

generate user interface data for rendering a user interface on a computing device, the user interface including one or more selectable elements useable by a user for indicating a tag type;

in response to receiving an indication of a first tag type, update the user interface data such that the user interface further includes a plurality of first tiles, wherein:

the plurality of first tiles are arranged across a portion of the user interface,

each of the first tiles represents a different tag value of the first tag type,

each of the first tiles displays a time-based graph showing events associated with data clusters associated with the respective tag values of the respective first tiles,

each of the time-based graphs of the first tiles includes at least one common axis and a common range for the at least one common axis; and

in response to selection of a tile of the plurality of first tiles, update the user interface data such that, in the user interface, the time-based graph associated with the selected tile is resized to be displayed entirely horizontally across the portion of the user interface while maintaining the common axis and common range previously displayed by the selected tile.

Assignments (8)
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2016
From: VISBAL, ALEXANDER; THOMPSON, JAMES; SUM, MARVIN; MA, JASON; FU, BING JIE; NEPOMNYASHCHIY, ILYA; WITHERSPOON, DEVIN; LAI, VICTORIA; BERLER, STEVEN; SMALIY, ALEXEI; LEE, SUCHAN
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 039544/0423 →
Continuity (2)
Continuation 14579752 · Dec 22, 2014
Related Publication 20160253750A1 · Sep 1, 2016