IP Library Granted Patent US 11,379,607
Granted Patent B2
US 11,379,607 · App. 16/217,802 · Granted Jul 5, 2022

Automatically generating security policies

Inventor: Brandon L. Swafford (Greenwich, CT)
Assignee: Forcepoint, LLC
G06F21/6245G06F11/3438G06F21/552G06F21/577G06F21/602G06F21/6254G06F21/84H04L63/1408H04L63/1425H04L63/1433H04L63/1441H04L67/025H04L67/141H04L67/146H04L67/22H04L67/306G06F2221/031G06F2221/032G06F2221/034H04L63/20H04L67/289H04L2209/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,379,607
App. No.
16/217,802
Granted
Jul 5, 2022
Kind
B2
Abstract

A system, method, and computer-readable medium are disclosed for generating security policies. Generating security policies includes gathering information related to an organization, the information related to the organization comprising electronically-observable information related to the organization; converting the electronically-observable information related to the organization into electronic information related to the organization; using the electronic information related to the organization to automatically generate a plurality of organization specific rules; and, generating an organization specific security policy, the organization specific security policy comprising at least one organization specific rule.

Claims (64)

1. A computer-implementable method for generating security policies, comprising:

gathering information related to an organization, the information related to the organization comprising electronically-observable information related to the organization, the monitoring being performed by a protected endpoint, the protected endpoint comprising an endpoint agent executing on an endpoint device, the endpoint agent comprising an entity-specific security policy feature pack,

converting the electronically-observable information related to the organization into electronic information related to the organization;

using the electronic information related to the organization to automatically generate a plurality of organization specific rules;

generating an organization specific security policy, the organization specific security policy comprising at least one organization specific rule, the organization specific security policy comprising an aggregation of a plurality of entity specific security policies, each of the plurality of entity specific security policies corresponding to a respective entity, each respective entity having a corresponding user profile, each corresponding user profile comprising a collection of information that uniquely describes an identify of the respective entity, the collection of information comprising a user profile attribute, a user behavior factor and a user mindset factor, the mindset factor comprising information used to determine a mental state of a user at a particular point in time; the organization specific security policy comprises a risk-adaptive security policy, the risk-adaptive security policy comprising a security policy implemented to be revised to adaptively remediate risk associated with a user behavior, the user behavior being represented via a plurality of risk-adaptive behavior factors, the plurality of risk-adaptive behavior factors comprising at least one user behavior factor and a user mindset factor and,

using the organization specific security policy to perform a security analytics operation, the security analytics operation identifying anomalous, abnormal, unexpected, or malicious user behavior, the security analytics operation being performed by a security analytics system, the security analytics system communicating with the protected endpoint via a network.

2. The method of claim 1 , further comprising:

monitoring electronically-observable user interactions, the electronically-observable user interactions comprising a corresponding user behavior, the information related to the organization comprising the user behavior;

converting the electronically-observable user interactions into electronic information representing the user behavior;

evolving the organization specific security policy according to the electronically observable user interactions, the evolving the organization specific security policy comprising revising rules associated with the organization specific security policy according to enactment of a user behavior corresponding to an event.

3. The method of claim 1 , wherein:

each of the plurality of entity-specific security policies comprise an automatically generated entity-specific rule.

4. The method of claim 1 , wherein:

the plurality of rules comprise a rule associated with an event, the rule associated with the event comprising an indication of whether to allow a particular entity to perform the event;

the organization specific security policy is associated with an entity; and,

the organization security policy is applied to the entity.

5. The method of claim 1 , wherein:

the generating the organization specific security policy comprises performing a machine learning operation; and,

performing the machine learning operation on the security policy trains the security policy to recognize a true positive occurrence, a false positive occurrence, a true negative occurrence, a false negative occurrence and an indeterminate occurrence of an event.

6. A system comprising:

a processor;

a data bus coupled to the processor; and

a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for:

gathering information related to an organization, the information related to the organization comprising electronically-observable information related to the organization, the monitoring being performed by a protected endpoint, the protected endpoint comprising an endpoint agent executing on an endpoint device, the endpoint agent comprising an entity-specific security policy feature pack;

converting the electronically-observable information related to the organization into electronic information related to the organization;

using the electronic information related to the organization to automatically generate a plurality of organization specific rules;

generating an organization specific security policy, the organization specific security policy comprising at least one organization specific rule, the organization specific security policy comprising an aggregation of a plurality of entity specific security policies, each of the plurality of entity specific security policies corresponding to a respective entity, each respective entity having a corresponding user profile, each corresponding user profile comprising a collection of information that uniquely describes an identify of the respective entity, the collection of information comprising a user profile attribute, a user behavior factor and a user mindset factor, the mindset factor comprising information used to determine a mental state of a user at a particular point in time; the organization specific security policy comprises a risk-adaptive security policy, the risk-adaptive security policy comprising a security policy implemented to be revised to adaptively remediate risk associated with a user behavior, the user behavior being represented via a plurality of risk-adaptive behavior factors, the plurality of risk-adaptive behavior factors comprising at least one user behavior factor and a user mindset factor and

using the organization specific security policy to perform a security analytics operation, the security analytics operation identifying anomalous, abnormal, unexpected, or malicious user behavior, the security analytics operation being performed by a security analytics system, the security analytics system communicating with the protected endpoint via a network.

7. The system of claim 6 , wherein the instructions executable by the processor are further configured for:

monitoring electronically-observable user interactions, the electronically-observable user interactions comprising a corresponding user behavior, the information related to the organization comprising the user behavior;

converting the electronically-observable user interactions into electronic information representing the user behavior;

evolving the organization specific security policy according to the electronically observable user interactions, the evolving the organization specific security policy comprising revising rules associated with the organization specific security policy according to enactment of a user behavior corresponding to an event.

8. The system of claim 6 , wherein:

each of the plurality of entity-specific security policies comprise an automatically generated entity-specific rule.

9. The system of claim 6 , wherein:

the plurality of rules comprise a rule associated with an event, the rule associated with the event comprising an indication of whether to allow a particular entity to perform the event;

the organization specific security policy is associated with an entity; and,

the organization security policy is applied to the entity.

10. The system of claim 6 , wherein:

the generating the organization specific security policy comprises performing a machine learning operation; and,

performing the machine learning operation on the security policy trains the security policy to recognize a true positive occurrence, a false positive occurrence, a true negative occurrence, a false negative occurrence and an indeterminate occurrence of an event.

11. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for:

gathering information related to an organization, the information related to the organization comprising electronically-observable information related to the organization, the monitoring being performed by a protected endpoint, the protected endpoint comprising an endpoint agent executing on an endpoint device, the endpoint agent comprising an entity-specific security policy feature pack,

converting the electronically-observable information related to the organization into electronic information related to the organization;

using the electronic information related to the organization to automatically generate a plurality of organization specific rules;

generating an organization specific security policy, the organization specific security policy comprising at least one organization specific rule, the organization specific security policy comprising an aggregation of a plurality of entity specific security policies, each of the plurality of entity specific security policies corresponding to a respective entity, each respective entity having a corresponding user profile, each corresponding user profile comprising a collection of information that uniquely describes an identify of the respective entity, the collection of information comprising a user profile attribute, a user behavior factor and a user mindset factor, the mindset factor comprising information used to determine a mental state of a user at a particular point in time; the organization specific security policy comprises a risk-adaptive security policy, the risk-adaptive security policy comprising a security policy implemented to be revised to adaptively remediate risk associated with a user behavior, the user behavior being represented via a plurality of risk-adaptive behavior factors, the plurality of risk-adaptive behavior factors comprising at least one user behavior factor and a user mindset factor and,

using the organization specific security policy to perform a security analytics operation, the security analytics operation identifying anomalous, abnormal, unexpected, or malicious user behavior, the security analytics operation being performed by a security analytics system, the security analytics system communicating with the protected endpoint via a network.

12. The non-transitory, computer-readable storage medium of claim 11 , wherein the computer executable instructions are further configured for:

monitoring electronically-observable user interactions, the electronically-observable user interactions comprising a corresponding user behavior, the information related to the organization comprising the user behavior;

converting the electronically-observable user interactions into electronic information representing the user behavior;

evolving the organization specific security policy according to the electronically observable user interactions, the evolving the organization specific security policy comprising revising rules associated with the organization specific security policy according to enactment of a user behavior corresponding to an event.

13. The non-transitory, computer-readable storage medium of claim 11 , wherein:

each of the plurality of entity-specific security policies comprise an automatically generated entity-specific rule.

14. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the plurality of rules comprise a rule associated with an event, the rule associated with the event comprising an indication of whether to allow a particular entity to perform the event;

the organization specific security policy is associated with an entity; and,

the organization security policy is applied to the entity.

15. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the generating the organization specific security policy comprises performing a machine learning operation; and,

performing the machine learning operation on the security policy trains the security policy to recognize a true positive occurrence, a false positive occurrence, a true negative occurrence, a false negative occurrence and an indeterminate occurrence of an event.

16. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the computer executable instructions are deployable to a client system from a server system at a remote location.

17. The non-transitory, computer-readable storage medium of claim 11 , wherein:

the computer executable instructions are provided by a service provider to a user on an on-demand basis.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
SECURITY INTEREST Recorded Apr 1, 2025
From: FORCEPOINT LLC; BITGLASS, LLC
To: SOCIÉTÉ GÉNÉRALE
Reel/Frame 070703/0887 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2021
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: FORCEPOINT LLC
Reel/Frame 057001/0057 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056214/0798 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: FORCEPOINT LLC
Reel/Frame 055479/0676 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 15, 2019
From: FORCEPOINT LLC
To: RAYTHEON COMPANY
Reel/Frame 048613/0636 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2018
From: SWAFFORD, BRANDON L.
To: FORCEPOINT, LLC
Reel/Frame 047756/0905 →