IP Library › Granted Patent US 12,013,956
Granted Patent B2
US 12,013,956 · App. 17/487,115 · Granted Jun 18, 2024

Systems and methods for verifying user activity using behavioral models

Inventors: Alexander Tormasov (Moscow, RU); Noam Herold (Raanana, IL); Yury Averkiev (Singapore, SG); Serguei Beloussov (Costa del Sol, SG); Stanislav Protasov (Singapore, SG)
Assignee: Acronis International GmbH
G06F21/62G06F21/316G06F21/554G06N20/00G06F2221/032
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,013,956
App. No.
17/487,115
Granted
Jun 18, 2024
Kind
B2
Abstract

Disclosed herein are systems and methods for verifying user activity based on behavioral models. In an exemplary aspect, a method may include receiving and parsing sensor data from at least one sensor in an environment to determine a first identifier of a person that is not authorized to access data via a computing device. The method may include intercepting, on the computing device, a data access request including a second identifier of a user that is authorized to access the data via the computing device. The method may include verifying whether the data access request is from the user authorized to access data by determining whether a chain of events involving the first person and the user corresponds to a behavioral model indicative of malicious activity. Based on the verification, the data access request is either granted or denied.

Claims (53)

1. A method for verifying user activity based on behavioral models, the method comprising:

receiving sensor data from at least one sensor in an environment;

parsing the sensor data to determine a first identifier of a person that is not authorized to access data via a computing device;

subsequent to determining the first identifier, intercepting a data access request on the computing device, wherein the data access request includes a second identifier of a user that is authorized to access the data via the computing device;

verifying whether the data access request is from the user authorized to access data by:

generating a chain of events for a period of time preceding the data access request, wherein the chain of events includes generated events including identifiers of the person that is not authorized to access the data via the computing device and the user that is authorized;

determining whether the chain of events corresponds to a behavioral model indicative of malicious activity; and

in response to determining that the chain of events do not correspond to the behavioral model, verifying that the data access request is from the user and granting the data access request.

2. The method of claim 1 , further comprising:

in response to determining that the chain of events corresponds to the behavioral model, not verifying that the data access request is from the user and blocking the data access request.

3. The method of claim 1 , wherein generating the chain of events including the person and the user in response to determining the first identifier and intercepting the data access request with the second identifier within a threshold period of time.

4. The method of claim 1 , wherein determining whether the chain of events corresponds to a behavioral model indicative of malicious activity further comprises:

inputting the chain of events into a machine learning algorithm that classifies whether an input chain of events comprises the malicious activity, wherein the machine learning algorithm is trained with a dataset that comprises a plurality of behavioral models each including events associated with the malicious activity; and

receiving an output from the machine learning algorithm indicating whether the chain of events corresponds to a behavioral model indicative of the malicious activity.

5. The method of claim 4 , further comprising:

receiving a confirmation from the user that the data access request is not from the user; and

in response to receiving the confirmation, re-training the machine learning algorithm to classify the chain of events as corresponding to a behavioral model indicative of the malicious activity.

6. The method of claim 1 , wherein the behavioral model is a target chain of events, and wherein determining whether the chain of events corresponds to the behavioral model comprises:

determining a deviation of the chain of events from the target chain of events that is indicative of the malicious activity; and

in response to determining the deviation is less than a threshold deviation value, not verifying the data access request.

7. The method of claim 6 , wherein each respective event in the target chain of events is assigned a weight indicative of an importance of the respective event.

8. The method of claim 1 , wherein determining whether the chain of events corresponds to a behavioral model indicative of malicious activity is based on an order of events involving the person, another order of the events involving the user, and an amount of time in between each event.

9. A system for verifying user activity based on behavioral models, the system comprising:

a hardware processor configured to:

receive sensor data from at least one sensor in an environment;

parse the sensor data to determine a first identifier of a person that is not authorized to access data via a computing device;

subsequent to determining the first identifier, intercept a data access request on the computing device, wherein the data access request includes a second identifier of a user that is authorized to access the data via the computing device;

verify whether the data access request is from the user authorized to access data by:

generating a chain of events for a period of time preceding the data access request, wherein the chain of events includes generated events including identifiers of the person that is not authorized to access the data via the computing device and the user that is authorized;

determining whether the chain of events corresponds to a behavioral model indicative of malicious activity; and

in response to determining that the chain of events do not correspond to the behavioral model, verifying that the data access request is from the user and granting the data access request.

10. The system of claim 9 , wherein the hardware processor is further configured to:

in response to determining that the chain of events corresponds to the behavioral model, not verify that the data access request is from the user and block the data access request.

11. The system of claim 9 , wherein the hardware processor is configured to generate the chain of events including the person and the user in response to determining the first identifier and intercepting the data access request with the second identifier within a threshold period of time.

12. The system of claim 9 , wherein the hardware processor is further configured to determine whether the chain of events corresponds to a behavioral model indicative of malicious activity by:

inputting the chain of events into a machine learning algorithm that classifies whether an input chain of events comprises the malicious activity, wherein the machine learning algorithm is trained with a dataset that comprises a plurality of behavioral models each including events associated with the malicious activity; and

receiving an output from the machine learning algorithm indicating whether the chain of events corresponds to a behavioral model indicative of the malicious activity.

13. The system of claim 12 , wherein the hardware processor is further configured to:

receive a confirmation from the user that the data access request is not from the user; and

in response to receiving the confirmation, re-train the machine learning algorithm to classify the chain of events as corresponding to a behavioral model indicative of the malicious activity.

14. The system of claim 9 , wherein the behavioral model is a target chain of events, and wherein the hardware processor is further configured to determine whether the chain of events corresponds to the behavioral model by:

determining a deviation of the chain of events from the target chain of events that is indicative of the malicious activity; and

in response to determining the deviation is less than a threshold deviation value, not verifying the data access request.

15. The system of claim 9 , wherein the hardware processor is further configured to determine whether the chain of events corresponds to a behavioral model indicative of malicious activity based on an order of events involving the person, another order of the events involving the user, and an amount of time in between each event.

16. The system of claim 15 , wherein each respective event in the target chain of events is assigned a weight indicative of an importance of the respective event.

17. A non-transitory computer readable medium storing thereon computer executable instructions for verifying user activity based on a behavioral models, including instructions for:

receiving sensor data from at least one sensor in an environment;

parsing the sensor data to determine a first identifier of a person that is not authorized to access data via a computing device;

subsequent to determining the first identifier, intercepting a data access request on the computing device, wherein the data access request includes a second identifier of a user that is authorized to access the data via the computing device;

verifying whether the data access request is from the user authorized to access data by:

generating a chain of events for a period of time preceding the data access request, wherein the chain of events includes generated events including identifiers of the person that is not authorized to access the data via the computing device and the user that is authorized;

determining whether the chain of events corresponds to a behavioral model indicative of malicious activity; and

in response to determining that the chain of events do not correspond to the behavioral model, verifying that the data access request is from the user and granting the data access request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2024
From: TORMASOV, ALEXANDER; HEROLD, NOAM; AVERKIEV, YURY; BELOUSSOV, SERGUEI; PROTASOV, STANISLAV
To: ACRONIS INTERNATIONAL GMBH
Reel/Frame 067330/0277 →
Continuity (3)
Continuation In Part 17487054 · Sep 28, 2021
Continuation In Part 17486069 · Sep 27, 2021
Related Publication 20230139161A1 · May 4, 2023