IP Library › Granted Patent US 12,250,236
Granted Patent B2
US 12,250,236 · App. 17/664,920 · Granted Mar 11, 2025

Collecting endpoint data and network data to detect an anomaly

Inventor: Michael Benjamin (Broomfield, CO)
Assignee: Level 3 Communications, LLC
H04L63/1425H04L63/0227H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,250,236
App. No.
17/664,920
Granted
Mar 11, 2025
Kind
B2
Abstract

The present application describes a system that uses endpoint data and network data to detect an anomaly. Once an anomaly is detected, the system may determine a severity of the anomaly by comparing the anomaly to a global database of known anomalies. The system may then initiate preventative measures to address the anomaly.

Claims (39)

1. A method, comprising:

receiving endpoint data of a computing device from the computing device, the endpoint data comprising activities and/or events that occurred on the computing device;

receiving network data from a network access device, the network data being associated with the computing device;

combining the endpoint data and the network data to generate event data associated with the computing device, the event data including a sequence of events between the computing device and the network access device;

analyzing the event data associated with the computing device to detect an anomaly; and

initiating a mitigation procedure to address the anomaly.

2. The method of claim 1 , further comprising:

generating a timeline of the event data; and

causing the timeline to be provided on a display of a remote computing device.

3. The method of claim 2 , wherein at least a portion of the timeline is selectable.

4. The method of claim 3 , further comprising providing additional information associated with the timeline in response to receiving a selection of the at least the portion of the timeline.

5. The method of claim 1 , wherein the mitigation procedure includes causing a blocking action to be performed on the anomaly.

6. The method of claim 1 , wherein the endpoint data is endpoint detection and response (EDR) data.

7. A system, comprising:

a processor; and

a memory coupled to the processor and storing instructions that, when executed by the processor, perform operations, comprising:

receiving endpoint data of a computing device from the computing device, the endpoint data comprising activities and/or events that occurred on the computing device;

receiving network data from a network access device, the network data being associated with the computing device;

combining the endpoint data and the network data to generate event data associated with the computing device, the event data including a sequence of events between the computing device and the network access device;

analyzing the event data associated with the computing device to detect an anomaly;

categorizing the anomaly based, at least in part, on the analyzing; and

initiating a mitigation procedure to address the anomaly.

8. The system of claim 7 , further comprising instructions for:

generating a timeline of the event data; and

causing the timeline to be provided on a display of a remote computing device.

9. The system of claim 8 , wherein at least a portion of the timeline is selectable.

10. The system of claim 9 , further comprising instructions for providing additional information associated with the timeline in response to receiving a selection of the at least the portion of the timeline.

11. The system of claim 7 , wherein the mitigation procedure includes an initiating of a blocking action performed on the anomaly based, at least in part, on the categorization of the anomaly.

12. The system of claim 7 , wherein the endpoint data is endpoint detection and response (EDR) data.

13. A method, comprising:

receiving endpoint data of a first computing device from the first computing device, the endpoint data comprising activities and/or events that occurred on the first computing device;

receiving network data associated with the first computing device;

generating event data for the first computing device based, at least in part, on the endpoint data and the network data;

analyzing the event data;

identifying an anomaly in the event data; and

initiating a mitigation procedure on the anomaly.

14. The method of claim 13 , wherein the mitigation procedure is a blocking procedure.

15. The method of claim 13 , wherein the network data includes one or more of a domain name system (DNS) lookup associated with the first computing device, a website that was visited by the first computing device, or an address resolution protocol (ARP) communication associated with the first computing device.

16. The method of claim 13 , further comprising generating a timeline for display on a user interface, the timeline including one or more selectable events associated with the event data.

Assignments (4)
ASSIGNMENT OF FIRST LIEN SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT R/F 069295/0858 Recorded Jun 12, 2026
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS RETIRING COLLATERAL AGENT
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS SUCCESSOR COLLATERAL AGENT
Reel/Frame 075738/0427 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (FIRST LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0858 →
NOTICE OF GRANT OF SECURITY INTEREST IN INTELLECTUAL PROPERTY (SECOND LIEN) Recorded Nov 4, 2024
From: LEVEL 3 COMMUNICATIONS, LLC; GLOBAL CROSSING TELECOMMUNICATIONS, INC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 069295/0749 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2022
From: BENJAMIN, MICHAEL
To: LEVEL 3 COMMUNICATIONS, LLC
Reel/Frame 060257/0784 →
Continuity (2)
Provisional Application 63231346 · Aug 10, 2021
Related Publication 20230051880A1 · Feb 16, 2023
References Cited (12)
US 8528086B1 · Aziz · 2013 [cited by examiner]
US 11057414B1 · Giorgio · 2021 [cited by examiner]
US 11469946B2 · Srinivas · 2022 [cited by examiner]
US 11640470B1 · Amar · 2023 [cited by examiner]
US 11700190B2 · Yadav · 2023 [cited by examiner]
US 11824646B1 · Muddu · 2023 [cited by examiner]
US 20030005145A1 · Bullard · 2003 [cited by examiner]
US 20170250855A1 · Patil · 2017 [cited by examiner]
US 20190238584A1 · Somasundaram · 2019 [cited by examiner]
US 20190378119A1 · Hyuga · 2019 [cited by examiner]
US 20200412549A1 · Endo · 2020 [cited by examiner]
US 20220027465A1 · Hercock · 2022 [cited by examiner]