IP Library Granted Patent US 12,373,757
Granted Patent B2
US 12,373,757 · App. 17/197,480 · Granted Jul 29, 2025

Using weighted peer groups to selectively trigger a security alert

Inventors: Idan Hen (Tel Aviv, IL); Itay Argoety (Tel Aviv, IL); Dror Cohen (Tel Aviv, IL)
Assignee: Microsoft Technology Licensing, LLC
G06Q10/0635
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,373,757
App. No.
17/197,480
Granted
Jul 29, 2025
Kind
B2
Abstract

Techniques are described herein that are capable of using weighted peer groups to selectively trigger a security alert. A determination is made that an entity performs an operation. The entity has peers that are categorized among peer groups. For each peer group, an extent to which the peers in the peer group perform the operation is determined. Weights are assigned to the respective peer groups. For each peer group, the extent to which the peers in the peer group perform the operation and the weight that is assigned to the peer group are combined to provide a respective weighted group value. A risk score, which is based at least in part on the weighted group values of the peer groups, is assigned to the operation. The security alert regarding the operation is selectively triggered based at least in part on the risk score.

Claims (63)

1. A system comprising:

a memory; and

a processing system coupled to the memory, the processing system configured to:

determine that an entity performs an operation, the operation comprising an attempt to access a resource;

obtain a feature vector to represent the entity, wherein the feature vector of the entity is based on at least one of a behavioral attribute of the entity or a static attribute of the entity;

obtain feature vectors to represent respective peers of a plurality of peers of the entity, wherein the feature vectors of the respective peers are based on at least one of the following: behavioral attributes of the respective peers or static attributes of the respective peers;

cluster the plurality of peers of the entity into a plurality of peer groups, which comprise subsets of the plurality of peers, using a non-parametric or density-based clustering algorithm by providing information indicating types of relationships, comprising a collaboration relationship, between the peers and the entity from the feature vector of the entity and the feature vectors of the respective peers as input to the non-parametric or density-based clustering algorithm, which causes the non-parametric or density-based clustering algorithm to define the plurality of peer groups, comprising a collaboration peer group, based at least in part on peers in the subsets having respective types of relationships with the entity and further based at least in part on the peers in the subsets having a number of features in common with the entity that is greater than or equal to a threshold number, the collaboration peer group defined by the subset of the peers in the collaboration peer group and the entity having the collaboration relationship by sharing a file, a folder, or a message;

determine a plurality of extents to which the peers in the plurality of peer groups perform the operation;

assign a plurality of weights to the plurality of peer groups, the plurality of weights indicating a plurality of extents to which attributes of the entity, as indicated by the feature vector of the entity, correspond to attributes of the peers in the plurality of peer groups, as indicated by a plurality of combinations of the feature vectors corresponding to the plurality of peer groups, wherein the weights that are assigned to the peer groups are based at least in part on respective sizes of the peer groups, wherein a size of a peer group being smaller corresponds to the weight of the peer group being higher, and wherein the size of the peer group being larger corresponds to the weight of the peer group being lower;

combine the plurality of extents to which the peers in the plurality of peer groups perform the operation and the plurality of weights that are assigned to the plurality of peer groups to provide a plurality of weighted group values;

assign a risk score, which is based at least in part on the weighted group values of the peer groups, to the operation; and

based at least in part on the risk score being greater than or equal to a score threshold, perform a remedial action with regard to the operation by preventing the entity from accessing the resource.

2. The system of claim 1 , wherein the plurality of peer groups further comprises an organizational peer group, which is defined such that each peer in the organizational peer group has a same manager as the entity.

3. The system of claim 1 , wherein the plurality of peer groups further comprises a security peer group, which is defined such that each peer in the security peer group has an identified security permission in common with the entity.

4. The system of claim 1 , wherein the plurality of peer groups further comprises a behavioral peer group, which is defined such that each peer in the behavioral peer group performs a same activity as the entity.

5. The system of claim 1 , wherein the plurality of peer groups is configured to change over time based at least in part on the attributes of the entity changing over time.

6. The system of claim 1 , wherein the weight that is assigned to a peer group is inversely proportional to an average of a difference between a representation of the attributes of the entity and a representation of the attributes of the peers in the peer group; and

wherein the processing system is configured to:

divide the weight that is assigned to the peer group by the extent to which the peers in the peer group perform the operation to provide the respective weighted group value.

7. The system of claim 6 , wherein the risk score that is assigned to the operation is based at least in part on a sum of the weighted group values of the peer groups.

8. The system of claim 1 , wherein the risk score that is assigned to the operation is further based at least in part on a number of peer groups of the entity;

wherein fewer peer groups weights in favor of a lower risk score; and

wherein more peer groups weigh in favor of a higher risk score.

9. The system of claim 1 , wherein the threshold number changes dynamically with time depending on at least one of the following:

a number of peers that are included in the plurality of peers;

an average number of attributes per peer in the plurality of peers; or

a median number of attributes per peer in the plurality of peers.

10. A method implemented by a computing system, the method comprising:

determining that an entity performs an operation, the operation comprising an attempt to access a resource;

obtaining a feature vector to represent the entity, wherein the feature vector of the entity is based on at least one of a behavioral attribute of the entity or a static attribute of the entity;

obtaining feature vectors to represent respective peers of a plurality of peers of the entity, wherein the feature vectors of the respective peers are based on at least one of the following: behavioral attributes of the respective peers or static attributes of the respective peers;

clustering the plurality of peers of the entity into a plurality of peer groups, which comprise subsets of the plurality of peers, using a non-parametric or density-based clustering algorithm by providing information indicating types of relationships, which comprise a collaboration relationship, between the peers and the entity from the feature vector of the entity and the feature vectors of the respective peers as input to the non-parametric or density-based clustering algorithm, which causes the non-parametric or density-based clustering algorithm to define the plurality of peer groups, which comprise a collaboration peer group, based at least in part on peers in the subsets having respective types of relationships with the entity and further based at least in part on the peers in the subsets having a number of features in common with the entity that is greater than or equal to a threshold number, the collaboration peer group defined by a first subset of the plurality of peers having the collaboration relationship with the entity by sharing a file, a folder, or a message with the entity;

determining a plurality of extents to which the peers in the plurality of peer groups perform the operation;

assigning a plurality of weights to the plurality of peer groups, the plurality of weights indicating a plurality of extents to which attributes of the entity, as indicated by the feature vector of the entity, correspond to attributes of the peers in the plurality of peer groups, as indicated by a plurality of combinations of the feature vectors corresponding to the plurality of peer groups;

combining the plurality of extents to which the peers in the plurality of peer groups perform the operation and the plurality of weights that are assigned to the plurality of peer groups to provide a plurality of weighted group values;

assigning a risk score to the operation, wherein the risk score is based at least in part on the weighted group values of the peer groups and is further based at least in part on a number of peer groups of the entity, wherein fewer peer groups weighs in favor of a lower risk score, and wherein more peer groups weighs in favor of a higher risk score; and

based at least in part on the risk score being greater than or equal to a score threshold, performing a remedial action with regard to the operation by preventing the entity from accessing the resource.

11. The method of claim 10 , wherein the plurality of peer groups changes over time based at least in part on the attributes of the entity changing over time.

12. The method of claim 10 , wherein the weight that is assigned to a peer group is inversely proportional to an average of a difference between a representation of the attributes of the entity and a representation of the attributes of the peers in the peer group; and

wherein, for each peer group in the plurality of peer groups, combining the extent to which the peers in the peer group perform the operation and the weight that is assigned to the peer group to provide a respective weighted group value comprises:

dividing the weight that is assigned to the peer group by the extent to which the peers in the peer group perform the operation to provide the respective weighted group value.

13. The method of claim 10 , wherein the weights that are assigned to the peer groups are based at least in part on respective sizes of the peer groups;

wherein a smaller size of a peer group causes the weight of the peer group to be higher; and

wherein a larger size of a peer group causes the weight of the peer group to be lower.

14. The method of claim 10 , wherein the organizational peer group defined by the subset of the peers in the organizational peer group and the entity have a same manager.

15. A computer program product comprising a computer-readable storage medium having instructions recorded thereon for enabling a processor-based system to perform operations, the operations comprising:

determining that an entity performs an operation, the operation comprising an attempt to access a resource;

obtaining a feature vector to represent the entity, wherein the feature vector of the entity is based on at least one of a behavioral attribute of the entity or a static attribute of the entity;

obtaining feature vectors to represent respective peers of a plurality of peers of the entity, wherein the feature vectors of the respective peers are based on at least one of the following: behavioral attributes of the respective peers or static attributes of the respective peers;

clustering the plurality of peers of the entity into a plurality of peer groups, which comprise subsets of the plurality of peers, using a non-parametric or density-based clustering algorithm by providing information indicating types of relationships, comprising an organizational relationship, between the peers and the entity from the feature vector of the entity and the feature vectors of the respective peers as input to the non-parametric or density-based clustering algorithm, which causes the non-parametric or density-based clustering algorithm to define the plurality of peer groups, comprising an organizational peer group, based at least in part on peers in the subsets having respective types of relationships with the entity and further based at least in part on the peers in the subsets having a number of features in common with the entity that is greater than or equal to a threshold number;

determining a plurality of extents to which the peers in the plurality of peer groups perform the operation;

assigning a plurality of weights to the plurality of peer groups, the plurality of weights indicating a plurality of extents to which attributes of the entity, as indicated by the feature vector of the entity, correspond to attributes of the peers in the plurality of peer groups, as indicated by a plurality of combinations of the feature vectors corresponding to the plurality of peer groups;

combining the plurality of extents to which the peers in the plurality of peer groups perform the operation and the plurality of weights that are assigned to the plurality of peer groups to provide a plurality of weighted group values;

assigning a risk score, which is based at least in part on the weighted group values of the peer groups, to the operation; and

based at least in part on the risk score being greater than or equal to a score threshold, performing a remedial action with regard to the operation by preventing the entity from accessing the resource;

wherein at least one of the following:

the plurality of weights that are assigned to the plurality of peer groups are based at least in part on a plurality of respective sizes of the plurality of peer groups, wherein a smaller size of a peer group causes the weight of the peer group to be higher, and wherein a larger size of a peer group causes the weight of the peer group to be lower; or

the risk score that is assigned to the operation is further based at least in part on a number of peer groups of the entity, wherein fewer peer groups weights in favor of a lower risk score, and wherein more peer groups weigh in favor of a higher risk score.

16. The computer program product of claim 15 , wherein the plurality of peer groups further comprises a collaboration peer group, which is defined by the subset of the peers in the collaboration peer group and the entity having the collaboration relationship by sharing at least one of a file or a folder.

17. The computer program product of claim 15 , wherein the plurality of peer groups further comprises a security peer group, which is defined such that each peer in the security peer group has an identified security permission in common with the entity.

18. The computer program product of claim 15 , wherein the plurality of peer groups further comprises a behavioral peer group, which is defined such that each peer in the behavioral peer group performs a same activity as the entity.

19. The computer program product of claim 15 , wherein the plurality of weights that are assigned to the plurality of peer groups are based at least in part on the plurality of respective sizes of the plurality of peer groups.

20. The computer program product of claim 15 , wherein the risk score that is assigned to the operation is further based at least in part on the number of peer groups of the entity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 10, 2021
From: HEN, IDAN; ARGOETY, ITAY; COHEN, DROR
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 055549/0478 →
Continuity (1)
Related Publication 20220292417A1 · Sep 15, 2022
References Cited (50)
US 9288202B1 · Felton et al. · 2016 [cited by applicant]
US 10609218B1 · Moller et al. · 2020 [cited by applicant]
US 10887325B1 · Lin et al. · 2021 [cited by applicant]
US 11295241B1 · Badawy · 2022 [cited by examiner]
US 20140380484A1 · Choi · 2014 [cited by examiner]
US 20150101053A1 · Sipple · 2015 [cited by examiner]
US 20150200953A1 · Vidhun · 2015 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20170193514A1 · Chen · 2017 [cited by applicant]
US 20170324760A1 · Gorny · 2017 [cited by examiner]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180082192A1 · Cormier et al. · 2018 [cited by applicant]
US 20180131661A1 · He et al. · 2018 [cited by applicant]
US 20180139227A1 · Martin · 2018 [cited by examiner]
US 20180241764A1 · Nadolski · 2018 [cited by examiner]
US 20180329977A1 · Soceanu · 2018 [cited by examiner]
US 20200045064A1 · Bindal et al. · 2020 [cited by applicant]
US 20200053111A1 · Jakobsson · 2020 [cited by examiner]
US 20210073828A1 · Dutta et al. · 2021 [cited by applicant]
US 20210142209A1 · Patil · 2021 [cited by examiner]
US 20210157907A1 · Argoety et al. · 2021 [cited by applicant]
US 20210216928A1 · O'Toole · 2021 [cited by examiner]
US 20210266323A1 · Jani · 2021 [cited by examiner]
US 20220075788A1 · Kalou · 2022 [cited by examiner]
US 20220086162A1 · Badawy · 2022 [cited by examiner]
US 20220200800A1 · Xu · 2022 [cited by examiner]
US 20220277402A1 · Keda et al. · 2022 [cited by applicant]
US 20220329612A1 · Verma · 2022 [cited by examiner]
CN 101442433A · 2009 [cited by applicant]
CN 106104563A · 2016 [cited by applicant]
WO 2019220363A1 · 2019 [cited by applicant]
Peer Group Analysis in Identity and Access Management to Identify Anomalies; Dhamdhere et al; 2017 (Year: 2017). [cited by examiner]
“Non Final Office Action Issued in U.S. Appl. No. 16/692,545”, Mailed Date: Apr. 8, 2022, 13 Pages. [cited by applicant]
“Final Office Action Issued in U.S. Appl. No. 16/692,545”, Mailed Date: Dec. 8, 2021, 10 Pages. [cited by applicant]
“Non Final Office Action Issued in U.S. Appl. No. 16/692,545”, Mailed Date: Aug. 2, 2021, 10 Pages. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US2020/057267”, Mailed Date: Dec. 23, 2020, 11 Pages. [cited by applicant]
Das, et al., “Modeling User Communities for Identifying Security Risks in an Organization”, In the Proceedings of IEEE International Conference on Big Data, Dec. 11, 2017, pp. 4481-4486. [cited by applicant]
Li, et al., “Generating Interpretable Network Asset Clusters For Security Analytics”, In Proceedings of IEEE International Conference on Big Data, Dec. 10, 2018, pp. 2972-2979. [cited by applicant]
Lin, et al., “BEAM: An Anomaly-Based Threat Detection System for Enterprise Multi-Domain Data”, In Proceedings of IEEE International Conference on Big Data, Dec. 10, 2020, pp. 2610-2618. [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US22/018588”, Mailed Date: Jun. 24, 2022, 14 Pages. [cited by applicant]
“Final Office Action Issued in U.S. Appl. No. 16/692,545”, Mailed Date: Oct. 14, 2022, 13 Pages. [cited by applicant]
“Non-Final Office Action Issued in U.S. Appl. No. 16/692,545”, Mailed Date: Apr. 7, 2023, 13 Pages. [cited by applicant]
First Office Action received on Chinese Application No. 202080092286.4 mailed on Feb. 20, 2024, 10 pages (English Translation Provided). [cited by applicant]
Notice of Allowance mailed on Dec. 6, 2023, in U.S. Appl. No. 16/692,545, 5 Pages. [cited by applicant]
Communication under Rule 71(3) Received in European Patent Application No. 22711410.5, mailed on Jul. 18, 2024, 08 pages. [cited by applicant]
Communication 94(3) Received for European Application No. 20811788.7, mailed on Apr. 4, 2024, 5 pages. [cited by applicant]
Decision to Grant pursuant to Article 97(1) received in European Application No. 22711410.5, mailed Nov. 21, 2024, 2 pages. [cited by applicant]
“Notice of Allowance Issued in U.S. Appl. No. 16/692,545”, Mailed Date: Aug. 29, 2023, 5 Pages. [cited by applicant]
Notice of Allowance received on Chinese Application No. 202080092286.4 mailed on Jan. 1, 13, 2025, 08 pages (English Translation Provided). [cited by applicant]
First Examination Report Received for Indian Application No. 202217026866, mailed on Mar. 22, 2025, 06 pages. [cited by applicant]