IP Library › Granted Patent US 12,481,777
Granted Patent B2
US 12,481,777 · App. 18/673,015 · Granted Nov 25, 2025

Centralized event detection

Inventors: Joseph H. Levy (Farmington, UT); Andrew J. Thomas (Oxfordshire, GB); Daniel Salvatore Schiappa (Bedford, NH); Kenneth D. Ray (Seattle, WA)
Assignee: Sophos Limited
G06F21/6218G06F16/137G06F16/285G06F16/93G06F21/64G06N20/00H04L9/3265H04L41/20H04L41/22H04L63/08H04L63/0838H04L63/101H04L63/102H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/20H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,481,777
App. No.
18/673,015
Granted
Nov 25, 2025
Kind
B2
Abstract

A threat management facility stores a number of entity models that characterize reportable events from one or more entities. A stream of events from compute instances within an enterprise network can then be analyzed using these entity models to detect behavior that is inconsistent or anomalous for one or more of the entities that are currently active within the enterprise network.

Claims (34)

1 . A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs the steps of:

storing an entity model at a threat management facility for an enterprise network, the entity model characterizing a baseline of expected events for a stack of assets, each asset in the stack of assets representing an entity associated with a compute instance, and the baseline of expected events based on events from a corresponding entity over an interval spanning an historical window;

instrumenting a local security agent on the compute instance to detect one or more events from one or more sensors on the compute instance and report a number of event vectors, the number of event vectors including the one or more events;

receiving an event stream that includes the number of event vectors at the threat management facility;

calculating a risk score for the compute instance based on a comparison of one or more of the event vectors included in the event stream received at the threat management facility with the entity model for the entity;

selecting a remedial action for the compute instance based on the number of event vectors when the risk score exceeds a threshold; and

adjusting, with the threat management facility, a local monitoring activity by the local security agent on the compute instance to increase a level of the local activity monitoring based on a determination that the risk score indicates a deviation from the baseline of expected events.

2 . The computer program product of claim 1 , wherein the interval for the baseline of expected events is algorithmically determined.

3 . The computer program product of claim 1 , wherein the threat management facility stores a plurality of entity models for a plurality of different entity types associated with the compute instance.

4 . The computer program product of claim 1 , wherein the threat management facility stores a plurality of entity models for a plurality of different entity types associated with the enterprise network.

5 . The computer program product of claim 1 , wherein the event stream received by the threat management facility includes additional event vectors from a plurality of other compute instances associated with the enterprise network.

6 . The computer program product of claim 1 , wherein the event vectors are received from two or more different entities associated with the compute instance.

7 . The computer program product of claim 1 , further comprising code that performs the step of refining the entity model based on one or more additional event vectors in the event stream received after the entity model is created.

8 . The computer program product of claim 7 , wherein refining the entity model includes refining the entity model based on a distance in an event vector space between the entity model and the one or more additional event vectors in the event stream.

9 . The computer program product of claim 1 , wherein instrumenting the compute instance includes configuring the compute instance to normalize at least one of the events from at least one of the one or more sensors.

10 . The computer program product of claim 1 , wherein instrumenting the compute instance includes configuring the compute instance to tokenize at least one of the events from at least one of the one or more sensors.

11 . The computer program product of claim 1 , wherein instrumenting the compute instance includes configuring the compute instance to encrypt at least one of the events from at least one of the one or more sensors.

12 . The computer program product of claim 1 , wherein instrumenting the compute instance includes prioritizing at least one of the events from at least one of the one or more sensors.

13 . The computer program product of claim 1 , wherein calculating the risk score includes calculating a distance between one or more of the event vectors and the baseline in a vector space using at least one of a Mahalanobis distance, a Euclidean distance, and a Minkowski distance.

14 . The computer program product of claim 1 , wherein calculating the risk score includes calculating a distance between one or more of the event vectors and the baseline using a k-nearest neighbor algorithm.

15 . A method, comprising:

storing an entity model at a threat management facility for a compute instance in an enterprise network, the entity model characterizing a baseline of expected events for a stack of assets, each asset in the stack of assets representing an entity associated with the compute instance, and the baseline of expected events based on events from a corresponding entity over an interval spanning an historical window;

instrumenting the compute instance to detect one or more events and report a number of event vectors, the number of event vectors including the one or more events;

receiving an event stream that includes the number of event vectors;

calculating a risk score for the compute instance based on a comparison of one or more of the event vectors included in the event stream with the entity model for the entity;

selecting a remedial action for the compute instance based on the number of event vectors when the risk score exceeds a threshold; and

adjusting local monitoring activity on the compute instance based on a determination that the risk score indicates a deviation from the baseline of expected events.

16 . The method of claim 15 , wherein adjusting the local monitoring activity includes increasing a level of local activity monitoring when the risk score indicates the deviation from the baseline.

17 . The method of claim 15 , further comprising refining the entity model based on additional event vectors in the event stream received after the entity model is created.

18 . The method of claim 15 , wherein receiving the event stream includes receiving the event stream at a threat management facility.

19 . The method of claim 18 , wherein adjusting local monitoring activity on the compute instance includes adjusting local monitoring activity in response to an instruction from the threat management facility.

20 . A system, comprising:

a compute instance in an enterprise network, the compute instance configured to detect one or more events associated with the compute instance and to report a number of event vectors, the number of event vectors including the one or more events; and

a threat management facility, the threat management facility including a memory storing an entity model characterizing a baseline of expected events for a stack of assets, each asset in the stack of assets representing an entity associated with the compute instance, and the baseline of expected events based on events from a corresponding entity over an interval spanning an historical window, and the threat management facility configured to receive an event stream that includes the number of event vectors, calculate a risk score for the compute instance based on a comparison of one or more of the event vectors included in the event stream with the entity model for the entity, select a remedial action for the compute instance based on the number of event vectors when the risk score exceeds a threshold, and adjust local monitoring activity on the compute instance to increase a level of local activity monitoring based on a determination that the risk score indicates a deviation from the baseline of expected events.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2024
From: LEVY, JOSEPH H.; THOMAS, ANDREW J.; SCHIAPPA, DANIEL SALVATORE; RAY, KENNETH D.
To: SOPHOS LIMITED
Reel/Frame 067560/0893 →
Continuity (6)
Continuation 18096882 · Jan 13, 2023
Continuation 16383335 · Apr 12, 2019
Provisional Application 62744956 · Oct 12, 2018
Provisional Application 62659031 · Apr 17, 2018
Provisional Application 62657542 · Apr 13, 2018
Related Publication 20240311503A1 · Sep 19, 2024
References Cited (83)
US 7660981B1 · Hunt · 2010 [cited by applicant]
US 8181244B2 · Boney · 2012 [cited by applicant]
US 8201243B2 · Boney · 2012 [cited by applicant]
US 8418250B2 · Morris et al. · 2013 [cited by applicant]
US 8544087B1 · Eskin · 2013 [cited by examiner]
US 8719932B2 · Boney · 2014 [cited by applicant]
US 8726389B2 · Morris et al. · 2014 [cited by applicant]
US 8763123B2 · Morris et al. · 2014 [cited by applicant]
US 8769676B1 · Kashyap · 2014 [cited by applicant]
US 8856505B2 · Schneider · 2014 [cited by applicant]
US 9413721B2 · Morris et al. · 2016 [cited by applicant]
US 9426185B1 · Vora et al. · 2016 [cited by applicant]
US 9578045B2 · Jaroch et al. · 2017 [cited by applicant]
US 10147065B1 · Yiftachel et al. · 2018 [cited by applicant]
US 10257224B2 · Jaroch et al. · 2019 [cited by applicant]
US 10284591B2 · Giuliani et al. · 2019 [cited by applicant]
US 10367842B2 · Chen et al. · 2019 [cited by applicant]
US 10594710B2 · Wright et al. · 2020 [cited by applicant]
US 10599844B2 · Schmidtler et al. · 2020 [cited by applicant]
US 10887326B2 · Weizman et al. · 2021 [cited by applicant]
US 11087014B2 · Levy et al. · 2021 [cited by applicant]
US 11562088B2 · Levy et al. · 2023 [cited by applicant]
US 11599660B2 · Levy et al. · 2023 [cited by applicant]
US 11621969B2 · Dodson · 2023 [cited by examiner]
US 20130191919A1 · Basavapatna et al. · 2013 [cited by applicant]
US 20140279641A1 · Singh et al. · 2014 [cited by applicant]
US 20150229662A1 · Hitt et al. · 2015 [cited by applicant]
US 20150317325A1 · Key · 2015 [cited by applicant]
US 20150373043A1 · Wang et al. · 2015 [cited by applicant]
US 20160021117A1 · Harmon et al. · 2016 [cited by applicant]
US 20160125183A1 · Niemela · 2016 [cited by applicant]
US 20160156460A1 · Feng et al. · 2016 [cited by applicant]
US 20160173509A1 · Ray et al. · 2016 [cited by applicant]
US 20170046604A1 · Kaye et al. · 2017 [cited by applicant]
US 20170054729A1 · Ford · 2017 [cited by applicant]
US 20170085539A1 · Wishard · 2017 [cited by applicant]
US 20170134162A1 · Code et al. · 2017 [cited by applicant]
US 20170149701A1 · Mancine et al. · 2017 [cited by applicant]
US 20170185930A1 · Perry · 2017 [cited by applicant]
US 20170359220A1 · Weith et al. · 2017 [cited by applicant]
US 20180004948A1 · Martin · 2018 [cited by examiner]
US 20180048668A1 · Gupta et al. · 2018 [cited by applicant]
US 20180139227A1 · Martin et al. · 2018 [cited by applicant]
US 20180191766A1 · Holeman et al. · 2018 [cited by applicant]
US 20180247713A1 · Rothman · 2018 [cited by applicant]
US 20190036952A1 · Sim et al. · 2019 [cited by applicant]
US 20190068627A1 · Thampy · 2019 [cited by applicant]
US 20190116193A1 · Wang et al. · 2019 [cited by applicant]
US 20190166141A1 · Xu et al. · 2019 [cited by applicant]
US 20190319961A1 · Levy et al. · 2019 [cited by applicant]
US 20190319971A1 · Levy et al. · 2019 [cited by applicant]
US 20190319980A1 · Levy et al. · 2019 [cited by applicant]
US 20200213341A1 · Wu et al. · 2020 [cited by applicant]
US 20210342467A1 · Levy et al. · 2021 [cited by applicant]
US 20230185945A1 · Levy et al. · 2023 [cited by applicant]
US 20230421593A1 · Crabtree · 2023 [cited by examiner]
WO WO2019157333 · 2019 [cited by applicant]
WO WO2019200317 · 2019 [cited by applicant]
Munz, Gerhard et al., “Traffic anomaly detection using k-means clustering”, GI/ITG Workshop MMBnet NPL-699 2007 , 9 pages. [cited by applicant]
“U.S. Appl. No. 16/383,315 Final Office Action mailed Oct. 5, 2021”, NPL-793 , 27 pages. [cited by applicant]
“U.S. Appl. No. 16/383,315 Non-Final Office Action mailed Jun. 9, 2021”, NPL-698 , 23 pages. [cited by applicant]
“U.S. Appl. No. 16/383,315 Notice of Allowance mailed Apr. 6, 2022”, NPL-853 , 10 pages. [cited by applicant]
“U.S. Appl. No. 16/383,315 Notice of Allowance mailed Sep. 28, 2022”, NPL-878 , 10 pages. [cited by applicant]
“U.S. Appl. No. 16/383,315 Notice of Allowance mailed Nov. 21, 2022”, NPL-891 , 11 pages. [cited by applicant]
“U.S. Appl. No. 16/383,335 Final Office Action mailed Feb. 14, 2022”, NPL-824 , 11 pages. [cited by applicant]
“U.S. Appl. No. 16/383,335 Final Office Action mailed Jun. 8, 2021”, NPL-700 , 14 pages. [cited by applicant]
“U.S. Appl. No. 16/383,335 Non-Final Office Action mailed Sep. 16, 2021”, NPL-792 , 10 pages. [cited by applicant]
“U.S. Appl. No. 16/383,335 Non-Final Office Action mailed Dec. 10, 2020”, NPL-654 , 14 pages. [cited by applicant]
“U.S. Appl. No. 16/383,335 Notice of Allowance mailed Apr. 19, 2022”, NPL-854 , 9 pages. [cited by applicant]
“U.S. Appl. No. 16/383,335 Notice of Allowance mailed Jul. 28, 2022”, NPL-868 , 8 pages. [cited by applicant]
“U.S. Appl. No. 16/383,335 Notice of Allowance mailed Nov. 10, 2022”, NPL-892 , 5 pages. [cited by applicant]
“U.S. Appl. No. 16/383,407 Non-Final Office Action mailed Nov. 18, 2020”, NPL-655 , 28 pages. [cited by applicant]
“U.S. Appl. No. 16/383,407 Notice of Allowance mailed Mar. 25, 2021”, NPL-683 , 10 pages. [cited by applicant]
“U.S. Appl. No. 16/383,407 Notice of Allowance mailed Apr. 9, 2021”, NPL-694 , 12 pages. [cited by applicant]
“U.S. Appl. No. 17/373,916 Non-Final Office Action mailed Sep. 28, 2022”, NPL-879 , 71 pages. [cited by applicant]
“U.S. Appl. No. 17/373,916 Notice of Allowance mailed Jan. 25, 2023”, NPL-966 , 8 pages. [cited by applicant]
“U.S. Appl. No. 18/096,882 Non-Final Office Action mailed Aug. 3, 2023”, , 12 pages. [cited by applicant]
“U.S. Appl. No. 18/096,882 Notice of Allowance mailed Jan. 26, 2024”, , 11 pages. [cited by applicant]
WIPO, , “Application No. PCT/US19/27320 International Preliminary Report on Patentability mailed Oct. 22, 2020”, NPL-630 , 17 pages. [cited by applicant]
ISA, , “PCT Application No. PCT/US19/27320 International Search Report and Written Opinion mailed Aug. 19, 2019”, NPL-465 , 21 pages. [cited by applicant]
IPO, , “UK Application No. 2017906.5 Search and Examination Report mailed Jun. 20, 2022”, NPL-863 , 6 pages. [cited by applicant]
UKIPO, , “UK Application No. 2216072.5 Search and Examination Report mailed Nov. 29, 2022”, NPL-894 , 6 pages. [cited by applicant]
UKIPO, , “UK Application No. 2302847.5 Search and Examination Report mailed Mar. 17, 2023”, NPL-968 , 6 pages. [cited by applicant]