IP Library › Granted Patent US 12,732,515
Granted Patent B2
US 12,732,515 · App. 18/654,753 · Granted Sep 8, 2026

Cross-platform security threat detection

Inventors: Sanjay Jeyakumar (El Cerrito, CA); Abhijit Bagri (Atlanta, GA); Tejas Khot (Long Island City, NY); Cheng-Lin Yeh (San Mateo, CA); Yingkai Gao (Brooklyn, NY)
Assignee: Abnormal AI, Inc.
H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,515
App. No.
18/654,753
Granted
Sep 8, 2026
Kind
B2
Abstract

In various embodiments, a process for cross-platform security threat detection includes determining that a specific event in a plurality of events from a plurality of different digital service platforms meets a criterion for multievent analysis. The process includes identifying, among the plurality of events, a group of cross-platform events related to the specific event; and analyzing at least the group of cross-platform events to detect a potential security threat. The process includes providing a security threat analysis result associated with the identified group of cross-platform events.

Claims (40)

1 . A method, comprising:

determining that a specific event in a plurality of events from a plurality of different digital service platforms meets a criterion for multievent analysis;

identifying, among the plurality of events, a group of cross-platform events related to the specific event;

analyzing at least the group of cross-platform events to detect a potential security threat; and

providing a security threat analysis result associated with the identified group of cross-platform events, wherein providing the security threat analysis result includes generating a user interface comprising an automatically generated narrative associated with the detection of the potential security threat, the automatically generated narrative is generated based on an abnormality score and a risk score determined for the specific event, the abnormality score is determined independently from the risk score using an abnormality detection machine learning model configured to identify behavior that is unusual for a particular entity, and the risk score is determined using a risk detection machine learning model configured to identify behavior resembling previously seen attack patterns for a plurality of entities.

2 . The method of claim 1 , wherein the group of cross-platform events includes at least one event associated with a first platform and at least one event associated with a second platform.

3 . The method of claim 1 , wherein events included in the group of cross-platform events related to the specific event are related by at least one of: being associated with a particular user, being a notable event, or being associated with a particular entity.

4 . The method of claim 1 , wherein identifying the group of cross-platform events related to the specific event includes filtering events to determine a subset of notable events that are relevant to the specific event.

5 . The method of claim 4 , wherein the filtering is based at least on a similarity between the specific event and other events in the group of cross-platform events with respect to at least one of: time, internet protocol (IP) address, or type.

6 . The method of claim 1 , wherein analyzing at least the group of cross-platform events to detect the potential security threat includes using at least one detector to detect the potential security threat.

7 . The method of claim 6 , wherein each of at least a subset of the at least one detector is configured to detect a respective type of potential security threat.

8 . The method of claim 6 , wherein the at least one detector utilizes rule-based pattern analysis.

9 . The method of claim 6 , wherein the at least one detector detects the potential security threat in response to at least one of:

at least a first number of sign-ins are observed for a user within a time span, at least one sign-in exceeds an abnormal score, and at least one sign-in exceeds a risk score; or

fewer than the first number of sign-ins are observed for the user within the time span, and at least one sign-in exceeds a risk score.

10 . The method of claim 1 , further comprising determining a confidence score associated with the security threat analysis result.

11 . The method of claim 1 , wherein the security threat analysis result includes a history of specific events associated with the detection of the potential security threat.

12 . The method of claim 1 , wherein at least a portion of the security threat analysis result is logged without presenting the security threat analysis result on a user interface.

13 . The method of claim 1 , wherein:

the user interface includes an event card for each event in a group of events associated with the potential security threat; and

the event card includes a dynamically generated reason for why a respective event is included in the group of events.

14 . The method of claim 1 , wherein:

the user interface includes a set of events associated with the automatically generated narrative; and

the set of events is a subset of the plurality of events from the plurality of different digital service platforms meeting the criterion for the multievent analysis.

15 . The method of claim 1 , wherein the user interface specifies a confidence associated with the security threat analysis result.

16 . A system, comprising:

a processor configured to:

determine that a specific event in a plurality of events from a plurality of different digital service platforms meets a criterion for multievent analysis;

identify, among the plurality of events, a group of cross-platform events related to the specific event;

analyze at least the group of cross-platform events to detect a potential security threat; and

provide a security threat analysis result associated with the identified group of cross-platform events, wherein providing the security threat analysis result includes generating a user interface comprising an automatically generated narrative associated with the detection of the potential security threat, the automatically generated narrative is generated based on an abnormality score and a risk score determined for the specific event, the abnormality score is determined independently from the risk score using an abnormality detection machine learning model configured to identify behavior that is unusual for a particular entity, and the risk score is determined using a risk detection machine learning model configured to identify behavior resembling previously seen attack patterns for a plurality of entities; and

a memory coupled to the processor and configured to provide the processor with instructions.

17 . The system of claim 16 , wherein analyzing at least the group of cross-platform events to detect the potential security threat includes using at least one detector to detect the potential security threat.

18 . The system of claim 16 , wherein events included in the group of cross-platform events related to the specific event are related by at least one of: being associated with a particular user, being a notable event, or being associated with a particular entity.

19 . The system of claim 16 , wherein identifying the group of cross-platform events related to the specific event includes filtering events to determine a subset of notable events that are relevant to the specific event.

20 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

determining that a specific event in a plurality of events from a plurality of different digital service platforms meets a criterion for multievent analysis;

identifying, among the plurality of events, a group of cross-platform events related to the specific event;

analyzing at least the group of cross-platform events to detect a potential security threat; and

providing a security threat analysis result associated with the identified group of cross-platform events, wherein providing the security threat analysis result includes generating a user interface comprising an automatically generated narrative associated with the detection of the potential security threat, the automatically generated narrative is generated based on an abnormality score and a risk score determined for the specific event, the abnormality score is determined independently from the risk score using an abnormality detection machine learning model configured to identify behavior that is unusual for a particular entity, and the risk score is determined using a risk detection machine learning model configured to identify behavior resembling previously seen attack patterns for a plurality of entities.

Assignments (4)
SECURITY INTEREST Recorded Jul 23, 2026
From: ABNORMAL AI, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 076064/0692 →
CHANGE OF NAME Recorded Apr 22, 2025
From: ABNORMAL SECURITY CORPORATION
To: ABNORMAL AI, INC.
Reel/Frame 070947/0132 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2025
From: JEYAKUMAR, SANJAY; BAGRI, ABHIJIT; KHOT, TEJAS; YEH, CHENG-LIN; GAO, YINGKAI
To: ABNORMAL SECURITY CORPORATION
Reel/Frame 070729/0877 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2024
From: JEYAKUMAR, SANJAY; KHOT, TEJAS; YEH, CHENG-LIN; GAO, YINGKAI
To: ABNORMAL SECURITY CORPORATION
Reel/Frame 068046/0447 →
Continuity (1)
Related Publication 20250343804A1 · Nov 6, 2025
References Cited (15)
US 11972427B2 · Zevetchin · 2024 [cited by examiner]
US 20100024033A1 · Kang · 2010 [cited by examiner]
US 20140372526A1 · Zaveri · 2014 [cited by applicant]
US 20170279824A1 · Haugsnes · 2017 [cited by applicant]
US 20180004948A1 · Martin · 2018 [cited by applicant]
US 20190132328A1 · Sims · 2019 [cited by examiner]
US 20190132787A1 · Ryan · 2019 [cited by examiner]
US 20210273976A1 · Reiser · 2021 [cited by applicant]
US 20210360027A1 · Boyer · 2021 [cited by applicant]
US 20220286432A1 · Chechik · 2022 [cited by applicant]
US 20220358212A1 · Dixit · 2022 [cited by examiner]
US 20220377093A1 · Crabtree · 2022 [cited by applicant]
US 20230239303A1 · Hutelmyer · 2023 [cited by applicant]
US 20240056405A1 · Wilson · 2024 [cited by examiner]
US 20240155007A1 · Gasiorek · 2024 [cited by applicant]