Generating user-specific polygraphs for network activity

US11916947B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-11916947-B2
Application numberUS-202217810978-A
CountryUS
Kind codeB2
Filing dateJul 6, 2022
Priority dateNov 27, 2017
Publication dateFeb 27, 2024
Grant dateFeb 27, 2024

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Generating user-specific polygraphs for network activity, including: gathering information describing network activity associated with a user and generating, based on the information, a user-specific polygraph that includes one or more destinations associated with the network activity.

First claim

Opening claim text (preview).

What is claimed is: 1. A method comprising: gathering information describing network activity associated with a user; and generating, based on the information, a user-specific visualization comprising a graph of a plurality of linked visual representations, wherein the plurality of linked visual representations comprises one or more first visual representations corresponding to one or more destinations accessed by the user and one or more second visual representations linked describing access to the one or more destinations and to the one or more first visualizations, wherein the one or more destinations share a same destination type, wherein the same destination type comprises a Software-as-a-Service (SaaS) application. 2. The method of claim 1 wherein the same destination type comprises a private application. 3. The method of claim 1 wherein the same destination type comprises document. 4. The method of claim 1 wherein the same destination type comprises a shadow application. 5. The method of claim 1 wherein the same destination type comprises a website, and wherein the method further comprises: calculating, for each website of one or more websites, a risk score based on a degree of deviation from normal browsing activity for the user; and wherein generating the user-specific visualization comprises generating the user-specific visualization to include visual representations of those of the one or more websites having a corresponding risk score exceeding a threshold. 6. The method of claim 1 further comprising: determining, based on the information, that the network activity deviates from normal activity for the user and including, in the user-specific visualization, an alert that the network activity deviates from normal activity for the user. 7. The method of claim 1 wherein the one or more second visual representations correspond to one or more access types for the network activity. 8. The method of claim 1 wherein the one or more second visual representations correspond to one or more access time groupings for the network activity. 9. A computer program product disposed on a non-transitory computer readable medium, the computer program product including computer program instructions configurable to carry out the steps of: gathering information describing network activity associated with a user; and generating, based on the information, a user-specific visualization comprising a graph of a plurality of linked visual representations, wherein the plurality of linked visual representations comprises one or more first visual representations corresponding to one or more destinations accessed by the user and one or more second visual representations linked describing access to the one or more destinations and to the one or more first visualizations, wherein the one or more destinations share a same destination type, wherein the same destination type comprises a Software-as-a-Service (SaaS) application. 10. The computer program product of claim 9 wherein the same destination type comprises a private application. 11. The computer program product of claim 9 wherein the same destination type comprises document. 12. The computer program product of claim 9 wherein the same destination type comprises a shadow application. 13. The computer program product of claim 9 wherein the same destination type comprises a website, and wherein the steps further comprise: calculating, for each website of one or more websites, a risk score based on a degree of deviation from normal browsing activity for the user; and wherein generating the user-specific visualization comprises generating the user-specific visualization to include visual representations of those of the one or more websites having a corresponding risk score exceeding a threshold. 14. The computer program product of claim 9 wherein the steps further comprise: determining, based on the information, that the network activity deviates from normal activity for the user and including, in the user-specific visualization, an alert that the network activity deviates from normal activity for the user. 15. The computer program product of claim 9 wherein the one or more second visual representations correspond to one or more access types for the network activity. 16. The computer program product of claim 9 wherein the one or more second visual representations correspond to one or more access time groupings for the network activity.

Assignees

Inventors

Classifications

  • Traffic logging, e.g. anomaly detection · CPC title

  • Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines · CPC title

  • where tasks reside in different layers, e.g. user- and kernel-space · CPC title

  • Graphs; Linked lists (G06F16/9027 takes precedence) · CPC title

  • Presentation of query results · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US11916947B2 cover?
Generating user-specific polygraphs for network activity, including: gathering information describing network activity associated with a user and generating, based on the information, a user-specific polygraph that includes one or more destinations associated with the network activity.
Who is the assignee on this patent?
Lacework Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Feb 27 2024 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).