Using an entity behavior profile when performing human-centric risk modeling operations

US12212581B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12212581-B2
Application numberUS-202418425915-A
CountryUS
Kind codeB2
Filing dateJan 29, 2024
Priority dateMay 15, 2017
Publication dateJan 28, 2025
Grant dateJan 28, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system, method, and computer-readable medium for performing a security operation. The security operation includes: monitoring an entity, the monitoring observing at least one electronically-observable data source; identifying a security related activity, the security related activity being of analytic utility; accessing an entity behavior profile based upon the security related activity, the entity behavior profile comprising a collection of information uniquely describing an identity and behavior of the entity; identifying a risk associated with the entity using a human-centric risk modeling framework, the human-centric risk modeling framework enabling quantification of a human-centric factor associated with the entity, the human-centric factor comprising a motivation factor, a stressor factor and an organizational dynamics stressor factor, the human-centric factor having an associated effect on the entity, the motivation factor representing a motivation for enacting an entity behavior, the stressor factor representing an issue influencing the user entity behavior, the organizational stressor factor representing an event occurring within an organization affecting the entity behavior; and, performing a security operation based upon the risk associated with the entity, the security operation using the human-centric risk modeling framework and the entity behavior profile, the security operation being performed by at least one of an endpoint device and a security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing the security operation on a hardware processor associated with the security analytics system.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implementable method for performing a security operation, comprising: monitoring an entity, the monitoring observing at least one electronically-observable data source; identifying a security related activity of the entity, the security related activity being of analytic utility; accessing an entity behavior profile based upon the security related activity, the entity behavior profile comprising a collection of information uniquely describing an identity and behavior of the entity; identifying a risk associated with the entity using a human-centric risk modeling framework, the human-centric risk modeling framework enabling quantification of a human-centric factor associated with the entity, the human-centric factor comprising a motivation factor, a stressor factor and an organizational dynamics stressor factor, the human-centric factor having an associated effect on the entity, the motivation factor representing a motivation for enacting an entity behavior, the stressor factor representing an issue influencing the user entity behavior, the organizational stressor factor representing an event occurring within an organization affecting the entity behavior; and, performing a security operation based upon the risk associated with the entity, the security operation using the human-centric risk modeling framework and the entity behavior profile, the security operation being performed by at least one of an endpoint device and a security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing the security operation on a hardware processor associated with the security analytics system. 2. The method of claim 1 , wherein: the entity behaviors comprise at least one of a user entity behavior and a non-user entity behavior. 3. The method of claim 2 , wherein: an entity behavior has an associated attribute, the associated attribute comprising at least one of a user entity attribute associated with the user entity behavior and a non-user entity attribute associated with the non-user entity behavior. 4. The method of claim 1 , wherein: the human-centric risk modeling framework comprises at least one of a user entity behavior, a security risk use case, a kill chain phase, a security risk persona, a user entity predisposition, a security vulnerability scenario, a concerning behavior and a contextual modifier. 5. The method of claim 4 , wherein: the concerning behavior comprises an associated concerning behavior score, the security risk persona comprises an associated persona baseline risk score, and the user entity behavior comprises the security related activity. 6. The method of claim 1 , wherein: the security operation uses the entity behavior profile to determine whether an event is of analytic utility. 7. A system comprising: a processor; a data bus coupled to the processor; and a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for: monitoring an entity, the monitoring observing at least one electronically-observable data source; identifying a security related activity of the entity, the security related activity being of analytic utility; accessing an entity behavior profile based upon the security related activity, the entity behavior profile comprising a collection of information uniquely describing an identity and behavior of the entity; identifying a risk associated with the entity using a human-centric risk modeling framework, the human-centric risk modeling framework enabling quantification of a human-centric factor associated with the entity, the human-centric factor comprising a motivation factor, a stressor factor and an organizational dynamics stressor factor, the human-centric factor having an associated effect on the entity, the motivation factor representing a motivation for enacting an entity behavior, the stressor factor representing an issue influencing the user entity behavior, the organizational stressor factor representing an event occurring within an organization affecting the entity behavior; and, performing a security operation based upon the risk associated with the entity, the security operation using the human-centric risk modeling framework and the entity behavior profile, the security operation being performed by at least one of an endpoint device and a security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing the security operation on a hardware processor associated with the security analytics system. 8. The system of claim 7 , wherein: the entity behaviors comprise at least one of a user entity behavior and a non-user entity behavior. 9. The system of claim 8 , wherein: an entity behavior has an associated attribute, the associated attribute comprising at least one of a user entity attribute associated with the user entity behavior and a non-user entity attribute associated with the non-user entity behavior. 10. The system of claim 7 , wherein: the human-centric risk modeling framework comprises at least one of a user entity behavior, a security risk use case, a kill chain phase, a security risk persona, a user entity predisposition, a security vulnerability scenario, a concerning behavior and a contextual modifier. 11. The system of claim 10 , wherein: the concerning behavior comprises an associated concerning behavior score, the security risk persona comprises an associated persona baseline risk score, and the user entity behavior comprises the security related activity. 12. The system of claim 11 , wherein: the security operation uses the entity behavior profile to determine whether an event is of analytic utility. 13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for: monitoring an entity, the monitoring observing at least one electronically-observable data source; identifying a security related activity of the entity, the security related activity being of analytic utility; accessing an entity behavior profile based upon the security related activity, the entity behavior profile comprising a collection of information uniquely describing an identity and behavior of the entity; identifying a risk associated with the entity using a human-centric risk modeling framework, the human-centric risk modeling framework enabling quantification of a human-centric factor associated with the entity, the human-centric factor comprising a motivation factor, a stressor factor and an organizational dynamics stressor factor, the human-centric factor having an associated effect on the entity, the motivation factor representing a motivation for enacting an entity behavior, the stressor factor representing an issue influencing the user entity behavior, the organizational stressor factor representing an event occurring within an organization affecting the entity behavior; and, performing a security operation based upon the risk associated with the entity, the security operation using the human-centric risk modeling framework and the entity behavior profile, the security operation being performed by at least one of an endpoint device and a security analytics system, the endpoint

Assignees

Inventors

Classifications

  • User profiles · CPC title

  • involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved (negotiation of communication capabilities H04L69/24) · CPC title

  • Vulnerability analysis · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • Event detection, e.g. attack signature detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12212581B2 cover?
A system, method, and computer-readable medium for performing a security operation. The security operation includes: monitoring an entity, the monitoring observing at least one electronically-observable data source; identifying a security related activity, the security related activity being of analytic utility; accessing an entity behavior profile based upon the security related activity, the …
Who is the assignee on this patent?
Forcepoint Llc
What technology area does this patent fall under?
Primary CPC classification H04L63/14. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jan 28 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).