User in group behavior signature monitor

US12255885B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12255885-B2
Application numberUS-202217804823-A
CountryUS
Kind codeB2
Filing dateMay 31, 2022
Priority dateMay 31, 2022
Publication dateMar 18, 2025
Grant dateMar 18, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system of monitoring a user behavior for abnormalities compared to a group behavior includes a processor configured to implement instructions for a user to group behavior signature monitor (UGBSM) with at least one user, as a monitored user, and a group of one or more users, as baseline users, to access to certain characteristics of the monitored user and certain characteristics of the baseline users, calculate a user behavioral signature of the monitored user, calculate a group behavioral signature of the baseline users, calculate a degree of variance (DoV) between the user behavioral signature of the monitored user and the group behavioral signature of baseline users, and compare the calculated DoV to a variance threshold to determine whether the user behavioral signature of the monitored user is similar or is different from the group behavioral signature of the baseline users.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for monitoring user behavior of a user of a computing system for abnormalities compared to baseline users of the computing system by reference to a database storing information about previously classified activities of a plurality of baseline users, the method comprising: monitoring an activity of the user of the computing system using a behavior signature monitor, wherein the behavior signature monitor is a software module under program control of a microprocessor and wherein the activity comprises one of the previously classified activities; calculating, with the behavior signature monitor, a user behavioral signature for the activity as a new behavior vector of values representing event data from the monitored activity; calculating a group behavioral signature of the plurality of baseline users for the activity, wherein the group behavioral signature of the plurality of baseline users is a previous behavior vector of values representing event data from a previously classified activity corresponding to the monitored activity; calculating a degree of variance (DoV) by mathematical vector multiplication of the user behavioral signature of the user and the group behavioral signature of the plurality of baseline users, wherein the DoV is a distance between the new behavior vector and the previous behavior vector; comparing the calculated DoV to a predetermined variance threshold to determine whether the user behavioral signature of the monitored user is similar or is different from the group behavioral signature of the plurality of baseline users; determining that the user belongs in a group with the plurality of baseline users associated with the group behavioral signature when the calculated DoV is less than or equal the predetermined variance threshold; determining that the user does not belong in the group with the plurality of baseline users associated with the group behavioral signature when the calculated DoV is greater than the predetermined variance threshold; and sending an indication to a destination in the computing system about the determination when the user does not belong to the group with the plurality of baseline users. 2. The method of claim 1 , wherein the monitored activity comprises actions of applications related to the monitored user applications running on behalf of the user, when the user is logged in and logged off, or a resource of the computing system accessed by the user. 3. The method of claim 1 , wherein the monitored activity comprises a beginning, an end, a frequency, or a duration of an event related to the monitored user. 4. The method of claim 1 , wherein the monitored activity comprises observing authentication events related to the monitored user. 5. The method of claim 1 , wherein the monitored activity comprises the user's access to the user's computer, a mobile device of the user, or hardware devices related to the monitored user. 6. The method of claim 1 , wherein the monitored activity comprises activity in a web browser related to the monitored user. 7. The method of claim 1 , wherein the monitored activity comprises network traffic of the user, including one or more of Internet Protocol addresses, port numbers, protocol types, volumes of data sent and received, and types of information sent and received. 8. The method of claim 1 , further comprising performing an analysis of a behavior vector of the user using one or more pre-programmed heuristic rules, statistical analysis, a neural network, or support vector machines. 9. The method of claim 1 , further comprising performing an analysis of a behavior vector of the user to identify a security incident. 10. The method of claim 1 , further comprising performing an action or communicating predetermined information about an identified abnormality of the user based on a behavior vector of the user to at least one destination in the computing system. 11. A system of monitoring user behavior in a computing system for abnormalities compared to a group's behavior in the computing system, the system comprising: a database storing information about previously classified activities of a plurality of baseline users of the computing system; a microprocessor coupled to a memory storing instructions, the microprocessor being configured to: monitor an activity of a user; calculate a user behavioral signature of the monitored user for the monitored activity as a new behavior vector of values representing event data from the monitored activity; calculate a degree of variance (DoV) of the monitored activity from a behavior signature of the previously classified activities, wherein the behavior signature of the previously classified activities is a previous behavior vector of values representing events data related to a previously classified activity corresponding to the monitored activity, and the DoV is a distance between the new behavior vector and the previous behavior vector calculated by mathematical vector multiplication; compare the calculated DoV to a predetermined variance threshold; determine that the user belongs in a group with the plurality of baseline users associated with the behavior signature of the previously classified activities when the calculated DoV is less than or equal the predetermined variance threshold; determine that the user does not belong in the group with the plurality of baseline users associated with the behavior signature of the previously classified activities when the calculated DoV is greater than the predetermined variance threshold; and send an indication to a destination in the computing system about the determination when the user does not belong to the group with the plurality of baseline users. 12. The system of claim 11 , wherein the monitored activity comprises actions of applications related to the monitored user applications running on behalf of the user, when the user is logged in and logged off, or a resource of the computing system accessed by the user. 13. The system of claim 11 , wherein the monitored activity comprises a beginning, an end, a frequency, or a duration of events related to the monitored user. 14. The system of claim 11 , wherein the monitored activity comprises authentication events related to the monitored user. 15. The system of claim 11 , wherein the monitored activity comprises the user's access to the user's computer, a mobile device of the user, or hardware devices related to the monitored user. 16. The system of claim 11 , wherein the monitored activity comprises activity in a web browser related to the monitored user. 17. The system of claim 11 , wherein the monitored activity comprises network traffic of the user, including one or more of Internet Protocol addresses, port numbers, protocol types, types of peripheral devices, volumes of data sent and received, and types of information sent and received. 18. The system of claim 11 , wherein the microprocessor is further configured to perform an analysis of a behavior vector of the user using one or more of predetermined heuristic rules, statistical analysis, a neural network, or support vector machines. 19. The system of claim 11 , wherein the microprocessor is further configured to perform an analysis of a behavior vector of the user to identify a security incident. 20. The system of claim 11 , wherein the microprocessor is further configured to perform an action or communicate information about an identified abnormality of the user based on a behavior vector of the user

Assignees

Inventors

Classifications

  • H04L63/102Primary

    Entity profiles · CPC title

  • Event detection, e.g. attack signature detection · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title

  • H04L63/083Primary

    using passwords (cryptographic mechanisms or cryptographic arrangements for entity authentication using a predetermined code H04L9/3226) · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12255885B2 cover?
A system of monitoring a user behavior for abnormalities compared to a group behavior includes a processor configured to implement instructions for a user to group behavior signature monitor (UGBSM) with at least one user, as a monitored user, and a group of one or more users, as baseline users, to access to certain characteristics of the monitored user and certain characteristics of the baseli…
Who is the assignee on this patent?
Acronis Int Gmbh
What technology area does this patent fall under?
Primary CPC classification H04L63/102. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 18 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).