Systems and methods for automated anomalous behavior detection and risk-scoring individuals

US12335280B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12335280-B2
Application numberUS-202318195315-A
CountryUS
Kind codeB2
Filing dateMay 9, 2023
Priority dateJan 11, 2021
Publication dateJun 17, 2025
Grant dateJun 17, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A computing system comprising a processing circuit is configured to receive, via a data channel from an agentless monitoring data source, user activity data associated with a first computing device of a first user, determine a policy violation based on the user activity data, compare employee-related information associated with the first user to a threshold, determine a baseline level of risk based on the employee-related information exceeding the threshold, determine a user score based on at least one of a threat dimension or an exposure dimension or an impact dimension, determine a probability of an adverse event based on the determined baseline level of risk and the user score, generate a user-interactive electronic notification comprising an indication of the probability of the adverse event, and transmit the user-interactive electronic notification to a second computing device of a second user.

First claim

Opening claim text (preview).

What is claimed is: 1. A computing system comprising one or more processors configured to: receive, via a data channel from an agentless monitoring data source, user activity data associated with a first computing device of a first user; determine a policy violation based on the user activity data; compare employee-related information associated with the first user to a threshold; determine a baseline level of risk based on the employee-related information exceeding the threshold; determine a user score based on an impact dimension and at least one of a threat dimension or an exposure dimension, wherein the impact dimension comprises a permissions component defining a number of active accounts accessible by the first user and an access component defining a number of inactive accounts associated with the first user, the threat dimension comprises a relative component, and the exposure dimension comprises a technical component; determine a probability of an adverse event based on the baseline level of risk and the user score; generate a user-interactive electronic notification comprising an indication of the probability of the adverse event; and transmit the user-interactive electronic notification to a second computing device. 2. The computing system of claim 1 , wherein the agentless monitoring data source is different from the first computing device, and wherein the agentless monitoring data source is a storage array, a network device, a server, or a hypervisor. 3. The computing system of claim 1 , wherein the agentless monitoring data source comprises computer-executable code executed from the first computing device, the one or more processors configured to parse the user activity data from the computer-executable code. 4. The computing system of claim 1 , wherein the user activity data further comprises data generated by a logging agent executed on the first computing device. 5. The computing system of claim 1 , wherein the user activity data comprises use data pertaining to the first computing device. 6. The computing system of claim 1 , wherein the user activity data comprises Internet traffic data from the first computing device. 7. The computing system of claim 1 , wherein the policy violation comprises at least one of an infiltration characteristic associated with an event indicative of data loss or a flight characteristic associated with an event indicative of a departure. 8. The computing system of claim 7 , wherein the employee-related information comprises performance evaluation data associated with the first user. 9. The computing system of claim 7 , wherein the employee-related information comprises job role and seniority data associated with the first user. 10. The computing system of claim 1 , wherein the data channel is a batch channel and wherein the one or more processors receive the user activity data at predetermined time intervals. 11. The computing system of claim 1 , the one or more processors further configured to: activate a logging agent on the first computing device based on the probability of the adverse event. 12. The computing system of claim 1 , wherein the data channel is a synchronous channel and wherein the one or more processors receive the user activity data in substantially real-time. 13. The computing system of claim 1 , wherein the user-interactive electronic notification comprises a linked training video. 14. A computer-implemented method comprising: receiving, via a data channel from an agentless monitoring data source, user activity data associated with a first computing device of a first user; determining a policy violation based on the user activity data; comparing employee-related information associated with the first user to a threshold; determining a baseline level of risk based on the employee-related information exceeding the threshold; determining a user score based on an impact dimension and at least one of a threat dimension or an exposure dimension, wherein the impact dimension comprises a permissions component defining a number of active accounts accessible by the first user and an access component defining a number of inactive accounts associated with the first user, the threat dimension comprises a relative component defining a behavior of the first user relative to a behavior of a peer of the first user, and the exposure dimension comprises a technical component defining an amount of communication traffic for the first user and a determination of whether a login credential of the first user is compromised; determining a probability of an adverse event based on the baseline level of risk and the user score; generating a user-interactive electronic notification comprising an indication of the probability of the adverse event; and transmitting the user-interactive electronic notification to a second computing device. 15. The computer-implemented method of claim 14 , wherein the agentless monitoring data source is different from the first computing device, and wherein the agentless monitoring data source is a storage array, a network device, a server, or a hypervisor. 16. The computer-implemented method of claim 14 , wherein the user activity data further comprises data generated by a logging agent executed on the first computing device. 17. The computer-implemented method of claim 14 , wherein the user activity data comprises at least one of use data pertaining to the first computing device and Internet traffic data from the first computing device. 18. The computer-implemented method of claim 14 , wherein the policy violation comprises at least one of an infiltration characteristic associated with an event indicative of data loss and a flight characteristic associated with an event indicative of a departure. 19. The computer-implemented method of claim 18 , wherein the employee-related information comprises at least one of performance evaluation data associated with the first user or job role and seniority data associated with the first user, the computer-implemented method further comprising activating a logging agent on the first computing device based on the probability of the adverse event. 20. A non-transitory computer-readable medium comprising instructions stored thereon that, when executed by one or more processors of a computing system, cause the computing system to perform operations comprising: receiving, via a data channel from an agentless monitoring data source, user activity data associated with a first computing device of a first user; determining a policy violation based on the user activity data; comparing employee-related information associated with the first user to a threshold; determining a baseline level of risk based on the employee-related information exceeding the threshold; determining a user score based on an impact dimension, a threat dimension, and an exposure dimension, wherein the impact dimension comprises a permissions component, the threat dimension comprises a relative component defining a behavior of the first user relative to a behavior of peers of the first user, and the exposure dimension comprises a technical component defining an amount of communication traffic for the first user and a determination of whether a login credential of the first user is compromised; determining a probability of an adverse event based on the baseline level of risk and the user score; generating a user-interactive electronic notification comprising an indication of the probability of the adverse event; and transmitting th

Assignees

Inventors

Classifications

  • Vulnerability analysis · CPC title

  • Traffic logging, e.g. anomaly detection · CPC title

  • Performance of employee with respect to a job function · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • Event detection, e.g. attack signature detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12335280B2 cover?
A computing system comprising a processing circuit is configured to receive, via a data channel from an agentless monitoring data source, user activity data associated with a first computing device of a first user, determine a policy violation based on the user activity data, compare employee-related information associated with the first user to a threshold, determine a baseline level of risk b…
Who is the assignee on this patent?
Wells Fargo Bank Na
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jun 17 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).