Security analytics system for performing an interaction classification operation

US12400002B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12400002-B2
Application numberUS-202217991026-A
CountryUS
Kind codeB2
Filing dateNov 21, 2022
Priority dateDec 30, 2021
Publication dateAug 26, 2025
Grant dateAug 26, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A system, method, and computer-readable medium are disclosed for performing entity interaction risk analysis operation. The entity interaction risk analysis operation includes: monitoring an entity, the monitoring observing an electronically-observable data source; identifying an interaction between the entity and another entity based upon the monitoring; analyzing the interaction between the entity and the another entity; classifying the interaction between the entity and the another entity; and, performing a security operation in response to the analyzing the interaction and the classifying the interaction.

First claim

Opening claim text (preview).

What is claimed is: 1. A computer-implementable method for performing an entity interaction risk analysis operation, comprising: monitoring an entity that is a member of an organization, the monitoring observing an electronically-observable data source, the monitoring being performed via an endpoint device; identifying a security related activity associated with the entity; identifying an interaction between the entity and another entity based upon the monitoring; analyzing the interaction between the entity and the another entity; classifying the interaction between the entity and the another entity, the classifying performing a phrase analysis operation on the interaction, the phrase analysis operation identifying at least one phrase associated with an organizational interaction in furtherance of an objective of the organization; generating a security risk score based upon the security related activity associated with the entity, the security risk score representing a security risk corresponding to a particular indicator of behavior (IOB), the analyzing the interaction between the entity and the another entity and the interaction between the entity and the another entity; and, performing a security operation that mitigates an identified security risk in response to the analyzing the interaction and the classifying the interaction, the security operation taking into account the security risk score, the security operation being performed by at least one of the endpoint device and a security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing on a hardware processor associated with the security analytics system. 2. The method of claim 1 , wherein: the entity comprises a user entity and the another entity comprises another user entity. 3. The method of claim 1 , wherein: the classifying the interaction comprises classifying the interaction as at least one of a personal interaction and an organizational interaction. 4. The method of claim 1 , wherein: the classifying performs a grammatical analysis operation on the interaction, the grammatical analysis operation identifying at least one grammar characteristic associated with a personal communication, the grammar characteristic relating to usage of various parts of speech, diction, style and proper punctuation. 5. The method of claim 1 , wherein: the phrase analysis operation identifies at least one acronym associated with an organizational interaction in furtherance of an objective of the organization. 6. The method of claim 1 , wherein: the classifying includes generating a classification score and the interaction is classified as at least one of a personal interaction and an organization interaction when the classification score is above a predetermined threshold. 7. A system comprising: a processor; a data bus coupled to the processor; and a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for: monitoring an entity that is a member of an organization, the monitoring observing an electronically-observable data source; identifying a security related activity associated with the entity; identifying an interaction between the entity and another entity based upon the monitoring; analyzing the interaction between the entity and the another entity; classifying the interaction between the entity and the another entity, the classifying performing a phrase analysis operation on the interaction, the phrase analysis operation identifying at least one phrase associated with an organizational interaction in furtherance of an objective of the organization; generating a security risk score based upon the security related activity associated with the entity, the security risk score representing a security risk corresponding to a particular indicator of behavior (IOB), the analyzing the interaction between the entity and the another entity and the interaction between the entity and the another entity; and, performing a security operation that mitigates an identified security risk in response to the analyzing the interaction and the classifying the interaction, the security operation taking into account the security risk score, the security operation being performed by at least one of the endpoint device and a security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing on a hardware processor associated with the security analytics system. 8. The system of claim 7 , wherein: the entity comprises a user entity and the another entity comprises another user entity. 9. The system of claim 7 , wherein: the classifying the interaction comprises classifying the interaction as at least one of a personal interaction and an organizational interaction. 10. The system of claim 7 , wherein: the classifying performs a grammatical analysis operation on the interaction, the grammatical analysis operation identifying at least one grammar characteristic associated with a personal communication, the grammar characteristic relating to usage of various parts of speech, diction, style and proper punctuation. 11. The system of claim 7 , wherein: the phrase analysis operation identifies at least one acronym associated with an organizational interaction in furtherance of an objective of the organization. 12. The system of claim 7 , wherein: the classifying includes generating a classification score and the interaction is classified as at least one of a personal interaction and an organization interaction when the classification score is above a predetermined threshold. 13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for: monitoring an entity that is a member of an organization, the monitoring observing an electronically-observable data source; identifying a security related activity associated with the entity; identifying an interaction between the entity and another entity based upon the monitoring; analyzing the interaction between the entity and the another entity; classifying the interaction between the entity and the another entity, the classifying performing a phrase analysis operation on the interaction, the phrase analysis operation identifying at least one phrase associated with an organizational interaction in furtherance of an objective of the organization; generating a security risk score based upon the security related activity associated with the entity, the security risk score representing a security risk corresponding to a particular indicator of behavior (IOB), the analyzing the interaction between the entity and the another entity and the interaction between the entity and the another entity; and, performing a security operation that mitigates an identified security risk in response to the analyzing the interaction and the classifying the interaction, the security operation taking into account the security risk score, the security operation being performed by at least one of the endpoint device and a security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system exe

Assignees

Inventors

Classifications

  • Test or assess a computer or a system · CPC title

  • involving long-term monitoring or reporting · CPC title

  • G06F21/577Primary

    Assessing vulnerabilities and evaluating computer system security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12400002B2 cover?
A system, method, and computer-readable medium are disclosed for performing entity interaction risk analysis operation. The entity interaction risk analysis operation includes: monitoring an entity, the monitoring observing an electronically-observable data source; identifying an interaction between the entity and another entity based upon the monitoring; analyzing the interaction between the e…
Who is the assignee on this patent?
Forcepoint Llc, Everfox Holdings Llc
What technology area does this patent fall under?
Primary CPC classification G06F21/577. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Aug 26 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).