System and method for deriving network address spaces affected by security threats to apply mitigations
US-2023147714-A1 · May 11, 2023 · US
US12400002B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-12400002-B2 |
| Application number | US-202217991026-A |
| Country | US |
| Kind code | B2 |
| Filing date | Nov 21, 2022 |
| Priority date | Dec 30, 2021 |
| Publication date | Aug 26, 2025 |
| Grant date | Aug 26, 2025 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A system, method, and computer-readable medium are disclosed for performing entity interaction risk analysis operation. The entity interaction risk analysis operation includes: monitoring an entity, the monitoring observing an electronically-observable data source; identifying an interaction between the entity and another entity based upon the monitoring; analyzing the interaction between the entity and the another entity; classifying the interaction between the entity and the another entity; and, performing a security operation in response to the analyzing the interaction and the classifying the interaction.
Opening claim text (preview).
What is claimed is: 1. A computer-implementable method for performing an entity interaction risk analysis operation, comprising: monitoring an entity that is a member of an organization, the monitoring observing an electronically-observable data source, the monitoring being performed via an endpoint device; identifying a security related activity associated with the entity; identifying an interaction between the entity and another entity based upon the monitoring; analyzing the interaction between the entity and the another entity; classifying the interaction between the entity and the another entity, the classifying performing a phrase analysis operation on the interaction, the phrase analysis operation identifying at least one phrase associated with an organizational interaction in furtherance of an objective of the organization; generating a security risk score based upon the security related activity associated with the entity, the security risk score representing a security risk corresponding to a particular indicator of behavior (IOB), the analyzing the interaction between the entity and the another entity and the interaction between the entity and the another entity; and, performing a security operation that mitigates an identified security risk in response to the analyzing the interaction and the classifying the interaction, the security operation taking into account the security risk score, the security operation being performed by at least one of the endpoint device and a security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing on a hardware processor associated with the security analytics system. 2. The method of claim 1 , wherein: the entity comprises a user entity and the another entity comprises another user entity. 3. The method of claim 1 , wherein: the classifying the interaction comprises classifying the interaction as at least one of a personal interaction and an organizational interaction. 4. The method of claim 1 , wherein: the classifying performs a grammatical analysis operation on the interaction, the grammatical analysis operation identifying at least one grammar characteristic associated with a personal communication, the grammar characteristic relating to usage of various parts of speech, diction, style and proper punctuation. 5. The method of claim 1 , wherein: the phrase analysis operation identifies at least one acronym associated with an organizational interaction in furtherance of an objective of the organization. 6. The method of claim 1 , wherein: the classifying includes generating a classification score and the interaction is classified as at least one of a personal interaction and an organization interaction when the classification score is above a predetermined threshold. 7. A system comprising: a processor; a data bus coupled to the processor; and a non-transitory, computer-readable storage medium embodying computer program code, the non-transitory, computer-readable storage medium being coupled to the data bus, the computer program code interacting with a plurality of computer operations and comprising instructions executable by the processor and configured for: monitoring an entity that is a member of an organization, the monitoring observing an electronically-observable data source; identifying a security related activity associated with the entity; identifying an interaction between the entity and another entity based upon the monitoring; analyzing the interaction between the entity and the another entity; classifying the interaction between the entity and the another entity, the classifying performing a phrase analysis operation on the interaction, the phrase analysis operation identifying at least one phrase associated with an organizational interaction in furtherance of an objective of the organization; generating a security risk score based upon the security related activity associated with the entity, the security risk score representing a security risk corresponding to a particular indicator of behavior (IOB), the analyzing the interaction between the entity and the another entity and the interaction between the entity and the another entity; and, performing a security operation that mitigates an identified security risk in response to the analyzing the interaction and the classifying the interaction, the security operation taking into account the security risk score, the security operation being performed by at least one of the endpoint device and a security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system executing on a hardware processor associated with the security analytics system. 8. The system of claim 7 , wherein: the entity comprises a user entity and the another entity comprises another user entity. 9. The system of claim 7 , wherein: the classifying the interaction comprises classifying the interaction as at least one of a personal interaction and an organizational interaction. 10. The system of claim 7 , wherein: the classifying performs a grammatical analysis operation on the interaction, the grammatical analysis operation identifying at least one grammar characteristic associated with a personal communication, the grammar characteristic relating to usage of various parts of speech, diction, style and proper punctuation. 11. The system of claim 7 , wherein: the phrase analysis operation identifies at least one acronym associated with an organizational interaction in furtherance of an objective of the organization. 12. The system of claim 7 , wherein: the classifying includes generating a classification score and the interaction is classified as at least one of a personal interaction and an organization interaction when the classification score is above a predetermined threshold. 13. A non-transitory, computer-readable storage medium embodying computer program code, the computer program code comprising computer executable instructions configured for: monitoring an entity that is a member of an organization, the monitoring observing an electronically-observable data source; identifying a security related activity associated with the entity; identifying an interaction between the entity and another entity based upon the monitoring; analyzing the interaction between the entity and the another entity; classifying the interaction between the entity and the another entity, the classifying performing a phrase analysis operation on the interaction, the phrase analysis operation identifying at least one phrase associated with an organizational interaction in furtherance of an objective of the organization; generating a security risk score based upon the security related activity associated with the entity, the security risk score representing a security risk corresponding to a particular indicator of behavior (IOB), the analyzing the interaction between the entity and the another entity and the interaction between the entity and the another entity; and, performing a security operation that mitigates an identified security risk in response to the analyzing the interaction and the classifying the interaction, the security operation taking into account the security risk score, the security operation being performed by at least one of the endpoint device and a security analytics system, the endpoint device executing the security operation on a hardware processor associated with the endpoint device, the security analytics system exe
Test or assess a computer or a system · CPC title
involving long-term monitoring or reporting · CPC title
Assessing vulnerabilities and evaluating computer system security · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.