-
公开(公告)号:US11630902B2
公开(公告)日:2023-04-18
申请号:US16791445
申请日:2020-02-14
Applicant: Forcepoint, LLC
Inventor: Alan Ross , Raffael Marty , Margaret Cunningham , Ruchika Pandey
Abstract: A system, method, and computer-readable medium are disclosed for performing an entity behavior cataloging operation. The entity behavior cataloging operation includes: identifying a plurality of security related activities, the plurality of security related activities being based upon observables from an electronic data source; analyzing the plurality of security related activities, the analyzing identifying a set of entity behaviors associated with the plurality of security related activities; and, performing a security operation via a security system, the security operation accessing entity behavior catalog data stored within an entity behavior catalog based upon the set of entity behaviors associated with the plurality of security related activities, the entity behavior catalog providing an inventory of entity behaviors for use when performing the security operation.
-
公开(公告)号:US20210224395A1
公开(公告)日:2021-07-22
申请号:US16791454
申请日:2020-02-14
Applicant: Forcepoint, LLC
Inventor: Alan Ross , Raffael Marty , Margaret Cunningham , Ruchika Pandey
IPC: G06F21/57
Abstract: A system, method, and computer-readable medium are disclosed for performing an entity behavior cataloging operation. The entity behavior cataloging operation includes: identifying a plurality of security related activities, the plurality of security related activities being based upon an observable from an electronic data source; analyzing the plurality of security related activities, the analyzing identifying a plurality of events of analytic utility associated with the plurality of security related activities; generating a set of entity behavior catalog data based upon the event of analytic utility associated with the security related activity, the set of entity behavior catalog data comprising an associated group of behaviors; and, storing the set of entity behavior data and the associated group of behaviors within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation.
-
公开(公告)号:US11411990B2
公开(公告)日:2022-08-09
申请号:US16277468
申请日:2019-02-15
Applicant: Forcepoint LLC
Inventor: Ruchika Pandey , Ran Mosessco
IPC: H04L9/40
Abstract: A method, system, and computer-usable medium are disclosed for establishing a reference outbound email volume rate for a user account, monitoring the user account to determine a current outbound email volume rate, determining a risk score based on the current outbound email volume rate and the reference outbound email volume rate, buffering outgoing emails of the user account if the risk score exceeds a threshold risk score, analyzing the buffered emails against one or more factors indicative of a probability of the buffered emails comprising spam, and responsive to analysis of the buffered emails against the one or more factors indicating that the user account is potentially compromised, quarantine the user account and prevent outbound mail from being delivered from the user account.
-
公开(公告)号:US20210226970A1
公开(公告)日:2021-07-22
申请号:US16791445
申请日:2020-02-14
Applicant: Forcepoint, LLC
Inventor: Alan Ross , Raffael Marty , Margaret Cunningham , Ruchika Pandey
IPC: H04L29/06
Abstract: A system, method, and computer-readable medium are disclosed for performing an entity behavior cataloging operation. The entity behavior cataloging operation includes: identifying a plurality of security related activities, the plurality of security related activities being based upon observables from an electronic data source; analyzing the plurality of security related activities, the analyzing identifying a set of entity behaviors associated with the plurality of security related activities; and, performing a security operation via a security system, the security operation accessing entity behavior catalog data stored within an entity behavior catalog based upon the set of entity behaviors associated with the plurality of security related activities, the entity behavior catalog providing an inventory of entity behaviors for use when performing the security operation.
-
公开(公告)号:US11295023B2
公开(公告)日:2022-04-05
申请号:US16791454
申请日:2020-02-14
Applicant: Forcepoint, LLC
Inventor: Alan Ross , Raffael Marty , Margaret Cunningham , Ruchika Pandey
Abstract: A system, method, and computer-readable medium are disclosed for performing an entity behavior cataloging operation. The entity behavior cataloging operation includes: identifying a plurality of security related activities, the plurality of security related activities being based upon an observable from an electronic data source; analyzing the plurality of security related activities, the analyzing identifying a plurality of events of analytic utility associated with the plurality of security related activities; generating a set of entity behavior catalog data based upon the event of analytic utility associated with the security related activity, the set of entity behavior catalog data comprising an associated group of behaviors; and, storing the set of entity behavior data and the associated group of behaviors within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation.
-
-
-
-