Adaptive Trust Profile Reference Architecture

    公开(公告)号:US20200342140A1

    公开(公告)日:2020-10-29

    申请号:US16415763

    申请日:2019-05-17

    申请人: Forcepoint LLC

    IPC分类号: G06F21/62 H04L29/08

    摘要: A system, method, and computer-readable medium are disclosed for generating an adaptive trust profile via an adaptive trust profile operation. In various embodiments the adaptive trust profile operation includes: monitoring an electronically-observable action of an entity, the electronically-observable action of the entity corresponding to an event enacted by the entity; converting the electronically-observable action of the entity to electronic information representing the action of the entity; generating an entity profile based upon the action of the entity; and, using the entity profile to generate the adaptive trust profile.

    Inferring a Scenario When Performing a Security Operation Using an Entity Behavior Catalog

    公开(公告)号:US20210226982A1

    公开(公告)日:2021-07-22

    申请号:US16791461

    申请日:2020-02-14

    申请人: Forcepoint, LLC

    IPC分类号: H04L29/06 G06N5/04

    摘要: A system, method, and computer-readable medium are disclosed for performing a security operation. The security operation includes: monitoring an entity, the monitoring observing at least one electronically-observable data source; deriving an observable based upon the monitoring of the electronically-observable data source; identifying a security related activity of the entity, the security related activity being based upon the observable derived from the electronic data source, the security related activity being of analytic utility; converting the security related activity to entity behavior catalog data, the entity behavior catalog providing an inventory of entity behaviors; accessing an entity behavior catalog based upon the entity behavior catalog data; inferring a security vulnerability scenario from the observable derived based upon the monitoring; and performing a security operation via a security system, the security operation using the security vulnerability scenario and the entity behavior catalog data stored within the entity behavior catalog based upon the security related activity.

    Using expected behavior of an entity when prepopulating an adaptive trust profile

    公开(公告)号:US10999297B2

    公开(公告)日:2021-05-04

    申请号:US16557564

    申请日:2019-08-30

    申请人: Forcepoint LLC

    IPC分类号: H04L29/06

    摘要: A system, method, and computer-readable medium are disclosed for generating a prepopulated adaptive trust profile via an adaptive trust profile operation. In various embodiments the adaptive trust profile operation includes: receiving a request to generate a prepopulated adaptive trust profile for a target entity; accessing adaptive trust profile data, the adaptive trust profile data comprising a plurality of adaptive trust profiles; identifying an adaptive trust profile relevant to the entity from the plurality of adaptive trust profiles, the adaptive trust profile relevant to the entity comprising at least one substantively similar entity characteristic to an entity characteristic of the target entity; and, generating an adaptive trust profile for the target entity using the adaptive trust profile relevant to the target entity.

    ADAPTIVE TRUST PROFILE BEHAVIORAL FINGERPRINT

    公开(公告)号:US20200342108A1

    公开(公告)日:2020-10-29

    申请号:US16415771

    申请日:2019-05-17

    申请人: Forcepoint LLC

    IPC分类号: G06F21/57

    摘要: A system, method, and computer-readable medium are disclosed for using a behavioral fingerprint via a behavioral fingerprint operation. In various embodiments the behavioral fingerprint operation includes: monitoring an electronically-observable action of an entity, the electronically-observable action of the entity corresponding to an event enacted by the entity; converting the electronically-observable action of the entity to electronic information representing the action of the entity; generating the behavioral fingerprint based upon observations associated with the action of the entity; and, using the behavioral fingerprint in combination with an adaptive trust profile to generate an inference regarding the entity.

    Entity behavior catalog architecture

    公开(公告)号:US11295022B2

    公开(公告)日:2022-04-05

    申请号:US16791437

    申请日:2020-02-14

    申请人: Forcepoint, LLC

    摘要: A system, method, and computer-readable medium are disclosed for performing an entity behavior cataloging operation. The entity behavior cataloging operation includes: identifying a security related activity, the security related activity being based upon an observable from an electronic data source; analyzing the security related activity, the analyzing identifying an event of analytic utility associated with the security related activity; generating entity behavior catalog data based upon the event of analytic utility associated with the security related activity; and, storing the entity behavior catalog data within an entity behavior catalog, the entity behavior catalog providing an inventory of entity behaviors for use when performing a security operation.

    Adaptive trust profile reference architecture

    公开(公告)号:US10997295B2

    公开(公告)日:2021-05-04

    申请号:US16415763

    申请日:2019-05-17

    申请人: Forcepoint LLC

    摘要: A system, method, and computer-readable medium are disclosed for generating an adaptive trust profile via an adaptive trust profile operation. In various embodiments the adaptive trust profile operation includes: monitoring an electronically-observable action of an entity, the electronically-observable action of the entity corresponding to an event enacted by the entity; converting the electronically-observable action of the entity to electronic information representing the action of the entity; generating an entity profile based upon the action of the entity; and, using the entity profile to generate the adaptive trust profile.

    Adaptive trust profile behavioral fingerprint

    公开(公告)号:US10853496B2

    公开(公告)日:2020-12-01

    申请号:US16415771

    申请日:2019-05-17

    申请人: Forcepoint LLC

    IPC分类号: G06F21/57

    摘要: A system, method, and computer-readable medium are disclosed for using a behavioral fingerprint via a behavioral fingerprint operation. In various embodiments the behavioral fingerprint operation includes: monitoring an electronically-observable action of an entity, the electronically-observable action of the entity corresponding to an event enacted by the entity; converting the electronically-observable action of the entity to electronic information representing the action of the entity; generating the behavioral fingerprint based upon observations associated with the action of the entity; and, using the behavioral fingerprint in combination with an adaptive trust profile to generate an inference regarding the entity.

    Inferring a scenario when performing a security operation using an entity behavior catalog

    公开(公告)号:US11487883B2

    公开(公告)日:2022-11-01

    申请号:US16791461

    申请日:2020-02-14

    申请人: Forcepoint, LLC

    摘要: A system, method, and computer-readable medium are disclosed for performing a security operation. The security operation includes: monitoring an entity, the monitoring observing at least one electronically-observable data source; deriving an observable based upon the monitoring of the electronically-observable data source; identifying a security related activity of the entity, the security related activity being based upon the observable derived from the electronic data source, the security related activity being of analytic utility; converting the security related activity to entity behavior catalog data, the entity behavior catalog providing an inventory of entity behaviors; accessing an entity behavior catalog based upon the entity behavior catalog data; inferring a security vulnerability scenario from the observable derived based upon the monitoring; and performing a security operation via a security system, the security operation using the security vulnerability scenario and the entity behavior catalog data stored within the entity behavior catalog based upon the security related activity.