Invention Grant
- Patent Title: Leveraging user-behavior analytics for improved security event classification
-
Application No.: US16709352Application Date: 2019-12-10
-
Publication No.: US11588839B2Publication Date: 2023-02-21
- Inventor: Udi Yavo , Roy Katmor , Ido Kelson
- Applicant: Fortinet, Inc.
- Applicant Address: US CA Sunnyvale
- Assignee: Fortinet, Inc.
- Current Assignee: Fortinet, Inc.
- Current Assignee Address: US CA Sunnyvale
- Agency: HDC Intellectual Property Law, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F16/28 ; G06N20/00 ; H04L9/40

Abstract:
Systems and methods for improving security event classification by leveraging user-behavior analytics are provided. According to an embodiment, a UEBA-based security event classification service of a cloud-based security platform maintains information regarding historical user behavior of various users of an enterprise network. An endpoint protection platform running on an endpoint device that is part of the enterprise network performs an initial classification of the event, based on which the endpoint protection platform blocks activity by the process. The endpoint production platform requests input from the cloud-based security platform which causes the cloud-based security platform performs a reclassification of the event based on contextual information, multiple data feeds and the UEBA-based security event classification service. Based on the reclassification of the event, the cloud-based security platform causes the endpoint protection platform to allow the process to proceed by providing the resulting security event classification to the endpoint protection platform.
Public/Granted literature
- US20210176264A1 LEVERAGING USER-BEHAVIOR ANALYTICS FOR IMPROVED SECURITY EVENT CLASSIFICATION Public/Granted day:2021-06-10
Information query