×

Protection system including machine learning snapshot evaluation

  • US 9,998,488 B2
  • Filed: 04/04/2017
  • Issued: 06/12/2018
  • Est. Priority Date: 12/19/2013
  • Status: Active Grant
First Claim
Patent Images

1. A system for snapshot evaluation and user behavior classification, comprising:

  • a processor;

    memory circuitry to store at least one user profile;

    communication circuitry to;

    receive user data associated with a user of a device;

    receive device information from the device and one or more other devices; and

    receive a snapshot of operation of the device, the snapshot to identify at least one active operation in the device and at least one planned operation in the device at the time the snapshot was generated; and

    a user behavior classification engine to;

    determine whether the user is a new user;

    determine whether the device is a new device;

    responsive to a determination that the user is a new user;

    generate a new user profile; and

    associate the new user profile with the device;

    responsive to a determination that the device is a new device;

    determine expected device operations based, at least in part, on the received device information; and

    generate a verification to indicate whether the device comprises a potential threat based, at least in part, on a comparison between the received snapshot and the expected device operations;

    responsive to a determination that the device is not a new device and the user is not a new user;

    determine whether a classification of user behavior has been developed;

    responsive to a determination that a classification of user behavior has been developed;

    identify the classification of user behavior based, at least in part, on the received snapshot and the received user data;

    generate a model configuration based on the classification of user behavior; and

    generate a threat analysis indicating whether the device comprises a potential threat based, at least in part, on a comparison between the model configuration and the received snapshot.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×