US 12,289,331 B2
Methods and systems for locating anomalous query activity on data stores
Supreeth Hosur Nagesh Rao, Cupertino, CA (US); Navindra Yadav, Cupertino, CA (US); Ravi Sankuratri, Cupertino, CA (US); Alok Lalit Wadhwa, Milipitas, CA (US); Aria Rahadian, San Jose, CA (US); Brady Schulman, Milford, NH (US); Ravi Shanker Prasad, Fremont, CA (US); Vasil Dochkov Yordanov, San Jose, CA (US); Yiwei Wang, San Jose, CA (US); Zhiwen Zhang, San Jose, CA (US); Udayan Joshi, San Diego, CA (US); Soumyadeep Choudhury, San Jose, CA (US); Muhammada Furqan, Lowell, MA (US); and Danesh Irani, San Carlos, CA (US)
Filed by Supreeth Hosur Nagesh Rao, Cupertino, CA (US); Navindra Yadav, Cupertino, CA (US); Ravi Sankuratri, Cupertino, CA (US); Alok Lalit Wadhwa, Milipitas, CA (US); Aria Rahadian, San Jose, CA (US); Brady Schulman, Milford, NH (US); Ravi Shanker Prasad, Fremont, CA (US); Vasil Dochkov Yordanov, San Jose, CA (US); Yiwei Wang, San Jose, CA (US); Zhiwen Zhang, San Jose, CA (US); Udayan Joshi, San Diego, CA (US); Soumyadeep Choudhury, San Jose, CA (US); Muhammada Furqan, Lowell, MA (US); and Danesh Irani, San Carlos, CA (US)
Filed on Jun. 1, 2022, as Appl. No. 17/829,361.
Application 17/829,361 is a continuation in part of application No. 17/335,932, filed on Jun. 1, 2021, granted, now 12,010,124.
Claims priority of provisional application 63/153,362, filed on Feb. 24, 2021.
Prior Publication US 2023/0018068 A1, Jan. 19, 2023
Int. Cl. H04L 9/40 (2022.01)
CPC H04L 63/1425 (2013.01) 16 Claims
OG exemplary drawing
 
1. A computerized system for locating anomalous query activity,
comprising:
at least one computer processor;
an atypical query engine:
analyzing data within a cloud-based database,
processing all accesses to the data within the cloud-based database and a SAAS environment,
generating a list of user that accesses a table from a location in the cloud-based database, and
capture a set of specified key statistics about the cloud-based database query; and
a role suggestion engine:
generating a user behavior fingerprint comprising a history of the user's behavior within the cloud-based database,
identifying that a user is an outlier with respect to behavior with respect to the set of specified key statistics, and
suggesting a new role within an enterprise managing the cloud-based database for the user, wherein the fingerprint of the outlier user is used to generate the suggestion for the new role.