IP Library Granted Patent US 12705258
Granted Patent B1
US 12705258 · App. 18/985,932 · Granted Aug 11, 2026

Exploratory data analysis system for determination of beaconing risk score

Inventors: Francis Beckert (Mountain View, CA); Kristal Curtis (San Francisco, CA); Om Rajyaguru (San Diego, CA); Abraham Starosta (Boston, MA); Poonam Yadav (San Francisco, CA)
Assignee: Cisco Technology, Inc.
G06F16/285G06F16/248G06F16/9577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12705258
App. No.
18/985,932
Granted
Aug 11, 2026
Kind
B1
Abstract

A search assistant engine that integrates with a data intake and query system and provides an intuitive user interface to assist a user in searching and evaluating indexed event data. Additionally, the search assistant engine provides logic to determine a mutual information score for field groupings derived from a plurality of fields included within a plurality of events, wherein a mutual information score for a first field grouping a level of diversity between values included in the first field grouping, and dynamically update the GUI resulting in display of an illustration of the field groupings according to a mutual information score of each field grouping. Additional operations may include, receiving additional user input corresponding to a search string, wherein the plurality of events obtained from an index are filtered from a larger set of events based on the search string.

Claims (61)

1 . A computerized method comprising:

displaying a graphical user interface (GUI) configured to receive user input indicating selection of an index;

obtaining a plurality of events by (i) processing event data stored in the index, and (ii) applying a schema at search time resulting in extraction of a plurality of fields, wherein each of the plurality of events includes at least a subset of the plurality of fields;

generating a first display portion within the GUI that illustrates a ranked listing of field groupings according to determining a mutual information score for each of the field groupings, wherein the field groupings are derived from the plurality of fields included within the plurality of events obtained from the index, wherein a mutual information score for a first field grouping represents a level of diversity between values included in the first field grouping, and wherein each field grouping comprises a combination of a plurality of fields;

receiving additional user input indicating a selected field grouping of the field groupings from the ranked listing of the field groupings;

generating a second display portion within the GUI that illustrates a comparison of values across fields within the selected field grouping;

automatically generating a search query through importing one or more fields of a selected field grouping into a search query template; and

executing the search query resulting in retrieved data and performing an analysis on the retrieved data resulting in identification of anomalous behavior.

2 . The computerized method of claim 1 , further comprising:

prior to the obtaining of the plurality of events from the index, receiving first user input corresponding to a search string, wherein the plurality of events obtained from the index are filtered from a larger set of events based on the search string.

3 . The computerized method of claim 1 , further comprising:

receiving first user input corresponding to a selection of a pair of fields within the plurality of fields, wherein the pair of fields includes a first field and a second field;

performing a correlation of values of the first field with values of the second field; and

displaying a ranking of the pair of fields among a plurality of pairs of fields based on a result of the correlation.

4 . The computerized method of claim 1 , further comprising:

importing a selected first field of the plurality of fields into a predetermined search query template thereby generating a tailored search query.

5 . The computerized method of claim 4 , further comprising:

executing the tailored search query thereby providing search query results pertaining to previously received user input.

6 . The computerized method of claim 1 , wherein the illustration of the field groupings according to the mutual information score of each field grouping includes a listing of a set of mutual information scores and a set of corresponding field groupings.

7 . The computerized method of claim 1 , wherein the illustration of the field groupings according to the mutual information score of each field grouping is configured to receive first user input corresponding to a selection of a selected field grouping, and wherein receipt of the first user input results in generation of a display portion that provides an illustrative comparison of values across fields of the selected field grouping.

8 . A computing device, comprising:

a processor; and

a non-transitory computer-readable medium having stored thereon instructions that, when executed by the processor, cause the processor to perform operations including:

displaying a graphical user interface (GUI) configured to receive user input indicating selection of an index;

obtaining a plurality of events by (i) processing event data stored in the index, and (ii) applying a schema at search time resulting in extraction of a plurality of fields, wherein each of the plurality of events includes at least a subset of the plurality of fields;

generating a first display portion within the GUI that illustrates a ranked listing of field groupings according to determining a mutual information score for each of the field groupings, wherein the field groupings are derived from the plurality of fields included within the plurality of events obtained from the index, wherein a mutual information score for a first field grouping represents a level of diversity between values included in the first field grouping, and wherein each field grouping comprises a combination of a plurality of fields;

receiving additional user input indicating a selected field grouping of the field groupings from the ranked listing of the field groupings;

generating a second display portion within the GUI that illustrates a comparison of values across fields within the selected field grouping;

automatically generating a search query through importing one or more fields of a selected field grouping into a search query template; and

executing the search query resulting in retrieved data and performing an analysis on the retrieved data resulting in identification of anomalous behavior.

9 . The computing device of claim 8 , wherein the operations further include:

prior to the obtaining of the plurality of events from the index, receiving first user input corresponding to a search string, wherein the plurality of events obtained from the index are filtered from a larger set of events based on the search string.

10 . The computing device of claim 8 , wherein the operations further include:

receiving first user input corresponding to a selection of a pair of fields within the plurality of fields, wherein the pair of fields includes a first field and a second field;

performing a correlation of values of the first field with values of the second field; and

displaying a ranking of the pair of fields among a plurality of pairs of fields based on a result of the correlation.

11 . The computing device of claim 8 , wherein the operations further include:

importing a selected first field of the plurality of fields into a predetermined search query template thereby generating a tailored search query.

12 . The computing device of claim 11 , wherein the operations further include:

executing the tailored search query thereby providing search query results pertaining to previously received user input.

13 . The computing device of claim 8 , wherein the illustration of the field groupings according to the mutual information score of each field grouping includes a listing of a set of mutual information scores and a set of corresponding field groupings.

14 . The computing device of claim 8 , wherein the illustration of the field groupings according to the mutual information score of each field grouping is configured to receive first user input corresponding to a selection of a selected field grouping, and wherein receipt of the additional first user input results in generation of a display portion that provides an illustrative comparison of values across fields of the selected field grouping.

15 . A non-transitory computer-readable medium having stored thereon instructions that, when executed by one or more processors, cause the one or more processor to perform operations including:

displaying a graphical user interface (GUI) configured to receive user input indicating selection of an index;

obtaining a plurality of events by (i) processing event data stored in the index, and (ii) applying a schema at search time resulting in extraction of a plurality of fields, wherein each of the plurality of events includes at least a subset of the plurality of fields;

generating a first display portion within the GUI that illustrates a ranked listing of field groupings according to determining a mutual information score for each of the field groupings, wherein the field groupings are derived from the plurality of fields included within the plurality of events obtained from the index, wherein a mutual information score for a first field grouping represents a level of diversity between values included in the first field grouping, and wherein each field grouping comprises a combination of a plurality of fields;

receiving additional user input indicating a selected field grouping of the field groupings from the ranked listing of the field groupings;

generating a second display portion within the GUI that illustrates a comparison of values across fields within the selected field grouping;

automatically generating a search query through importing one or more fields of a selected field grouping into a search query template; and

executing the search query resulting in retrieved data and performing an analysis on the retrieved data resulting in identification of anomalous behavior.

16 . The non-transitory computer-readable medium of claim 15 , wherein the operations further include:

prior to the obtaining of the plurality of events from the index, receiving first user input corresponding to a search string, wherein the plurality of events obtained from the index are filtered from a larger set of events based on the search string.

17 . The non-transitory computer-readable medium of claim 15 , wherein the operations further include:

receiving first user input corresponding to a selection of a pair of fields within the plurality of fields, wherein the pair of fields includes a first field and a second field;

performing a correlation of values of the first field with values of the second field; and

displaying a ranking of the pair of fields among a plurality of pairs of fields based on a result of the correlation.

18 . The non-transitory computer-readable medium of claim 15 , wherein the operations further include:

importing a selected first field of the plurality of fields into a predetermined search query template thereby generating a tailored search query, and

executing the tailored search query thereby providing search query results pertaining to previously received user input.

19 . The non-transitory computer-readable medium of claim 15 , wherein the illustration of the field groupings according to the mutual information score of each field grouping includes a listing of a set of mutual information scores and a set of corresponding field groupings.

20 . The non-transitory computer-readable medium of claim 15 , wherein the illustration of the field groupings according to the mutual information score of each field grouping is configured to receive first user input corresponding to a selection of a selected field grouping, and wherein receipt of the additional first user input results in generation of a display portion that provides an illustrative comparison of values across fields of the selected field grouping.