IP Library Granted Patent US 8,224,761
Granted Patent B1
US 8,224,761 · App. 11/219,025 · Granted Jul 17, 2012

System and method for interactive correlation rule design in a network security system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,224,761
App. No.
11/219,025
Granted
Jul 17, 2012
Kind
B1
Abstract

A method for generating correlation rules for events comprises receiving event data for each of a plurality of events, the event data of a particular event comprising at least one attribute associated with that event. The method continues by displaying the event data for each of the plurality of events to an operator. The method continues by receiving a selection of at least a portion of the events. The method continues by generating at least one rule that correlates the selected events based at least in part upon the attributes associated with the selected events. The method concludes by displaying the event data to the operator in accordance with the at least one rule.

Claims (93)

1. A method for generating correlation rules for events, comprising:

receiving event data for each of a plurality of events, the event data of a particular event comprising at least one attribute associated with that event;

displaying the event data for each of the plurality of events to an operator, the event data for the plurality of events having been processed according to one or more rules of a ruleset stored in a memory, the event data being displayed in a unified interface for displaying event data processed by rules in the ruleset and for creation of new correlation rules;

receiving a selection made using the unified user interface of at least a portion of the plurality of events for which event data is displayed to the operator in the unified user interface;

generating at least one new rule that correlates the selected events, the at least one new rule generated based at least in part upon a pattern spread among the attributes associated with the selected events, the at least one new rule generated by at least one processor;

storing the at least one new rule and the selection of at least a portion of the events in the memory such that the at least one new rule is added to the ruleset stored in the memory; and

re-displaying, in the unified interface for displaying event data processed by rules in the ruleset and for creation of new correlation rules, the event data to the operator such that the event data is correlated in accordance with the at least one new rule.

2. The method of claim 1 , wherein:

the event data is received by one or more sensors; and

at least a portion of the events comprise alerts generated in an intrusion detection system.

3. The method of claim 1 , wherein at least a portion of the events comprise alerts generated in a military information system.

4. The method of claim 1 , wherein the selection is made by the operator in response to the display of event data.

5. The method of claim 1 , wherein:

the plurality of events comprises a first event, a second event, and a third event;

the selection comprises a selection of the first event and the third event; and

the at least one processor generates the at least one new rule by at least identifying one or more attributes associated with the first event that are in common with one or more attributes associated with the third event.

6. The method of claim 1 , wherein the at least one new rule comprises a first new rule, and further comprising:

receiving a selection of additional events made by the operator; and

generating a second new rule that correlates the initially selected events and the additionally selected events based at least in part upon the attributes associated with these events.

7. The method of claim 6 , wherein generating the second new rule comprises modifying the first new rule.

8. The method of claim 1 , wherein the at least one new rule comprises a first new rule, and further comprising:

receiving a deselection of events made by the operator; and

generating a second new rule that correlates the initially selected events but not the deselected events based at least in part upon the attributes associated with these events.

9. The method of claim 1 , wherein the at least one new rule is a first new rule and further comprising:

requesting the operator to indicate whether the correlation of the event data in accordance with the first new rule is acceptable; and

if the correlation is indicated to be unacceptable:

requesting the operator to deselect at least one of the plurality of events; and

generating a second new rule based at least in part on the at least one deselected event.

10. A system for generating correlation rules for events, comprising:

at least one sensor that receives event data for each of a plurality of events, the event data of a particular event comprising at least one attribute associated with that event;

at least one memory that stores a ruleset comprising a plurality of rules;

at least one interface device that displays the event data for each of the plurality of events to an operator, the event data for the plurality of events having been processed according to one or more rules of the ruleset, and that receives a selection of at least a portion of the plurality of events for which event data is displayed to the operator, the interface comprising a unified interface for displaying event data processed by rules in the ruleset and for creation of new correlation rules, the event data for each of the plurality of events being displayed to the operator using the unified user interface and the at least one selection being made using the unified user interface; and

at least one processor that generates at least one new rule that correlates the selected events, the at least one new rule generated based at least in part upon a pattern spread among the attributes associated with the selected events, stores the at least one new rule and the selection of at least a portion of the events in the at least one memory such that the at least one new rule is added to the ruleset stored in the at least one memory, and redisplays, in the unified user interface for displaying event data processed by rules in the ruleset and for creation of new correlation rules, the selected events to the operator such that the event data is correlated in accordance with the at least one new rule.

11. The system of claim 10 , wherein the correlation is based on more than one type of attribute.

12. The system of claim 10 , wherein:

the at least one new rule is a first new rule;

the at least one interface device requests the operator to indicate whether the correlation of the event data in accordance with the first new rule is acceptable; and

if the correlation is indicated to be unacceptable:

the at least one interface device requests the operator to deselect at least one of the plurality of events; and

the at least one processor generates a second new rule based at least in part on the at least one deselected event.

13. The system of claim 10 , wherein at least a portion of the events comprise alerts generated in an intrusion detection system.

14. The system of claim 10 , wherein at least a portion of the events comprise alerts generated in a military information system.

15. The system of claim 10 , wherein the selection is made by the operator in response to the display of event data.

16. The system of claim 10 , wherein:

the plurality of events comprises a first event, a second event, and a third event;

the selection comprises a selection of the first event and the third event; and

the at least one processor generates the at least one new rule by at least identifying one or more attributes associated with the first event that are in common with one or more attributes associated with the third event.

17. The system of claim 10 , wherein:

the at least one new rule comprises a first rule;

the processor receives a selection of additional events made by the operator; and

the processor generates a second new rule that correlates the initially selected events and the additionally selected events based at least in part upon the attributes associated with these events.

18. The system of claim 17 , wherein the processor generates a second new rule by modifying the first new rule.

19. The system of claim 10 , wherein:

the at least one new rule comprises a first new rule;

the processor receives a deselection of events made by the operator; and

the processor generates a second new rule that correlates the initially selected events but not the deselected events based at least in part upon the attributes associated with these events.

20. The system of claim 19 , wherein the processor generates a second new rule by modifying the first new rule.

21. An apparatus for generating correlation rules for events, the apparatus comprising:

at least one memory that stores a ruleset comprising a plurality of rules; and

a correlation engine that:

receives event data for each of a plurality of events, the event data of a particular event comprising a plurality of attributes associated with that event;

displays the event data for each of the plurality of events to at least one operator, the event data for the plurality of events having been processed according to one or more rules of the ruleset, the event data being displayed in a unified interface for displaying event data processed by rules in the ruleset and for creation of new correlation rules;

receives from the at least one operator a selection made using the unified user interface of at least a portion of the plurality of events for which event data is displayed to the at least one operator in the unified user interface;

generates at least one new rule that correlates the selected events, the at least one new rule generated based at least in part upon a pattern spread among the attributes associated with the selected events;

stores the at least one new rule and the selection of at least a portion of the events in the at least one memory such that the at least one new rule is added to the ruleset stored in the at least one memory; and

sends the event data to at least one graphical user interface in accordance with the at least one new rule such that the selected events are redisplayed, in the unified interface for displaying event data processed by rules in the ruleset and for creation of new correlation rules, to the at least one operator in such a way that the selected event data is correlated in accordance with the at least one new rule.

22. The apparatus of claim 21 , wherein at least a portion of the events comprise alerts generated in an intrusion detection system.

23. The apparatus of claim 21 , wherein at least a portion of the events comprise alerts generated in a military information system.

24. The apparatus of claim 21 , wherein:

the plurality of events comprises a first event, a second event, and a third event;

the selection comprises a selection of the first event and the third event; and

the correlation engine generates the at least one new rule by at least identifying one or more attributes associated with the first event that are in common with one or more attributes associated with the third event.

25. The apparatus of claim 21 , wherein the at least one new rule comprises a first new rule, and the correlation engine:

receives a selection of additional events made by the operator; and

generates a second new rule that correlates the initially selected events and the additionally selected events based at least in part upon the attributes associated with these events.

26. The apparatus of claim 25 , wherein the correlation engine generates the second new rule by modifying the first new rule.

27. The apparatus of claim 21 , wherein the at least one new rule comprises a first new rule, and the correlation engine:

receives a deselection of events made by the operator; and

generates a second new rule that correlates the initially selected events but not the deselected events based at least in part upon the attributes associated with these events.

28. The apparatus of claim 27 , wherein the correlation engine generates the second new rule by modifying the first new rule.

29. The apparatus of claim 21 , wherein:

at least one of the plurality of events is a data packet received at a network port, the at least one event associated with an attack; and

in conjunction with detecting the attack, the correlation engine disables the network port.

30. The apparatus of claim 21 , wherein:

the at least one new rule is a first new rule; and

the correlation engine generates a second new rule based at least in part on the selection stored in the memory.

31. The apparatus of claim 21 , wherein the plurality of attributes for each event comprises a source IP address, a destination IP address, a time, and a priority value.

32. The apparatus of claim 21 , wherein:

the correlation engine detects that the pattern spread among the attributes associated with the selected events is a particular IP address that is common among the selected events; and

in response to detecting the pattern, the correlation engine designs the at least one new rule to generate one or more alerts for events associated with the particular IP address.

33. The apparatus of claim 21 , wherein:

the correlation engine detects that the pattern spread among the attributes associated with the selected events is based at least in part on times associated with the selected events; and

in response to detecting the pattern, the correlation engine designs the at least one new rule to generate one or more alerts for events occurring between a first time and a second time.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded Apr 2, 2025
From: UBS AG, STAMFORD BRANCH
To: FORCEPOINT, LLC; BITGLASS, LLC
Reel/Frame 070706/0263 →
CHANGE OF NAME Recorded Mar 21, 2025
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: EVERFOX HOLDINGS LLC
Reel/Frame 070585/0625 →
SECURITY INTEREST Recorded Sep 29, 2023
From: FORCEPOINT FEDERAL HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC, AS COLLATERAL AGENT
Reel/Frame 065086/0822 →
CHANGE OF NAME Recorded May 12, 2021
From: FORCEPOINT LLC
To: FORCEPOINT FEDERAL HOLDINGS LLC
Reel/Frame 056216/0309 →
PATENT SECURITY AGREEMENT Recorded Jan 20, 2021
From: REDOWL ANALYTICS, INC.; FORCEPOINT LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 055052/0302 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded Jan 8, 2021
From: RAYTHEON COMPANY
To: WEBSENSE, INC.; PORTAUTHORITY TECHNOLOGIES, LLC (FKA PORTAUTHORITY TECHNOLOGIES, INC.); RAYTHEON OAKLEY SYSTEMS, LLC; FORCEPOINT FEDERAL LLC (FKA RAYTHEON CYBER PRODUCTS, LLC, FKA RAYTHEON CYBER PRODUCTS, INC.)
Reel/Frame 055492/0146 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2017
From: FORCEPOINT FEDERAL LLC
To: FORCEPOINT LLC
Reel/Frame 043397/0460 →
CHANGE OF NAME Recorded Feb 16, 2016
From: RAYTHEON CYBER PRODUCTS, LLC
To: FORCEPOINT FEDERAL LLC
Reel/Frame 037821/0818 →
PATENT SECURITY AGREEMENT Recorded Jun 9, 2015
From: WEBSENSE, INC.; RAYTHEON OAKLEY SYSTEMS, LLC; RAYTHEON CYBER PRODUCTS, LLC (FORMERLY KNOWN AS RAYTHEON CYBER PRODUCTS, INC.); PORT AUTHORITY TECHNOLOGIES, INC.
To: RAYTHEON COMPANY
Reel/Frame 035859/0282 →
CHANGE OF NAME Recorded Jun 2, 2015
From: RAYTHEON CYBER PRODUCTS, INC.
To: RAYTHEON CYBER PRODUCTS, LLC
Reel/Frame 035806/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2015
From: RAYTHEON COMPANY
To: RAYTHEON CYBER PRODUCTS, INC.
Reel/Frame 035774/0322 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2005
From: ROCKWOOD, TROY D.
To: RAYTHEON COMPANY
Reel/Frame 016961/0770 →