IP Library Granted Patent US 8,407,798
Granted Patent B1
US 8,407,798 · App. 12/206,076 · Granted Mar 26, 2013

Method for simulation aided security event management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,407,798
App. No.
12/206,076
Granted
Mar 26, 2013
Kind
B1
Abstract

A method for simulation aided security event management, the method includes: generating attack simulation information that comprises multiple simulation data items of at least one data item type out of vulnerability instances data items, attack step data items and attack simulation scope data items; wherein the generating of attack simulation information is responsive to a network model, at least one attack starting point and attack action information; identifying security events in response to a correlation between simulation data items and event data; and prioritizing identified security events.

Claims (27)

1. A method for simulation aided security event management, the method comprises:

obtaining event data indicative of a security event identified by a computerized security event manager;

searching for a simulated attack step that resembles the security event; and generating contextual information indicative of next attack steps and risk associated with the next attack steps in response to an attack simulation;

wherein the generating of the contextual information comprises extracting the contextual information from an attack simulation that determines possible multi-step attacks from start points to nodes and business assets within the network.

2. A method for simulation aided security event management, the method comprises:

obtaining event data indicative of a security event identified by a computerized security event manager;

searching for a simulated attack step that resembles the security event; and generating contextual information indicative of next attack steps and risk associated with the next attack steps in response to an attack simulation;

wherein the generating of the contextual information comprises extracting the contextual information from an attack graph that comprises graph nodes that represent attacker achievement, wherein transitions between the graph nodes represent attack steps or actions that enabled the attacker achievements.

3. A method for simulation aided security event management, the method comprises:

obtaining event data indicative of a security event identified by a computerized security event manager;

searching for a simulated attack step that resembles the security event; generating contextual information indicative of next attack steps and risk associated with the next attack steps in response to an attack simulation; and

generating attack simulation information that comprises multiple simulation data items of at least one data item type out of vulnerability instances data items, attack step data items and attack simulation scope data items; wherein the generating of attack simulation information is responsive to a network model, at least one attack starting point and attack action information.

4. A computer program product that comprises a non-transitory computer readable medium that stores instructions for:

obtaining event data indicative of a security event identified by a security event manager;

searching for a simulated attack step that resembles the security event; and

generating contextual information indicative of next attack steps and risk associated with the next attack steps in response to an attack simulation;

wherein the computer readable medium stores instructions for extracting the contextual information from an attack simulation that determines possible multi-step attacks from start points to nodes and business assets within the network.

5. A computer program product that comprises a non-transitory computer readable medium that stores instructions for:

obtaining event data indicative of a security event identified by a security event manager;

searching for a simulated attack step that resembles the security event; and

generating contextual information indicative of next attack steps and risk associated with the next attack steps in response to an attack simulation;

wherein the computer readable medium stores instructions for extracting the contextual information from an attack graph that comprises graph nodes that represent attacker achievement, wherein transitions between the graph nodes represent attack steps or actions that enabled the attacker achievements.

6. A computer program product that comprises a non-transitory computer readable medium that stores instructions for:

obtaining event data indicative of a security event identified by a security event manager;

searching for a simulated attack step that resembles the security event; and

generating contextual information indicative of next attack steps and risk associated with the next attack steps in response to an attack simulation;

wherein the computer readable medium stores instructions for generating attack simulation information that comprises multiple simulation data items of at least one data item type out of vulnerability instances data items, attack step data items and attack simulation scope data items; wherein the generating of attack simulation information is responsive to a network model, at least one attack starting point and attack action information.

Assignments (10)
PATENT SECURITY AGREEMENT Recorded May 30, 2025
From: SPEAR PARENT, INC.
To: TCG SENIOR FUNDING, L.L.C., AS COLLATERAL AGENT
Reel/Frame 071464/0732 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2025
From: SKYBOX SECURITY, INC.
To: SPEAR PARENT, INC.
Reel/Frame 071138/0372 →
RELEASE OF SECURITY INTEREST Recorded Feb 25, 2025
From: JPMORGAN CHASE BANK, N.A.
To: SKYBOX SECURITY, INC.
Reel/Frame 070326/0871 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CORRECT THE PROPERTY LIST BY DELETING PATENT APPLICATION NO. 10/409,993 AND ADDING PATENT NO. 10,409,993 PREVIOUSLY RECORDED AT REEL: 61994 FRAME: 530. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Feb 25, 2025
From: SKYBOX SECURITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 070328/0572 →
SECURITY INTEREST Recorded Dec 6, 2022
From: SKYBOX SECURITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 061994/0530 →
RELEASE OF IP SECURITY AGREEMENT Recorded Dec 1, 2022
From: ALLY BANK, AS AGENT
To: SKYBOX SECURITY, INC.
Reel/Frame 062034/0779 →
ACKNOWLEDGMENT OF TERMINATION OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 8, 2019
From: SILICON VALLEY BANK
To: SKYBOX SECURITY, INC.
Reel/Frame 050664/0927 →
SECURITY INTEREST Recorded Oct 3, 2019
From: SKYBOX SECURITY, INC.
To: ALLY BANK
Reel/Frame 050613/0083 →
SECURITY INTEREST Recorded Aug 31, 2018
From: SKYBOX SECURITY, INC.
To: SILICON VALLEY BANK
Reel/Frame 046769/0426 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2008
From: LOTEM, AMNON; COHEN, GIDEON; BEN NAON, LIOR
To: SKYBOX SECURITY INC
Reel/Frame 021639/0965 →