IP Library Patent Application 15011414
Patent Application
App. No. 15/011,414

DETECTION OF SECURITY TRANSACTIONS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/011,414
Abstract

In a method, a plurality of events is accessed, wherein an event of the plurality of events includes a portion of raw-machine data from a data source of a plurality of data sources. For at least one event of the plurality of events, a transaction phase of a computer security transaction is correlated with the at least one event based at least in part on a data source associated with the at least one event. The transaction phase of the at least one event is correlated with a particular asset of a plurality of assets.

Claims (44)

1 . A method comprising:

accessing a plurality of events, wherein an event of the plurality of events includes a portion of raw machine-data from a data source of a plurality of data sources;

for at least one event of the plurality of events, correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event; and

correlating the transaction phase of the at least one event with a particular asset of a plurality of assets.

2 . The method of claim 1 wherein the computer security transaction includes a. plurality of transaction phases indicative of a progressive cyber-attack.

3 . The method of claim 2 , wherein the plurality of transaction phases are defined by an attack chain security model, wherein the plurality of transaction phases comprises: a reconnaissance transaction phase, a weaponizati on transaction phase, a delivery transaction phase, an exploitation transaction phase, an installation transaction phase, a command and control transaction phase, and an actions on objectives transaction phase.

4 . The method of claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event is performed responsive to receiving the event of the plurality of events.

5 . The method of claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event is performed responsive to searching the plurality of events.

6 . The method of claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event is performed responsive to indexing the plurality of events.

7 . The method of claim 1 , wherein the data source is one of an intrusion detection system (IDS), a next-generation firewall (NGFW) device, an anti-virus (AV) application, an endpoint threat detection and response (ETDR) application, an electronic mail (e-mail) application, and an operating system.

8 . The method of claim 1 , wherein the correlating the transaction phase of the at least one event with a particular asset associated with the at least one event comprises:

correlating the transaction phase of the at least one event with a particular user associated with the particular asset and associated with the at least one event.

9 . The method of claim 1 , further comprising:

aggregating transactions phases for the plurality of assets.

10 . The method of claim 9 , further comprising:

providing an indication of particular assets having correlated transaction phases, the indication identifying the correlated transaction phases for the particular assets.

11 . The method of claim 1 , further comprising:

responsive to a determining that the transaction phase has occurred, generating a notification indicating that the transaction phase involving the particular asset has occurred.

12 . The method of claim 1 , further comprising:

responsive to determining that a plurality of transaction phases of the computer security transaction has occurred for a particular asset, generating a notification indicating that the plurality of transaction phases of the computer security transaction has occurred.

13 . The method of claim 12 , further comprising:

responsive to the plurality of transaction phases comprising non-successive transaction phases of the computer security transaction, generating a notification indicating a potential visibility gap in the detection of transaction phases of the computer security transaction.

14 . The method of claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event comprises:

accessing a table of a plurality of sources and respective corresponding transaction phases.

15 . The method of claim 1 , wherein the correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event comprises:

for the at least one event in the plurality of events, generating a metadata field identifying the transaction phase associated with the at least one event.

16 . The method of claim 15 , further comprising:

searching the plurality of events to identify an event that indicates an association between a particular user identifier and the particular asset; and

in response to the search, generating a data structure for storing the association between the particular asset and the particular user identifier.

17 . The method of claim 16 , wherein the correlating the transaction phase of the at least one event with a particular asset of a plurality of assets comprises:

updating the data structure to append the metadata field to the association between the particular asset and the particular user identifier.

18 . The method of claim 16 , wherein the event that indicates an association between the particular user and the particular asset is a successful authentication operation of the particular user identifier on the particular asset.

19 . The method of claim 1 , further comprising:

searching, based on a set of criteria, the plurality of events to identify the at least one ever

20 . A system, comprising:

one or more data processors; and

a non-transitory computer-readable storage medium containing instructions which when executed on the one or more data processors, cause the one or more processors to perform operations including:

accessing a plurality of events, wherein an event of the plurality of events includes a portion of raw machine-data from a data source of a plurality of data sources;

for at least one event of the plurality of events, correlating a transaction phase of a computer security transaction with the at least one event based at least in part on a data. source associated with the at least one event; and

correlating the transaction phase of the at least one event with a particular asset of a plurality of assets.

21 . A computer-program product tangibly embodied in a non-transitory machine-readable storage medium, including instructions configured to cause one or more data processors to:

access a plurality of events, wherein an event of the plurality of events includes a portion of raw machine-data from a data source of a plurality of data sources;

for at least one event of the plurality of events, correlate a transaction phase of a computer security transaction with the at least one event based at least in part on a data source associated with the at least one event; and

correlate the transaction phase of the at least one event with a particular asset of a plurality of assets.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0782 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2016
From: MERZA, MUNAWAR MONZY
To: SPLUNK INC.
Reel/Frame 037814/0929 →