IP Library Patent Application 15147487
Patent Application
App. No. 15/147,487

Systems and Methods for Detecting and Reacting to Malicious Activity in Computer Networks

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/147,487
Abstract

Described herein are systems and methods for performing operations responsive to potentially malicious activity. Embodiments may include receiving an indication of the potentially malicious activity in a computer network; identifying, based on data included in the indication, at least one network account associated with the potentially malicious activity; determining, based on the identifying and further based on the data included in the indication and according to a defined policy, at least one responsive operation with respect to the at least one identified network account; and invoking, based on the determining, the at least one responsive operation, the at least one responsive operation being implemented to mitigate the potentially malicious activity in the computer network.

Claims (56)

1 . A non-transitory computer readable medium including instructions that, when executed by at least one processor, cause the at least one processor to perform operations responsive to potentially malicious activity, comprising:

receiving an indication of the potentially malicious activity in a computer network;

identifying, based on data included in the indication, at least one network account associated with the potentially malicious activity;

determining, based on the identifying and further based on the data included in the indication and according to a defined policy, at least one responsive operation with respect to the at least one identified network account; and

invoking, based on the determining, the at least one responsive operation, the at least one responsive operation being implemented to mitigate the potentially malicious activity in the computer network.

2 . The non-transitory computer readable medium of claim 1 , wherein the responsive operation includes changing access settings of the defined policy for the at least one identified network account, the access settings controlling the ability of the at least one network account to receive incoming network communications.

3 . The non-transitory computer readable medium of claim 1 , wherein the responsive operation includes changing use settings of the defined policy for the at least one identified network account, the use settings controlling the ability of the at least one network account to send outgoing network communications.

4 . The non-transitory computer readable medium of claim 1 , wherein the responsive operation includes invalidating credentials for the at least one identified network account.

5 . The non-transitory computer readable medium of claim 1 , wherein the responsive operation includes taking an action on the at least one identified network account.

6 . The non-transitory computer readable medium of claim 1 , wherein the responsive operation includes changing a parameter of the defined policy.

7 . The non-transitory computer readable medium of claim 1 , wherein the responsive operation includes storing data associated with the potentially malicious activity.

8 . The non-transitory computer readable medium of claim 1 , wherein the operations further comprise:

determining, based on data received in the indication, at least one related network account with a relationship criteria in common with the at least one identified network account;

determining at least one corresponding responsive operation for the related network account; and

invoking a corresponding responsive operation, the corresponding response action being implemented to broaden the scope of the invoked at least one responsive operation.

9 . The non-transitory computer readable medium of claim 1 , wherein the receiving further includes querying a network resource and obtaining the indication from the queried network resource.

10 . The non-transitory computer readable medium of claim 1 , wherein the identifying further includes querying a network resource and identifying the at least one associated network account from the queried network resource.

11 . The non-transitory computer readable medium of claim 1 , wherein the determining further includes reading a policy file, the policy file being a locally stored policy file or a remotely stored policy file.

12 . The non-transitory computer readable medium of claim 1 , wherein the operations further comprise:

identifying a plurality of network accounts associated with the potentially malicious activity, each identified network account having at least one associated network communications policy;

determining, based on the identifying and according at least one associated network communications policy, at least one responsive operation with respect to the identified plurality of network accounts; and

invoking a plurality of responsive operations with respect to the plurality of network accounts, wherein differing responsive operations are applied to different network accounts.

13 . The non-transitory computer readable medium of claim 1 , wherein the at least one identified network account is determined to be a source of the potentially malicious activity.

14 . The non-transitory computer readable medium of claim 1 , wherein the at least one identified network account is determined to be a target of the potentially malicious activity.

15 . The non-transitory computer readable medium of claim 1 , wherein the at least one identified network account is determined based on a type of the potentially malicious activity.

16 . The non-transitory computer readable medium of claim 1 , wherein the at least one identified network account is determined based on data in the received indication of the potentially malicious activity.

17 . The non-transitory computer readable medium of claim 1 , wherein the operations further include changing network permissions for the at least one identified network account.

18 . The non-transitory computer readable medium of claim 1 , wherein identifying the at least one network account associated with the potentially malicious activity further includes:

identifying credential data associated with a potential network attack;

determining a privileged account from which the credential data originated; and

identifying, as the identified network account, the determined privileged account.

19 . A network system configured for cyber-attack remediation operations, the network system comprising:

at least one computer-readable memory storing instructions; and

at least one processor configured to execute the instructions to:

receive an indication of the potentially malicious activity in a computer network;

identify, based on data included in the indication, at least one network account associated with the potentially malicious activity;

determine, based on the identifying and further based on the data included in the indication and according to a defined policy, at least one responsive operation with respect to the at least one identified network account; and

invoke, based on the determining, the at least one responsive operation, the at least one responsive operation being implemented to mitigate the potentially malicious activity in the computer network.

20 . The network system of claim 19 , wherein the at least one processor is configured to execute the instructions to:

determine, based on data received in the indication, at least one related network account with a relationship criteria in common with the at least one identified network account;

determine at least one corresponding responsive operation for the related network account; and

invoke a corresponding responsive operation, the corresponding response action being implemented to broaden the scope of the invoked at least one responsive operation.

21 . The network system of claim 19 , wherein the responsive operation includes taking an action on the at least one identified network account.

22 . The network system of claim 19 , wherein the responsive operation includes changing a parameter of the defined policy.

23 . The network system of claim 19 , wherein the responsive operation includes storing data associated with the potentially malicious activity.

24 . The network system of claim 19 , wherein the responsive operation includes a change to access settings of the defined policy for the at least one identified network account, the access settings controlling the ability of the at least one network account to receive incoming network communications.

25 . The network system of claim 19 , wherein the responsive operation includes a change to use settings of the defined policy for the at least one identified network account, the use settings controlling the ability of the at least one network account to send outgoing network communications.

26 . A computer-implemented method for performing operations responsive to potentially malicious activity, comprising:

receiving an indication of the potentially malicious activity in a computer network;

identifying, based on data included in the indication, at least one network account associated with the potentially malicious activity;

determining, based on the identifying and further based on the data included in the indication and according to a defined policy, at least one responsive operation with respect to the at least one identified network account; and

invoking, based on the determining, the at least one responsive operation, the at least one responsive operation being implemented to mitigate the potentially malicious activity in the computer network.

27 . The computer-implemented method of claim 26 , wherein the responsive operation includes taking an action on the at least one identified network account.

28 . The computer-implemented method of claim 26 , wherein the responsive operation includes changing a parameter of the defined policy.

29 . The computer-implemented method of claim 26 , wherein the responsive operation includes storing data associated with the potentially malicious activity.

30 . The computer-implemented method of claim 26 , wherein the responsive operation includes changing access settings of the defined policy for the at least one identified network account, the access settings controlling the ability of the at least one network account to receive incoming network communications.

Assignments (1)
CHANGE OF NAME Recorded Oct 17, 2017
From: CYBER-ARK SOFTWARE LTD.
To: CYBERARK SOFTWARE LTD.
Reel/Frame 044218/0539 →