IP Library Granted Patent US 10,205,736
Granted Patent B2
US 10,205,736 · App. 15/443,857 · Granted Feb 12, 2019

Behavioral baselining of network systems

Inventors: Malcolm Rieke (Santa Cruz, CA); Holland Carrere Barry (Scotts Valley, CA)
Assignee: CATBIRD NETWORKS, INC.
H04L63/1425G06F3/0482G06F21/31H04L63/1433G06F17/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,205,736
App. No.
15/443,857
Granted
Feb 12, 2019
Kind
B2
Abstract

Systems and methods for behavioral baselining of network systems. In one embodiment, a method includes: storing, in an asset attribute database, information regarding assets, wherein each asset comprises at least one attribute; storing, in a relationship database, information regarding relationships, wherein each relationship comprises at least one attribute; selecting, from the asset attribute database, assets based on at least one attribute value; selecting, from the relationship database, one or more relationships based on at least one attribute value, the selected relationships including a first relationship; creating a baseline, wherein the baseline comprises the selected assets and the selected relationships; connecting a first event stream to the baseline, wherein the first event stream comprises a set of events, and each event comprises attributes; and detecting a drift from the baseline, wherein the drift is determined using the first event stream and is based on a failure of at least one attribute value in a first event of the first event stream to match at least one attribute value of the first relationship.

Claims (46)

1. A method, comprising:

storing, in an asset attribute database, information regarding assets, wherein each asset comprises at least one attribute;

storing, in a relationship database, information regarding relationships, wherein each relationship comprises at least one attribute;

selecting, from the asset attribute database, assets based on at least one attribute value;

selecting, from the relationship database, one or more relationships based on at least one attribute value, the selected relationships including a first relationship;

creating a baseline, wherein the baseline comprises the selected assets and the selected relationships;

connecting a first event stream to the baseline, wherein the first event stream comprises a sequence of events for times including a first time and at least a second time, and each event comprises attributes; and

detecting a drift from the baseline, wherein the drift is determined using the first event stream and is based on a failure of at least one attribute value in a first event of the first event stream to match at least one attribute value of the first relationship.

2. The method of claim 1 , further comprising recording, into at least one database, information from a plurality of event streams including the first event stream.

3. The method of claim 1 , wherein creating the baseline comprises selecting assets based on attribute values, and selecting relationships based on attribute values.

4. The method of claim 1 , further comprising defining an alert policy, and in response to detecting the drift, generating an alert based on the alert policy.

5. The method of claim 1 , further comprising evaluating each event of the first event stream based on evaluations corresponding to attributes in the selected relationships.

6. The method of claim 5 , wherein the first relationship comprises a first attribute and a first evaluation corresponding to the first attribute, and detecting the drift further comprises using the first evaluation to evaluate event data for the first attribute from a first event in the event stream, and determining that the evaluated event data fails the first evaluation.

7. The method of claim 6 , wherein the first event comprises data to be evaluated using the selected relationships, and wherein the data is at least one of: a source port, a destination port, a source asset, a destination asset, a source group, or a destination group.

8. The method of claim 1 , wherein each of the selected relationships references at least one event stream having an event type, and wherein the event type for each event stream is flow, authentication, or port scan.

9. The method of claim 8 , wherein an event type of the first relationship is authentication, and the first relationship includes a user attribute corresponding to a set of authorized users.

10. The method of claim 9 , wherein detecting the drift is based at least in part on evaluation of an event including a logon by a user that is not in the set of authorized users.

11. The method of claim 8 , wherein each selected relationship references an event stream having an event type of port scan, and each selected relationship comprises a detected ports attribute with attribute values that are determined when the selected relationship is instantiated.

12. The method of claim 1 , wherein the first relationship comprises an attribute with a value corresponding to a first group of assets, and a first asset is included in the selected assets based on a selection of assets having an attribute value matching the first group.

13. The method of claim 1 , wherein each attribute of each selected relationship is an asset attribute, an event attribute, an attribute for which a value is derived using at least one value from evaluation of an asset attribute or an event attribute, or an attribute for which a value is derived using at least one value from evaluation of each of an asset attribute and an event attribute.

14. The method of claim 1 , wherein the selected relationships are selected based on specifying, using a logical operator, a value of an attribute that identifies a group of assets, wherein each relationship including a group attribute equal to the value is selected.

15. The method of claim 1 , wherein each event comprises a time attribute having a value based on a time that the event occurred, and wherein an evaluation of the event corresponding to at least one attribute of a selected relationship comprises comparing the time that the event occurred to one or more temporal ranges.

16. The method of claim 11 , wherein each asset of the selected assets comprises an asset port attribute, the first event stream is provided from a set of vulnerability scanners, and each event of the first event stream includes data from a port scan that identifies port numbers for detected ports.

17. The method of claim 11 , wherein attribute values for detected port attributes of each of the selected relationships are based on values for asset port attributes of the selected assets when the respective selected relationship is instantiated, and wherein detecting the drift is based on a failure of detected ports in the first event for a first asset of the selected assets to match detected ports for the first asset in the first relationship in the baseline.

18. The method of claim 1 , wherein the first relationship comprises a derived attribute, the derived attribute has a value determined using data from a first plurality of events each having an event type of flow, and the data from the first plurality of events is used in a mathematical evaluation corresponding to an attribute of the first relationship to calculate the value of the derived attribute.

19. The method of claim 8 , wherein the first relationship references an event stream of a first event type and the first relationship further comprises a first attribute and a second attribute, wherein the first relationship evaluates the first attribute to provide a first value, and evaluates the second attribute to provide a second value, and wherein the first value and second value are mathematically derived from data from events of the first event type in the first event stream.

20. The method of claim 19 , wherein the selected relationships further comprise a second relationship that references a second event stream of a second event type different from the first event type, and the second relationship further comprises a third attribute and a fourth attribute, wherein the second relationship evaluates the third attribute to provide a third value, and evaluates the fourth attribute to provide a fourth value, wherein the third value and fourth value are each mathematically derived from data from events of the second event type in the second event stream, wherein an evaluation of the second relationship comprises a determination whether data from an event in the second event stream complies with the evaluation, and wherein the first relationship and the second relationship are used to detect the drift based on evaluations for attributes in both the first and the second relationships.

21. A non-transitory, computer-readable medium storing instructions that, when executed, cause a computing device to:

store, by at least one processor, information regarding assets, wherein each asset comprises at least one attribute;

store, in at least one memory, information regarding relationships, wherein each relationship comprises at least one attribute;

select assets based on at least one attribute value;

select one or more relationships based on at least one attribute value, the selected relationships including a first relationship;

create a baseline, wherein the baseline comprises the selected assets and the selected relationships;

connect a first event stream to the baseline, wherein the first event stream comprises a sequence of events for times including a first time and at least a second time, and each event comprises attributes; and

detect a drift from the baseline, wherein the drift is determined using the first event stream and is based on a failure of at least one attribute value in a first event of the first event stream to pass an evaluation of the first relationship.

22. A system, comprising:

at least one database,

at least one processor; and

at least one memory in communication with the at least one processor and storing instructions that, when executed by the at least one processor, cause the system to:

store, in the at least one database, information regarding assets, wherein each asset comprises at least one attribute;

store, in the at least one database, information regarding relationships, wherein each relationship comprises at least one attribute;

select, from the at least one database, assets based on at least one attribute value;

select, from the at least one database, one or more relationships based on at least one attribute value, the selected relationships including a first relationship;

create a baseline, wherein the baseline comprises the selected assets and the selected relationships;

connect a first event stream to the baseline, wherein the first event stream comprises a sequence of events for times including a first time and at least a second time, and each event comprises attributes; and

detect a drift from the baseline, wherein the drift is determined using the first event stream and is based on a failure of at least one attribute value in a first event of the first event stream to match at least one attribute value of the first relationship.

Assignments (7)
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0970 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: SIS HOLDINGS, L.P.
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068312/0011 →
RELEASE OF SECURITY INTEREST Recorded Jul 12, 2024
From: APPGATE FUNDING, LLC
To: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
Reel/Frame 068311/0570 →
SECURITY INTEREST Recorded Aug 22, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: APPGATE FUNDING, LLC
Reel/Frame 064672/0383 →
SECURITY INTEREST Recorded Jul 6, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: SIS HOLDINGS, L.P.
Reel/Frame 064461/0539 →
SECURITY INTEREST Recorded Jun 10, 2023
From: APPGATE CYBERSECURITY, INC.; CRYPTZONE NORTH AMERICA INC.; EASY SOLUTIONS ENTERPRISES CORP.; CATBIRD NETWORKS, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 063956/0470 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2018
From: RIEKE, MALCOLM; BARRY, HOLLAND CARRERE
To: CATBIRD NETWORKS, INC.
Reel/Frame 047754/0260 →
Continuity (1)
Related Publication 20180248899A1 · Aug 30, 2018
Cited By (62)
US 12,191,978 US 12,206,696 US 12,244,621 US 12,261,866 US 12,267,345 US 12,284,197 US 12,309,181 US 12,309,182 US 12,309,185 US 12,309,236 US 12,323,449 US 12,335,348 US 12,348,545 US 12,355,626 US 12,355,793 US 12,356,198 US 12,363,147 US 12,368,745 US 12,381,901 US 12,401,669 US 12,407,701 US 12,407,702 US 12,418,555 US 12,452,272 US 12,457,231 US 12,463,994 US 12,463,995 US 12,463,996 US 12,489,771 US 12,495,052 US 12,506,762 US 12,511,110 US 12,526,297 US 12,537,836 US 12,549,575 US 12,549,577 US 12,556,559 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,932 US 12,580,935 US 12,580,937 US 12,592,950 US 12,598,205 US 12,613,930 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,333 US 12,689,640 US 12,695,768 US 12,706,931 US 12,706,933 US 12,706,980 US 12,712,897 US 12,719,896