IP Library Granted Patent US 10,476,752
Granted Patent B2
US 10,476,752 · App. 15/477,625 · Granted Nov 12, 2019

Blue print graphs for fusing of heterogeneous alerts

Inventors: Kenji Yoshihira (Princeton Junction, NJ); Zhichun Li (Princeton, NJ); Zhengzhang Chen (Princeton Junction, NJ); Haifeng Chen (West Windsor, NJ); Guofei Jiang (Princeton, NJ); LuAn Tang (Pennington, NJ)
Assignee: NEC Corporation
H04L41/145H04L41/12H04L43/045
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,476,752
App. No.
15/477,625
Granted
Nov 12, 2019
Kind
B2
Abstract

Methods and systems for reporting anomalous events include building a process graph that models states of process-level events in a network. A topology graph is built that models source and destination relationships between connection events in the network. A set of alerts is clustered based on the process graph and the topology graph. Clustered alerts that exceed a threshold level of trustworthiness are reported.

Claims (27)

1. A method for reporting anomalous events, comprising:

building a process graph that models states of process-level events in a network using a processor, wherein the nodes in the process graph including process nodes, file nodes, and socket nodes;

building a topology graph that models source host and destination host relationships between connection events in the network using the processor;

clustering a set of alerts based on the process graph and the topology graph; and

reporting clustered alerts that exceed a threshold level of trustworthiness to reduce a false alert rate: and

performing a security management action responsive to the reported clustered alerts.

2. The method of claim 1 , further comprising trimming elements from the process graph and the topology graph if said elements have a last-connection-time value older than a threshold period.

3. The method of claim 1 , wherein building the process graph comprises creating a new process node in the process graph if a process node does not already exist in the process graph for a received process-level event.

4. The method of claim 3 , wherein building the process graph comprises creating a new object node in the process graph if an object node does not already exist in the process graph for the received process-level event.

5. The method of claim 4 , wherein building the process graph comprises creating a new edge between the process node and the object node if an edge does not already exist in the process graph between the process node and the object node.

6. The method of claim 5 , wherein building the process graph comprises updating a last-event-time value for the process node and the object node to a timestamp in the received process-level event.

7. The method of claim 1 , wherein building the topology graph comprises creating a new host node in the topology graph corresponding to a host node that does not already exist in the topology graph from a received network event.

8. The method of claim 7 , wherein building the topology graph comprises creating a new edge between host nodes indicated by the received network event if an edge does not already exist in the topology graph between said hosts.

9. The method of claim 8 , wherein building the topology graph comprises updating a last-event-time value for the hosts indicated by the received network event to a timestamp in the received network event.

10. A system for reporting anomalous events, comprising:

a blue print update module comprising a processor configured to build a process graph that models states of process-level events in a network and to build a topology graph that models source host and destination host relationships between connection events in the network, wherein the nodes in the process graph including process nodes, file nodes, and socket nodes;

a clustering module configured to cluster a set of alerts based on the process graph and the topology graph; and

a user interface configured to report clustered alerts that exceed a threshold level of trustworthiness to reduce a false alert rate; and

a system recovery module configured to perform a security management action responsive to the reported clustered alerts.

11. The system of claim 10 , wherein the blue print update module is further configured to trim elements from the process graph and the topology graph if said elements have a last-connection-time value older than a threshold period.

12. The system of claim 10 , wherein the blue print update module is further configured to create a new process node in the process graph if a process node does not already exist in the process graph for a received process-level event.

13. The system of claim 12 , wherein the blue print update module is further configured to create a new object node in the process graph if an object node does not already exist in the process graph for the received process-level event.

14. The system of claim 13 , wherein the blue print update module is further configured to create a new edge between the process node and the object node if an edge does not already exist in the process graph between the process node and the object node.

15. The system of claim 14 , wherein the blue print update module is further configured to update a last-event-time value for the process node and the object node to a timestamp in the received process-level event.

16. The system of claim 10 , wherein the blue print update module is further configured to create a new host node in the topology graph corresponding to a host node that does not already exist in the topology graph from a received network event.

17. The system of claim 16 , wherein the blue print update module is further configured to create a new edge between host nodes indicated by the received network event if an edge does not already exist in the topology graph between said hosts.

18. The system of claim 17 , wherein the blue print update module is further configured to update a last-event-time value for the hosts indicated by the received network event to a timestamp in the received network event.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2024
From: IP WAVE PTE LTD.
To: CLOUD BYTE LLC.
Reel/Frame 067944/0332 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2024
From: NEC ASIA PACIFIC PTE LTD.
To: IP WAVE PTE LTD.
Reel/Frame 066376/0276 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2023
From: NEC CORPORATION
To: NEC ASIA PACIFIC PTE LTD.
Reel/Frame 066124/0752 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2019
From: NEC LABORATORIES AMERICA, INC.
To: NEC CORPORATION
Reel/Frame 050498/0081 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2017
From: YOSHIHIRA, KENJI; LI, ZHICHUN; CHEN, ZHENGZHANG; CHEN, HAIFENG; JIANG, GUOFEI; TANG, LUAN
To: NEC LABORATORIES AMERICA, INC.
Reel/Frame 041830/0967 →
Continuity (3)
Continuation In Part 15098861 · Apr 14, 2016
Provisional Application 62317781 · Apr 4, 2016
Related Publication 20170288979A1 · Oct 5, 2017