IP Library Granted Patent US 10,242,202
Granted Patent B1
US 10,242,202 · App. 15/705,780 · Granted Mar 26, 2019

Apparatus and method for staged graph processing to produce a risk inference measure

Inventors: Mark Erickson (Mountain View, CA); Christopher Calvert (Boulder, CO); Nick Gilligan (San Francisco, CA); Pramod G. Joisha (Saratoga, CA); Mitchell Webb (Parker, CO)
Assignee: Respond Software, Inc.
G06F21/577G06F21/56G06K9/6278G06N5/04G06N7/005H04L63/1416H04W12/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,242,202
App. No.
15/705,780
Granted
Mar 26, 2019
Kind
B1
Abstract

A computer implemented method includes processing a deterministic factual graph to produce superfacts. The deterministic factual graph has deterministic factual graph leaf nodes individually resolving facts to discrete-valued outcomes and parent nodes of the deterministic factual graph leaf nodes resolving the discrete-valued outcomes to superfacts. Each superfact is a qualitative characterization summarizing discrete-valued outcomes. A stochastic factual graph is processed to produce a risk inference measure. The stochastic factual graph has stochastic factual graph leaf nodes incorporating the facts or superfacts. The stochastic factual graph is a Bayesian network where each stochastic factual graph node, except for a base node, is associated with a probability function, and edges between stochastic factual graph nodes represent conditional dependencies. The risk inference measure is compared to an escalation threshold. An incident is evaluated when the risk inference measure exceeds the escalation threshold.

Claims (21)

1. A computer implemented method, comprising:

collecting at a first machine information characterizing an incident on a second machine, wherein the first machine and the second machine communicate via a network;

processing a deterministic factual graph to produce superfacts, wherein the deterministic factual graph has deterministic factual graph leaf nodes individually resolving facts characterizing the incident to discrete-valued outcomes, and parent nodes of the deterministic factual graph leaf nodes resolving the discrete-valued outcomes to superfacts, wherein each superfact is a qualitative characterization summarizing discrete-valued outcomes;

processing a stochastic factual graph to produce a risk inference measure for the incident, wherein the stochastic factual graph has stochastic factual graph leaf nodes incorporating the facts or superfacts, wherein the stochastic factual graph is a Bayesian network wherein except for a base node each stochastic factual graph node is associated with a probability function and edges between stochastic factual graph nodes represent conditional dependencies;

comparing the risk inference measure to an escalation threshold;

evaluating the incident when the risk inference measure exceeds the escalation threshold;

evaluating the incident to reach a risk conclusion; and

updating a probability function in the Bayesian network based upon the risk conclusion.

2. The computer implemented method of claim 1 wherein evaluating includes evaluating a representation of at least part of the stochastic factual graph or the deterministic factual graph.

3. The computer implemented method of claim 1 wherein the risk inference measure is a fraud risk inference.

4. The computer implemented method of claim 1 wherein the risk inference measure is a security risk inference.

5. The computer implemented method of claim 1 wherein the deterministic factual graph has leaf nodes characterizing source internet protocol address facts.

6. The computer implemented method of claim 1 wherein the deterministic factual graph has leaf nodes characterizing destination internet protocol address facts.

7. The computer implemented method of claim 1 wherein the deterministic factual graph has leaf nodes characterizing a known intrusion signature.

8. The computer implemented method of claim 1 wherein the deterministic factual graph has leaf nodes characterizing a suspicious temporal event pattern.

9. The computer implemented method of claim 1 wherein the deterministic factual graph has leaf nodes characterizing persistence facts.

10. The computer implemented method of claim 1 wherein the deterministic factual graph has leaf nodes characterizing detection avoidance facts.

11. The computer implemented method of claim 1 wherein the deterministic factual graph has leaf nodes characterizing system exploitation facts.

12. The computer implemented method of claim 1 wherein the deterministic factual graph has leaf nodes characterizing data staging facts.

13. The computer implemented method of claim 1 wherein the deterministic factual graph has leaf nodes characterizing lateral movement facts.

14. The computer implemented method of claim 1 wherein the deterministic factual graph has leaf nodes characterizing reconnaissance facts.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 3, 2023
From: MANDIANT, INC.
To: GOOGLE LLC
Reel/Frame 063238/0555 →
CHANGE OF NAME Recorded Nov 10, 2021
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 058101/0088 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2021
From: RESPOND SOFTWARE, LLC
To: FIREEYE, INC.
Reel/Frame 055016/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 28, 2017
From: ERICKSON, MARK; CALVERT, CHRISTOPHER; GILLIGAN, NICK; JOISHA, PRAMOD G.; WEBB, MITCHELL
To: RESPOND SOFTWARE, INC.
Reel/Frame 044234/0363 →
Cited By (1)
US 12,689,649