IP Library Granted Patent US 10,462,175
Granted Patent B2
US 10,462,175 · App. 15/877,637 · Granted Oct 29, 2019

Systems for network risk assessment including processing of user access rights associated with a network of devices

Inventors: Miles Seiver (Los Altos Hills, CA); Charles Rosenblum (Palo Alto, CA)
Assignee: Palantir Technologies Inc.
H04L63/1433H04L41/12H04L43/0876H04L63/10H04L63/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,462,175
App. No.
15/877,637
Granted
Oct 29, 2019
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for network risk assessment. One of the methods includes obtaining information describing network traffic between a plurality of network devices within a network. A network topology of the network is determined based on the information describing network traffic, with the network topology including nodes connected by an edge to one or more other nodes, and with each node being associated with one or more network devices. Indications of user access rights of users are associated to respective nodes included in the network topology. User interface data associated with the network topology is generated.

Claims (67)

1. A computerized method comprising:

by a computing device having one or more computer processors and a non-transitory computer readable storage device storing software instruction for execution by the one or more computer processors,

determining a network topology of a network, the network topology comprising a plurality of nodes each connected to one or more of the plurality of nodes, wherein each node is associated with one or more network devices;

accessing information indicating compromise values associated with respective nodes; and

providing, for presentation, an interactive user interface, wherein the interactive user interface presents a graphical depiction of the network topology and compromise values associated with the plurality of nodes.

2. The method of claim 1 , further comprising:

selecting, for each node in the graphical depiction of the network topology, a label of a plurality of labels to be assigned to the node based on the compromise value associated with the node, each label graphically representing a respective range of compromise values; and

presenting, in the interactive user interface, a respective label for each of the nodes in the graphical depiction of the network topology.

3. The method of claim 1 , further comprising:

receiving user input, via the interactive user interface, selecting a particular node included in the graphical depiction of the network topology;

identifying access rights associated with the particular node, the access rights identifying one or more nodes with which the particular node can communicate; and

updating the graphical depiction of the network topology based on the identified access rights.

4. The method of claim 3 , wherein the graphical depiction of the network topology comprises visual representations of the plurality of nodes, and wherein updating the graphical depiction comprises:

updating the visual representations of the identified nodes with which the particular node can communicate, the updated visual representations comprising a same pattern or a same color.

5. The method of claim 1 , further comprising:

accessing information indicating compromise likelihoods associated with respective nodes, each compromise likelihood representing a likelihood of network devices being compromised; and

presenting, in the graphical depiction of the network topology, compromise likelihoods associated with the plurality of nodes.

6. The method of claim 5 , further comprising:

determining compromise risk values for the plurality of nodes, each compromise risk value for a node representing a compromise value associated with the node scaled according to a compromise likelihood associated with the node; and

updating the graphical depiction of the network topology to present the compromise risk values.

7. The method of claim 1 , further comprising:

receiving user input, via the interactive user interface, indicating a particular user account;

determining user account access rights associated with the particular user account, the user account access rights indicating access attempts to one or more nodes of the plurality of nodes; and

updating the graphical depiction of the network topology to identify the one or more nodes.

8. The method of claim 7 , wherein the interactive user interface includes a slider configured to adjust a time period associated with user account access rights.

9. The method of claim 7 , further comprising:

determining a node for which the particular user account is allowed access and has not accessed within a particular period of time; and

updating the graphical depiction of the network topology to identify the determined node.

10. The method of claim 1 , further comprising:

obtaining information indicating a critical area of the network topology, the critical area encompassing one or more nodes of the plurality of nodes;

determining one or more of: a percentage of user accounts allowed access to a node in the critical area or a percentage of nodes configured to communicate with a node in the critical area; and

presenting, in the interactive user interface, summary information associated with the determination.

11. The method of claim 10 , wherein obtaining information indicating a critical area is based on user input identifying the critical area or based on the encompassed one or nodes being associated with comprise risk values greater than a threshold.

12. A computer program product, encoded on one or more non-transitory computer storage media, comprising instructions that when executed by one or more computers cause the one or more computers to perform operations comprising:

determining a network topology of a network, the network topology comprising a plurality of nodes each connected to one or more of the plurality of nodes, wherein each node is associated with one or more network devices;

accessing information indicating compromise values associated with respective nodes; and

providing, for presentation, an interactive user interface, wherein the interactive user interface presents a graphical depiction of the network topology and compromise values associated with the plurality of nodes.

13. The computer program product of claim 12 , wherein the operations further comprise:

receiving user input, via the interactive user interface, selecting a particular node included in the graphical depiction of the network topology;

identifying access rights associated with the particular node, the access rights identifying one or more nodes with which the particular node can communicate; and

updating the graphical depiction of the network topology based on the identified access rights.

14. The computer program product of claim 13 , wherein the graphical depiction of the network topology comprises visual representations of the plurality of nodes, and wherein updating the graphical depiction comprises:

updating the visual representations of the identified nodes with which the particular node can communicate, the updated visual representations comprising a same pattern or a same color.

15. The computer program product of claim 12 , wherein the operations further comprise:

receiving user input, via the interactive user interface, indicating a particular user account;

determining user account access rights associated with the particular user account, the user account access rights indicating access attempts to one or more nodes of the plurality of nodes; and

updating the graphical depiction of the network topology to identify the one or more nodes,

wherein the interactive user interface includes a slider configured to adjust a time period associated with user account access rights.

16. The computer program product of claim 12 , wherein the operations further comprise:

obtaining information indicating a critical area of the network topology, the critical area encompassing one or more nodes of the plurality of nodes; and

determining one or more of: a percentage of user accounts allowed access to a node in the critical area or a percentage of nodes configured to communicate with a node in the critical area; and

presenting, in the interactive user interface, summary information associated with the determination.

17. The computer program product of claim 16 , wherein obtaining information indicating a critical area is based on user input identifying the critical area or based on the encompassed one or nodes being associated with comprise risk values greater than a threshold.

18. A system comprising one or more computers and non-transitory computer storage media storing instructions that, when executed by the computers, cause the computers to perform operations comprising:

determining a network topology of a network, the network topology comprising a plurality of nodes each connected to one or more of the plurality of nodes, wherein each node is associated with one or more network devices;

accessing information indicating compromise values associated with respective nodes; and

providing, for presentation, an interactive user interface, wherein the interactive user interface presents a graphical depiction of the network topology and compromise values associated with the plurality of nodes.

19. The system of claim 18 , wherein the operations further comprise:

receiving user input, via the interactive user interface, indicating a particular user account;

determining user account access rights associated with the particular user account, the user account access rights indicating access attempts to one or more nodes of the plurality of nodes; and

updating the graphical depiction of the network topology to identify the one or more nodes,

wherein the interactive user interface includes a slider configured to adjust a time period associated with user account access rights.

20. The system of claim 18 , wherein the operations further comprise:

obtaining information indicating a critical area of the network topology, the critical area encompassing one or more nodes of the plurality of nodes;

determining one or more of: a percentage of user accounts allowed access to a node in the critical area or a percentage of nodes configured to communicate with a node in the critical area; and

presenting, in the interactive user interface, summary information associated with the determination,

wherein obtaining information indicating a critical area is based on user input identifying the critical area or based on the encompassed one or nodes being associated with comprise risk values greater than a threshold.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 12, 2023
From: SEIVER, MILES; ROSENBLUM, CHARLES
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 064876/0466 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →
Cited By (1)
US 12,250,243