IP Library Granted Patent US 11,108,788
Granted Patent B1
US 11,108,788 · App. 15/980,695 · Granted Aug 31, 2021

Techniques for managing projects and monitoring network-based assets

Inventors: Brandon Dixon (San Francisco, CA); Jonas Edgeworth (San Francisco, CA); Stephen Ginty (Memphis, TN); Chris Kiernan (San Francisco, CA); Elias Manousos (San Francisco, CA); Jonathan Matkowsky (Mercer Island, WA)
Assignee: RiskIQ, Inc.
H04L63/1416H04L63/1425G06F3/04847G06T11/206G06T2200/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,108,788
App. No.
15/980,695
Granted
Aug 31, 2021
Kind
B1
Abstract

Techniques are disclosed of enabling projects to be managed for grouping artifacts about related network activity. A graphical interface can be provided to enable users to create both public and private projects with information including names, descriptions, collaborators and monitoring profiles. A project can include context and history of the project so multiple users can collaborate within a project to view the analysis process as assets are identified in the project. Information is retrieved for identified assets in separate projects and is available for display in the graphical interface.

Claims (63)

1. A method comprising:

accessing network data about one or more assets from one or more data sources by a network analysis system from one or more data sources;

generating, at the network analysis system, a plurality of data sets associated with the one or more assets based on the network data and user-generated data created by a plurality of users of the network analysis system;

generating a graphical interface to display information to a first viewing user of the plurality of users about the one or more assets based on the plurality of data sets and the user-generated data;

receiving a request from the first viewing user to configure a first project associated with at least one selected asset of the one or more assets, the first project comprising a logical container of the at least one selected asset of the one or more assets;

retrieving configured monitoring data associated with the at least one selected asset based on user-generated data associated with the at least one selected asset, wherein the user-generated data associated with the at least one selected asset configures the monitoring data and wherein the configured monitoring data comprises change information about the at least one selected asset;

generating data representing the first project associated with the at least one selected asset, the data representing the first project including the configured monitoring data;

causing the graphical interface to display the data representing the first project in association with the at least one selected asset;

identifying one or more assets in a second project created by a second viewing user of the plurality of users, the one or more identified assets related to the selected asset in the first project based on a shared attribute; and

updating the graphical interface to display a representation of the one or more identified assets in the second project in association with the first project based on the shared attribute.

2. The method of claim 1 , wherein the retrieved data associated with the one or more identified assets in the second project includes historical data indicating how the one or more identified assets were discovered.

3. The method of claim 1 , wherein the retrieved data associated with the one or more identified assets in the second project includes aggregated data of other assets having the shared attribute.

4. The method of claim 1 , wherein the first project is associated with public network data of a potential threat actor.

5. The method of claim 1 , further comprising:

receiving a request to configure monitoring of the at least one selected asset;

detecting an event related to the monitoring of the at least one selected asset;

generating data associated with the detected event; and

updating the graphical interface to display the detected event and the data associated with the detected event.

6. The method of claim 5 , wherein the request to configure monitoring is received by a toggling action performed on an interactive element in the graphical interface, wherein the graphical interface includes the interactive element to configure the monitoring.

7. The method of claim 1 , wherein the second project is associated with public network data of a potential threat actor.

8. A system comprising:

a network analysis component, implemented at least partially by hardware, configured to:

access network data about one or more assets from one or more data sources by a network analysis system from one or more data sources;

generate, at the network analysis system, a plurality of data sets associated with the one or more assets based on the network data and user-generated data created by a plurality of users of the network analysis system;

generate a graphical interface to display information to a first viewing user of the plurality of users about the one or more assets based on the plurality of data sets and the user-generated data;

receive a request from the first viewing user to configure a first project associated with at least one selected asset of the one or more assets, the first project comprising a logical container of the at least one selected asset of the one or more assets;

retrieve configured monitoring data associated with the at least one selected asset based on user-generated data associated with the at least one selected asset, wherein the user-generated data associated with the at least one selected asset configures the monitoring data and wherein the configured monitoring data comprises change information about the at least one selected asset;

generate data representing the first project associated with the at least one selected asset, the data representing the first project including the configured monitoring data; and

cause the graphical interface to display the data representing the first project in association with the at least one selected asset; and

a project manager component, implemented at least partially by hardware, configured to:

identify one or more assets in a second project created by a second viewing user of the plurality of users, the one or more identified assets related to the selected asset in the first project based on a shared attribute; and

update the graphical interface to display a representation of the one or more identified assets in the second project in association with the first project based on the shared attribute.

9. The system of claim 8 , wherein the retrieved data associated with the one or more identified assets in the second project includes historical data indicating how the one or more identified assets were discovered.

10. The system of claim 8 , wherein the retrieved data associated with the one or more identified assets in the second project includes aggregated data of other assets having the shared attribute.

11. The system of claim 8 , wherein the first project is associated with public network data of a potential threat actor.

12. The system of claim 8 , further comprising:

a monitor manager component, implemented at least partially by hardware, configured to:

receive a request to configure monitoring of the at least one selected asset;

detect an event related to the monitoring of the at least one selected asset;

generate data associated with the detected event; and

update the graphical interface to display the detected event and the data associated with the detected event.

13. The system of claim 12 , wherein the request to configure monitoring is received by a toggling action performed on an interactive element in the graphical interface, wherein the graphical interface includes the interactive element to configure the monitoring.

14. The system of claim 8 , wherein the second project is associated with public network data of a potential threat actor.

15. One or more non-transitory computer-readable media storing instructions that, when executed by one or more computing devices, cause:

accessing network data about one or more assets from one or more data sources by a network analysis system from one or more data sources;

generating, at the network analysis system, a plurality of data sets associated with the one or more assets based on the network data and user-generated data created by a plurality of users of the network analysis system;

generating a graphical interface to display information to a first viewing user of the plurality of users about the one or more assets based on the plurality of data sets and the user-generated data;

receiving a request from the first viewing user to configure a first project associated with at least one selected asset of the one or more assets, the first project comprising a logical container of the at least one selected asset of the one or more assets;

retrieving configured monitoring data associated with the at least one selected asset based on user-generated data associated with the at least one selected asset, wherein the user-generated data associated with the at least one selected asset configures the monitoring data and wherein the configured monitoring data comprises change information about the at least one selected asset;

generating data representing the first project associated with the at least one selected asset, the data representing the first project including the configured monitoring data;

causing the graphical interface to display the data representing the first project in association with the at least one selected asset; and

identifying one or more assets in a second project created by a second viewing user of the plurality of users, the one or more identified assets determined to be related to the selected asset in the first project based on a shared attribute; and

updating the graphical interface to display a representation of the one or more identified assets in the second project in association with the first project based on the shared attribute.

16. The one or more non-transitory computer-readable media of claim 15 , wherein the retrieved data associated with the one or more identified assets in the second project includes historical data indicating how the one or more identified assets were discovered.

17. The one or more non-transitory computer-readable media of claim 15 , wherein the retrieved data associated with the one or more identified assets in the second project includes aggregated data of other assets having the shared attribute.

18. The one or more non-transitory computer-readable media of claim 15 , wherein the first project is associated with public network data of a potential threat actor.

19. The one or more non-transitory computer-readable media of claim 15 , further comprising instructions that, when executed by the one or more computing devices, cause:

receiving a request to configure monitoring of the at least one selected asset;

detecting an event related to the monitoring of the at least one selected asset;

generating data associated with the detected event; and

updating the graphical interface to display the detected event and the data associated with the detected event.

20. The one or more non-transitory computer-readable media of claim 19 , wherein the request to configure monitoring is received by a toggling action performed on an interactive element in the graphical interface, wherein the graphical interface includes the interactive element to configure the monitoring.

21. The one or more non-transitory computer-readable media of claim 15 , wherein the second project is associated with public network data of a potential threat actor.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2021
From: RISKIQ, INC.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 057622/0417 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2021
From: RISKIQ, INC.
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 057581/0013 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2018
From: DIXON, BRANDON; EDGEWORTH, JONAS; GINTY, STEPHEN; KIERNAN, CHRIS; MANOUSOS, ELIAS; MATKOWSKY, JONATHAN
To: RISKIQ, INC.
Reel/Frame 046213/0208 →
Continuity (1)
Provisional Application 62506581 · May 15, 2017
Cited By (2)
US 12,381,844 US 12,700,046