IP Library Granted Patent US 10,116,679
Granted Patent B1
US 10,116,679 · App. 15/984,197 · Granted Oct 30, 2018

Privilege inference and monitoring based on network behavior

Inventors: Xue Jun Wu (Seattle, WA); Songqian Chen (Seattle, WA); Olga Kazakova (Lake Forest Park, WA)
Assignee: ExtraHop Networks, Inc.
H04L63/1425G06F17/30424H04L43/062H04L63/102H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,116,679
App. No.
15/984,197
Granted
Oct 30, 2018
Kind
B1
Abstract

Embodiments are directed to monitoring network traffic. A monitoring engine may monitor network traffic associated with entities in one or more networks. A device relation model may be provided based on the entities and the network traffic. An inference engine associate the entities with privilege levels based on the device relation model based on an amount of access or an amount of control that source entities exert over the target entities. An anomaly engine may determine one or more interactions between the source entities and the target entities based on the monitored network traffic. The anomaly engine may generate escalation events based on the interactions associated with the source entities and the target entities where the target entities have a higher privilege level than the source entities. The anomaly engine may provide the escalation events to one or more users.

Claims (114)

1. A method for monitoring network traffic using one or more network computers, wherein execution of instructions by the one or more network computers perform the method comprising:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics, wherein the entities include one or more of a source entity and one or more of a target entity; and

providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and

instantiating an inference engine to perform actions, including:

associating the plurality of entities with one or more privilege levels based on the device relation model and the one or more metrics, wherein a value for each of the one or more privilege levels is based on one or more of an amount of access or an amount of control that the one or more source entities exert over the one or more target entities; and

increasing the one or more privilege levels for a source entity based on one or more metric values that are associated with the one or more target entities that are linked to the source entity; and

instantiating an anomaly engine to perform actions, including:

determine one or more interactions between the one or more source entities and the one or more target entities based on the monitored network traffic;

generating one or more escalation events based on the one or more interactions and the one or more privilege levels associated with the one or more source entities and the one or more target entities, wherein the one or more interactions or the one or more target entities are associated with a privilege level that exceeds the one or more privilege levels associated with the one or more source entities; and

providing the one or more escalation events to one or more users.

2. The method of claim 1 , wherein the anomaly engine performs actions, further comprising:

determining one or more application protocols that are associated with the one or more interactions based on the monitored network traffic; and

determining a privilege level that is associated with each of the one or more interactions that are associated with the one or more determined application protocols.

3. The method of claim 1 , wherein the actions of the inference engine further comprise, modifying each privilege level associated with each entity based on one or more characteristics including one or more of resources accessed by an entity, resources provided by the entity, users that access the entity, users that are logged into the entity, an uptime of the entity, privilege levels of connected entities, privilege levels of related entities, privilege levels of the logged in users, number of clients, or additional metadata.

4. The method of claim 1 , wherein the actions of the monitoring engine further comprise:

modifying the device relation model based on one or more of additions or removals of the plurality of entities in the network; and

modifying the one or more privilege levels associated with the plurality of entities based on the one or more modifications to the device relation model.

5. The method of claim 1 , wherein the anomaly engine performs actions, further comprising:

querying one or more databases to obtain information about the one or more interactions, wherein the one or more databases are separate from the anomaly engine and a network monitoring computer; and

further determining the one or more escalation events based on the obtained information.

6. The method of claim 1 , wherein the monitoring engine performs actions, further comprising:

determining one or more network topology characteristics based on the monitored network traffic;

associating one or more default privilege levels with the plurality of entities based on the one or more network topology characteristics.

7. The method of claim 1 , wherein the inference engine performs further actions including:

associating the plurality of entities with metadata that includes one or more of user identities, user types, read/write accessibility, application types, direction of relation, age of relation, or frequency of activity; and

modifying the one or more privilege levels based on the metadata.

8. A processor readable non-transitory storage media that includes instructions for monitoring network traffic using one or more network monitoring computers, wherein execution of the instructions by the one or more network computers perform the method comprising:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics, wherein the entities include one or more of a source entity and one or more of a target entity; and

providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and

instantiating an inference engine to perform actions, including:

associating the plurality of entities with one or more privilege levels based on the device relation model and the one or more metrics, wherein a value for each of the one or more privilege levels is based on one or more of an amount of access or an amount of control that the one or more source entities exert over the one or more target entities; and

increasing the one or more privilege levels for a source entity based on one or more metric values that are associated with the one or more target entities that are linked to the source entity; and

instantiating an anomaly engine to perform actions, including:

determine one or more interactions between the one or more source entities and the one or more target entities based on the monitored network traffic;

generating one or more escalation events based on the one or more interactions and the one or more privilege levels associated with the one or more source entities and the one or more target entities, wherein the one or more interactions or the one or more target entities are associated with a privilege level that exceeds the one or more privilege levels associated with the one or more source entities; and

providing the one or more escalation events to one or more users.

9. The media of claim 8 , wherein the anomaly engine performs actions, further comprising:

determining one or more application protocols that are associated with the one or more interactions based on the monitored network traffic; and

determining a privilege level that is associated with each of the one or more interactions that are associated with the one or more determined application protocols.

10. The media of claim 8 , wherein the actions of the inference engine further comprise, modifying each privilege level associated with each entity based on one or more characteristics including one or more of resources accessed by an entity, resources provided by the entity, users that access the entity, users that are logged into the entity, an uptime of the entity, privilege levels of connected entities, privilege levels of related entities, privilege levels of the logged in users, number of clients, or additional metadata.

11. The media of claim 8 , wherein the actions of the monitoring engine further comprise:

modifying the device relation model based on one or more of additions or removals of the plurality of entities in the network; and

modifying the one or more privilege levels associated with the plurality of entities based on the one or more modifications to the device relation model.

12. The media of claim 8 , wherein the anomaly engine performs actions, further comprising:

querying one or more databases to obtain information about the one or more interactions, wherein the one or more databases are separate from the anomaly engine and a network monitoring computer; and

further determining the one or more escalation events based on the obtained information.

13. The media of claim 8 , wherein the monitoring engine performs actions, further comprising:

determining one or more network topology characteristics based on the monitored network traffic;

associating one or more default privilege levels with the plurality of entities based on the one or more network topology characteristics.

14. The media of claim 8 , wherein the inference engine performs further actions including:

associating the plurality of entities with metadata that includes one or more of user identities, user types, read/write accessibility, application types, direction of relation, age of relation, or frequency of activity; and

modifying the one or more privilege levels based on the metadata.

15. A system for monitoring network traffic in a network:

one or more network computers, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics, wherein the entities include one or more of a source entity and one or more of a target entity; and

providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and

instantiating an inference engine to perform actions, including:

associating the plurality of entities with one or more privilege levels based on the device relation model and the one or more metrics, wherein a value for each of the one or more privilege levels is based on one or more of an amount of access or an amount of control that the one or more source entities exert over the one or more target entities; and

increasing the one or more privilege levels for a source entity based on one or more metric values that are associated with the one or more target entities that are linked to the source entity; and

instantiating an anomaly engine to perform actions, including:

determine one or more interactions between the one or more source entities and the one or more target entities based on the monitored network traffic;

generating one or more escalation events based on the one or more interactions and the one or more privilege levels associated with the one or more source entities and the one or more target entities, wherein the one or more interactions or the one or more target entities are associated with a privilege level that exceeds the one or more privilege levels associated with the one or more source entities; and

providing the one or more escalation events to one or more users; and

one or more client computers, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing one or more portions of the network traffic.

16. The system of claim 15 , wherein the anomaly engine performs actions, further comprising:

determining one or more application protocols that are associated with the one or more interactions based on the monitored network traffic; and

determining a privilege level that is associated with each of the one or more interactions that are associated with the one or more determined application protocols.

17. The system of claim 15 , wherein the actions of the inference engine further comprise, modifying each privilege level associated with each entity based on one or more characteristics including one or more of resources accessed by an entity, resources provided by the entity, users that access the entity, users that are logged into the entity, an uptime of the entity, privilege levels of connected entities, privilege levels of related entities, privilege levels of the logged in users, number of clients, or additional metadata.

18. The system of claim 15 , wherein the actions of the monitoring engine further comprise:

modifying the device relation model based on one or more of additions or removals of the plurality of entities in the network; and

modifying the one or more privilege levels associated with the plurality of entities based on the one or more modifications to the device relation model.

19. The system of claim 15 , wherein the anomaly engine performs actions, further comprising:

querying one or more databases to obtain information about the one or more interactions, wherein the one or more databases are separate from the anomaly engine and a network monitoring computer; and

further determining the one or more escalation events based on the obtained information.

20. The system of claim 15 , wherein the monitoring engine performs actions, further comprising:

determining one or more network topology characteristics based on the monitored network traffic;

associating one or more default privilege levels with the plurality of entities based on the one or more network topology characteristics.

21. A network computer for monitoring communication over a network between two or more computers, comprising:

a transceiver that communicates over the network;

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic associated with a plurality of entities in one or more networks to provide one or more metrics, wherein the entities include one or more of a source entity and one or more of a target entity; and

providing a device relation model based on the plurality of entities, the network traffic, and the one or more metrics; and

instantiating an inference engine to perform actions, including:

associating the plurality of entities with one or more privilege levels based on the device relation model and the one or more metrics, wherein a value for each of the one or more privilege levels is based on one or more of an amount of access or an amount of control that the one or more source entities exert over the one or more target entities; and

increasing the one or more privilege levels for a source entity based on one or more metric values that are associated with the one or more target entities that are linked to the source entity; and

instantiating an anomaly engine to perform actions, including:

determine one or more interactions between the one or more source entities and the one or more target entities based on the monitored network traffic;

generating one or more escalation events based on the one or more interactions and the one or more privilege levels associated with the one or more source entities and the one or more target entities, wherein the one or more interactions or the one or more target entities are associated with a privilege level that exceeds the one or more privilege levels associated with the one or more source entities; and

providing the one or more escalation events to one or more users.

22. The network computer of claim 21 , wherein the anomaly engine performs actions, further comprising:

determining one or more application protocols that are associated with the one or more interactions based on the monitored network traffic; and

determining a privilege level that is associated with each of the one or more interactions that are associated with the one or more determined application protocols.

23. The network computer of claim 21 , wherein the actions of the inference engine further comprise, modifying each privilege level associated with each entity based on one or more characteristics including one or more of resources accessed by an entity, resources provided by the entity, users that access the entity, users that are logged into the entity, an uptime of the entity, privilege levels of connected entities, privilege levels of related entities, privilege levels of the logged in users, number of clients, or additional metadata.

24. The network computer of claim 21 , wherein the actions of the monitoring engine further comprise:

modifying the device relation model based on one or more of additions or removals of the plurality of entities in the network; and

modifying the one or more privilege levels associated with the plurality of entities based on the one or more modifications to the device relation model.

25. The network computer of claim 21 , wherein the anomaly engine performs actions, further comprising:

querying one or more databases to obtain information about the one or more interactions, wherein the one or more databases are separate from the anomaly engine and a network monitoring computer; and

further determining the one or more escalation events based on the obtained information.

26. The network computer of claim 21 , wherein the monitoring engine performs actions, further comprising:

determining one or more network topology characteristics based on the monitored network traffic;

associating one or more default privilege levels with the plurality of entities based on the one or more network topology characteristics.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2018
From: WU, XUE JUN; CHEN, SONGQIAN; KAZAKOVA, OLGA
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 045849/0960 →
Cited By (16)
US 12,225,030 US 12,238,102 US 12,267,299 US 12,309,192 US 12,355,770 US 12,355,816 US 12,432,242 US 12,468,639 US 12,483,384 US 12,587,535 US 12,603,921 US 12,639,057 US 12,647,441 US 12,652,312 US 12,670,246 US 12,695,793