IP Library Granted Patent US 11,089,043
Granted Patent B2
US 11,089,043 · App. 16/035,956 · Granted Aug 10, 2021

Systems for computer network security risk assessment including user compromise analysis associated with a network of devices

Inventors: Samuel Jones (New York, NY); Joseph Staehle (New York, NY); Lucy Cheng (Milpitas, CA)
Assignee: Palantir Technologies Inc.
H04L63/1433G06F21/55G06F21/577H04L63/102H04L63/107H04L63/14H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,089,043
App. No.
16/035,956
Granted
Aug 10, 2021
Kind
B2
Abstract

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for computer network security risk assessment. One of the methods includes obtaining compromise likelihoods for user accounts. Information describing a network topology of a network is obtained, with the network topology being nodes each connected by an edge to other nodes, each node being associated with a compromise likelihood, and one or more nodes are high value nodes associated with a compromise value. Unique paths to each of the high value nodes are determined for a particular user account. An expected value for each path is determined based on the compromise likelihood of the particular user account, the compromise likelihood of each node included in the path, the communication weight of each edge included in the path, and the compromise value associated with the high value node. User interface data is generated describing at least one path.

Claims (58)

1. A computerized method comprising:

by a system of one or more computer systems,

monitoring user behavior of a set of user accounts of a network, and identifying, based on the monitored user behavior, a particular user account of the set of user accounts for review;

obtaining information describing a network topology of the network, wherein the network topology comprises a plurality of nodes and wherein the plurality of nodes includes one or more high value nodes;

determining one or more expected values of the particular user account accessing respective high value nodes of the one or more high value nodes, wherein for a particular high value node of the one or more high value nodes, determining the expected value comprises:

identifying, for the particular user account, a plurality of unique paths to the particular high value node, wherein for a first unique path, the particular user account cannot authenticate to at least one node included in the first unique path, and

determining, based on the plurality of unique paths, an expected value of the particular user account accessing the particular high value node, wherein the expected value is based, at least in part, on communication weights between nodes included in each unique path and information describing transitions by the particular user account to one or more subsequent user accounts which are configured to authenticate to the at least one node, wherein communication weights associated with nodes included in each unique path are indicative of an access likelihood of a user transitioning between the nodes; and

determining a total expected value of the particular user account being compromised based on the one or more expected values associated with accessing the high value nodes, wherein the total expected value and identified paths are configured for presentation via a user interface.

2. The computerized method of claim 1 , wherein each unique path initiates at a respective node to which the particular user account can authenticate and indicates transitions between nodes which terminate at the particular high value node.

3. The computerized-method of claim 1 , wherein each subsequent user account being associated with a compromise likelihood.

4. The computerized-method of claim 1 , wherein determining an expected value comprises:

determining, for the particular user account, an access likelihood to the particular high value node, the access likelihood being based on the plurality of unique paths; and

determining the expected value based on a compromise value associated with the particular high value node and the determined access likelihood.

5. The computerized-method of claim 1 , wherein determining an expected value comprises:

determining, for the particular user account, an access likelihood for each unique path of the unique paths;

determining, for the unique paths, respective expected values based on a compromise value associated with the high value node and the respective access likelihood; and

selecting the expected value as a highest determined expected value.

6. The computerized-method of claim 1 , further comprising:

determining, based on the unique paths, one or more recommended nodes to reduce the expected value, each recommended node identifying a particular node to which the user can authenticate for and for which access rights of the user are to be eliminated.

7. The computerized-method of claim 6 , wherein determining recommended nodes is based on identifications of nodes to which the user has authenticated within a threshold period of time.

8. The computerized-method of claim 6 , further comprising:

generating, for at least one recommended node, an updated access control list to indicate elimination of access rights for the user; and

transmitting, to the recommended node, the updated access control list, such that the user cannot authenticate to the recommended node.

9. A system comprising one or more computers and computer storage media storing instructions that, when executed by the system, cause the system to perform operations comprising:

obtaining information describing a network topology of a network, wherein the network topology comprises a plurality of nodes and wherein the plurality of nodes includes one or more high value nodes;

determining one or more expected values of a particular user account accessing respective high value nodes of the one or more high value nodes, wherein for a particular high value node of the one or more high value nodes, determining the expected value comprises:

identifying, for the particular user account, a plurality of unique paths to the particular high value node, wherein for a first unique path, the particular user account cannot authenticate to at least one node included in the first unique path, and

determining, based on the plurality of unique paths, an expected value of the particular user account accessing the particular high value node, wherein the expected value is based, at least in part, on communication weights between nodes included in each unique path and information describing transitions by the particular user account to one or more subsequent user accounts which are configured to authenticate to the at least one node, wherein communication weights associated with nodes included in each unique path are indicative of an access likelihood of a user transitioning between the nodes; and

determining a total expected value of the particular user account being compromised based on the one or more expected values associated with accessing the high value nodes, wherein the total expected value and identified paths are configured for presentation via a user interface.

10. The system of claim 9 , wherein the operations further comprise:

monitoring user behavior of the set of user accounts associated with the network, and identifying, based on the monitored user behavior, the particular user account of the set of user accounts for review.

11. The system of claim 9 , wherein each unique path initiates at a respective node to which the particular user account can authenticate and indicates transitions between nodes which terminate at the particular high value node.

12. The system of claim 9 , wherein each subsequent user account being associated with a compromise likelihood.

13. The system of claim 9 , wherein determining an expected value comprises:

determining, for the particular user account, an access likelihood to the particular high value node, the access likelihood being based on the plurality of unique paths; and

determining the expected value based on a compromise value associated with the particular high value node and the determined access likelihood.

14. The system of claim 9 , wherein determining an expected value comprises:

determining, for the particular user account, an access likelihood for each unique path of the unique paths;

determining, for the unique paths, respective expected values based on a compromise value associated with the high value node and the respective access likelihood; and

selecting the expected value as a highest determined expected value.

15. The system of claim 9 , wherein the operations further comprise:

determining, based on the unique paths, one or more recommended nodes to reduce the expected value, each recommended node identifying a particular node to which the user can authenticate for and for which access rights of the user are to be eliminated.

16. Non-transitory computer storage media storing instructions that when executed by a system of one or more computers, cause the system to perform operations comprising:

obtaining information describing a network topology of the network, wherein the network topology comprises a plurality of nodes and wherein the plurality of nodes includes one or more high value nodes;

determining one or more expected values of a particular user account accessing respective high value nodes of the one or more high value nodes, wherein for a particular high value node of the one or more high value nodes, determining the expected value comprises:

identifying, for the particular user account, a plurality of unique paths to the particular high value node, wherein for a first unique path, the particular user account cannot authenticate to at least one node included in the first unique path, and

determining, based on the plurality of unique paths, an expected value of the particular user account accessing the particular high value node, wherein the expected value is based, at least in part, on communication weights between nodes included in each unique path and information describing transitions by the particular user account to one or more subsequent user accounts which are configured to authenticate to the at least one node, wherein communication weights associated with nodes included in each unique path are indicative of an access likelihood of a user transitioning between the nodes; and

determining a total expected value of the particular user account being compromised based on the one or more expected values associated with accessing the high value nodes, wherein the total expected value and identified paths are configured for presentation via a user interface.

17. The computer-storage media of claim 16 , wherein each subsequent user account being associated with a compromise likelihood.

18. The computer-storage media of claim 16 , wherein determining an expected value comprises:

determining, for the particular user account, an access likelihood to the particular high value node, the access likelihood being based on the plurality of unique paths; and

determining the expected value based on a compromise value associated with the particular high value node and the determined access likelihood.

19. The computer-storage media of claim 16 , wherein determining an expected value comprises:

determining, for the particular user account, an access likelihood for each unique path of the unique paths;

determining, for the unique paths, respective expected values based on a compromise value associated with the high value node and the respective access likelihood; and

selecting the expected value as a highest determined expected value.

20. The computer-storage media of claim 16 , wherein the operations further comprise:

determining, based on the unique paths, one or more recommended nodes to reduce the expected value, each recommended node identifying a particular node to which the user can authenticate for and for which access rights of the user are to be eliminated.

Assignments (8)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2023
From: JONES, SAMUEL; STAEHLE, JOSEPH; CHENG, LUCY
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 064911/0465 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENTS Recorded Jul 3, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0640 →
SECURITY INTEREST Recorded Jul 3, 2022
From: PALANTIR TECHNOLOGIES INC.
To: WELLS FARGO BANK, N.A.
Reel/Frame 060572/0506 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY LISTED PATENT BY REMOVING APPLICATION NO. 16/832267 FROM THE RELEASE OF SECURITY INTEREST PREVIOUSLY RECORDED ON REEL 052856 FRAME 0382. ASSIGNOR(S) HEREBY CONFIRMS THE RELEASE OF SECURITY INTEREST. Recorded Aug 26, 2021
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 057335/0753 →
RELEASE OF SECURITY INTEREST Recorded Jun 4, 2020
From: ROYAL BANK OF CANADA
To: PALANTIR TECHNOLOGIES INC.
Reel/Frame 052856/0382 →
SECURITY INTEREST Recorded Jun 4, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 052856/0817 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: ROYAL BANK OF CANADA, AS ADMINISTRATIVE AGENT
Reel/Frame 051709/0471 →
SECURITY INTEREST Recorded Jan 27, 2020
From: PALANTIR TECHNOLOGIES INC.
To: MORGAN STANLEY SENIOR FUNDING, INC., AS ADMINISTRATIVE AGENT
Reel/Frame 051713/0149 →