IP Library Granted Patent US 10,581,891
Granted Patent B1
US 10,581,891 · App. 16/134,794 · Granted Mar 3, 2020

Using graph-based models to identify datacenter anomalies

Inventors: Vikram Kapoor (Cupertino, CA); Samuel Joseph Pullara, III (Los Altos, CA); Murat Bog (Fremont, CA); Yijou Chen (Cupertino, CA); Sanjay Kalra (San Jose, CA)
Assignee: Lacework Inc.
H04L63/1425H04L43/045H04L43/06G06F16/2456
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,581,891
App. No.
16/134,794
Filed
Sep 18, 2018
Granted
Mar 3, 2020
Kind
B1
Art Unit
2443
USPC
709/224
Abstract

Activities within a network environment are monitored (e.g., using agents). At least a portion of the monitored activities are used to generate a logical graph model. The generated logical graph model is used to determine an anomaly. The detected anomaly is recorded and can be used to generate an alert.

Claims (45)

1. A system, comprising:

a processor configured to:

monitor activities within a network environment and generate a graph of physical connection information, wherein generating the graph of physical connection information includes matching information provided by a client and a server, respectively, into an established connection between the client and the server;

use at least a portion of the generated graph of physical connection information to generate a multidimensional logical graph model, wherein the multidimensional logical graph model comprises a set of nodes and a set of edges, wherein a first node included in the set of nodes corresponds to an entity of a first type and wherein a second node included in the set of nodes corresponds to an entity of a second type that is different from the first type, wherein an edge connects the first node and the second node, wherein a first edge between the first node and the second node has a first edge type and a second edge between the second node and a third node has a second edge type that is different from the first edge type, wherein the first edge type indicates a first behavioral relationship between arbitrary nodes interconnected by the first edge type, and wherein the second edge type indicates a different behavioral relationship between arbitrary nodes interconnected by the second edge type;

determine, using the generated multidimensional logical graph model, that a new edge has been added to the set of edges; and

in response to determining that the new edge has been added to the set of edges, automatically generate an alert that an anomaly in the network environment associated with the new edge has occurred; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 wherein the generated multidimensional logical graph model represents a baseline of behavior of nodes included in the network environment.

3. The system of claim 2 wherein using the multidimensional logical graph model to detect the anomaly includes comparing a current graph associated with the network environment against the baseline.

4. The system of claim 1 wherein the network environment comprises a datacenter.

5. The system of claim 1 wherein the detected anomaly is associated with identifying a security threat.

6. The system of claim 1 wherein the multidimensional logical graph model is generated at least in part by performing matching neighbors clustering on a graph.

7. The system of claim 6 wherein the graph comprises process information.

8. The system of claim 1 wherein the multidimensional logical graph model is generated at least in part by performing similarity ranking on a graph.

9. The system of claim 8 wherein the graph comprises process information.

10. The system of claim 1 wherein the multidimensional logical graph model is generated at least in part by performing a split on a graph.

11. The system of claim 10 wherein the graph comprises process information.

12. The system of claim 10 wherein the split is based at least in part on an application type.

13. The system of claim 1 wherein the processor is further configured to determine whether a process matches a predetermined application type included in a set of predetermined application types.

14. The system of claim 13 wherein the processor is further configured to generate an alert in response to determining that the process does not match any members of the set of predetermined application types.

15. The system of claim 1 wherein detecting the anomaly includes detecting a new node in the multidimensional logical graph model.

16. A method, comprising:

monitoring activities within a network environment and generating a graph of physical connection information, wherein generating the graph of physical connection information includes matching information provided by a client and a server, respectively, into an established connection between the client and the server;

using at least a portion of the generated graph of physical connection information to generate a multidimensional logical graph model, wherein the multidimensional logical graph model comprises a set of nodes and a set of edges, wherein a first node included in the set of nodes corresponds to an entity of a first type and wherein a second node included in the set of nodes corresponds to an entity of a second type that is different from the first type, wherein an edge connects the first node and the second node, wherein a first edge between the first node and the second node has a first edge type and a second edge between the second node and a third node has a second edge type that is different from the first edge type, wherein the first edge type indicates a first behavioral relationship between arbitrary nodes interconnected by the first edge type, and wherein the second edge type indicates a different behavioral relationship between arbitrary nodes interconnected by the second edge type;

determining, using the generated multidimensional logical graph model, that a new edge has been added to the set of edges; and

in response to determining that the new edge has been added to the set of edges, automatically generating an alert that an anomaly in the network environment associated with the new edge has occurred.

17. The method of claim 16 wherein the generated multidimensional logical graph model represents a baseline of behavior of nodes included in the network environment.

18. The method of claim 17 wherein using the multidimensional logical graph model to detect the anomaly includes comparing a current graph associated with the network environment against the baseline.

19. The method of claim 16 wherein the network environment comprises a datacenter.

20. The method of claim 16 wherein the detected anomaly is associated with identifying a security threat.

21. The method of claim 16 wherein the multidimensional logical graph model is generated at least in part by performing matching neighbors clustering on a graph.

22. The method of claim 21 wherein the graph comprises process information.

23. The method of claim 16 wherein the multidimensional logical graph model is generated at least in part by performing similarity ranking on a graph.

24. The method of claim 23 wherein the graph comprises process information.

25. The method of claim 16 wherein the multidimensional logical graph model is generated at least in part by performing a split on a graph.

26. The method of claim 25 wherein the graph comprises process information.

27. The method of claim 25 wherein the split is based at least in part on an application type.

28. The method of claim 16 further comprising determining whether a process matches a predetermined application type included in a set of predetermined application types.

29. The method of claim 28 further comprising generating an alert in response to determining that the process does not match any members of the set of predetermined application types.

30. The method of claim 16 wherein detecting the anomaly includes detecting a new node in the multidimensional logical graph model.

31. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

monitoring activities within a network environment and generating a graph of physical connection information, wherein generating the graph of physical connection information includes matching information provided by a client and a server, respectively, into an established connection between the client and the server;

using at least a portion of the generated graph of physical connection information to generate a multidimensional logical graph model, wherein the multidimensional logical graph model comprises a set of nodes and a set of edges, wherein a first node included in the set of nodes corresponds to an entity of a first type and wherein a second node included in the set of nodes corresponds to an entity of a second type that is different from the first type, wherein an edge connects the first node and the second node, wherein a first edge between the first node and the second node has a first edge type and a second edge between the second node and a third node has a second edge type that is different from the first edge type, wherein the first edge type indicates a first behavioral relationship between arbitrary nodes interconnected by the first edge type, and wherein the second edge type indicates a different behavioral relationship between arbitrary nodes interconnected by the second edge type;

determining, using the generated multidimensional logical graph model, that a new edge has been added to the set of edges; and

in response to determining that the new edge has been added to the set of edges, automatically generating an alert that an anomaly in the network environment associated with the new edge has occurred.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069113/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2018
From: KAPOOR, VIKRAM; PULLARA, SAMUEL JOSEPH, III; BOG, MURAT; CHEN, YIJOU; KALRA, SANJAY
To: LACEWORK INC.
Reel/Frame 046904/0396 →
Continuity (2)
Provisional Application 62650971 · Mar 30, 2018
Provisional Application 62590986 · Nov 27, 2017
Cited By (95)
US 12,206,696 US 12,244,621 US 12,261,866 US 12,267,345 US 12,284,197 US 12,309,185 US 12,309,236 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,574 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,279 US 12,457,231 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,489,771 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,500,917 US 12,505,126 US 12,506,762 US 12,513,221 US 12,526,297 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,568,085 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,932 US 12,706,933 US 12,706,980 US 12,712,897 US 12,719,896