IP Library Granted Patent US 10,425,437
Granted Patent B1
US 10,425,437 · App. 16/134,798 · Granted Sep 24, 2019

Extended user session tracking

Inventors: Murat Bog (Fremont, CA); Vikram Kapoor (Cupertino, CA); Samuel Joseph Pullara, III (Los Altos, CA); Yijou Chen (Cupertino, CA); Harish Kumar Bharat Singh (Mountain View, CA)
Assignee: Lacework Inc.
H04L63/1425G06F16/9024G06F21/57H04L63/10H04L67/22H04L67/306
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,425,437
App. No.
16/134,798
Granted
Sep 24, 2019
Kind
B1
Abstract

Network activity data is received, for example, from a set of agents reporting collectively information about a set of hosts. The received network activity data is used to identify a user login activity. A logical graph that links the user login activity to at least one user and at least one process is generated.

Claims (48)

1. A system, comprising:

a processor configured to:

receive network activity data;

use the received network activity data to identify a user login activity on a first machine; and

generate a logical graph comprising a plurality of edges and nodes, wherein generating the logical graph includes linking the user login activity on the first machine to: at least one of: (1) a first node corresponding to a user associated with the user login activity on the first machine, and (2) a second node corresponding to a process executed on the first machine; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 wherein the network activity data is received from a plurality of agents configured to report information, respectively, about a plurality of hosts.

3. The system of claim 1 wherein generating the logical graph includes matching connections between the first machine and a second machine.

4. The system of claim 3 wherein the first machine and second machine are different.

5. The system of claim 3 wherein the first machine and second machine are the same.

6. The system of claim 1 wherein identifying the user login activity includes identifying secure shell (ssh) connection records occurring within a first time period.

7. The system of claim 1 wherein identifying the user login activity includes matching a pair of secure shell (ssh) connection records occurring within a first time period, wherein a first member of a matched pair corresponds to a source of a connection and wherein a second member of the matched pair corresponds to a destination of the connection.

8. The system of claim 1 wherein identifying the user login activity includes matching a pair of secure shell (ssh) connection records in which a first member of a matched pair occurs within a first time period and wherein a second member of the matched pair occurs outside the first time period.

9. The system of claim 1 wherein identifying the user login activity includes matching a pair of secure shell (ssh) connection records, and wherein, in response to a determination that multiple matches are possible, a pair having the smallest delta between respective start times is selected.

10. The system of claim 1 wherein identifying the user login activity includes matching a pair of secure shell (ssh) connection records using a globally unique identifier (GUID) included by a client in a connection request.

11. The system of claim 1 wherein generating the logical graph includes joining an secure shell (ssh) connection record and a new login record.

12. The system of claim 1 wherein the processor is further configured to identify an original session associated with a subsequent chain of sessions.

13. The system of claim 12 wherein the processor is configured to identify the original session at least in part by using an secure shell (ssh) lineage table.

14. The system of claim 12 wherein the original session occurs on a first machine and wherein at least one session included in the subsequent chain of sessions occurs on a second machine that is different from the first machine.

15. The system of claim 1 wherein generating the logical graph includes determining an adjacency relationship between two login sessions.

16. The system of claim 1 wherein generating the logical graph includes associating a connection to a process.

17. The system of claim 16 wherein generating the logical graph further includes associating the process to a child process using a process hierarchy.

18. The system of claim 16 wherein generating the logical graph includes associating the process to a parent process using a process hierarchy.

19. A method, comprising:

receiving network activity data;

using the received network activity data to identify a user login activity on a first machine; and

generating a logical graph comprising a plurality of edges and nodes, wherein generating the logical graph includes linking the user login activity on the first machine to: at least one of: (1) a first node corresponding to a user associated with the user login activity on the first machine, and (2) a second node corresponding to a process executed on the first machine.

20. The method of claim 19 wherein the network activity data is received from a plurality of agents configured to report information, respectively, about a plurality of hosts.

21. The method of claim 19 wherein generating the logical graph includes matching connections between the first machine and a second machine.

22. The method of claim 21 wherein the first machine and second machine are different.

23. The method of claim 21 wherein the first machine and second machine are the same.

24. The method of claim 19 wherein identifying the user login activity includes identifying secure shell (ssh) connection records occurring within a first time period.

25. The method of claim 19 wherein identifying the user login activity includes matching a pair of secure shell (ssh) connection records occurring within a first time period, wherein a first member of a matched pair corresponds to a source of a connection and wherein a second member of the matched pair corresponds to a destination of the connection.

26. The method of claim 19 wherein identifying the user login activity includes matching a pair of secure shell (ssh) connection records in which a first member of a matched pair occurs within a first time period and wherein a second member of the matched pair occurs outside the first time period.

27. The method of claim 19 wherein identifying the user login activity includes matching a pair of secure shell (ssh) connection records, and wherein, in response to a determination that multiple matches are possible, a pair having the smallest delta between respective start times is selected.

28. The method of claim 19 wherein identifying the user login activity includes matching a pair of secure shell (ssh) connection records using a globally unique identifier (GUID) included by a client in a connection request.

29. The method of claim 19 wherein generating the logical graph includes joining an secure shell (ssh) connection record and a new login record.

30. The method of claim 19 further comprising identifying an original session associated with a subsequent chain of sessions.

31. The method of claim 30 identifying the original session includes using an secure shell (ssh) lineage table.

32. The method of claim 30 wherein the original session occurs on a first machine and wherein at least one session included in the subsequent chain of sessions occurs on a second machine that is different from the first machine.

33. The method of claim 19 wherein generating the logical graph includes determining an adjacency relationship between two login sessions.

34. The method of claim 19 wherein generating the logical graph includes associating a connection to a process.

35. The method of claim 34 wherein generating the logical graph further includes associating the process to a child process using a process hierarchy.

36. The method of claim 34 wherein generating the logical graph includes associating the process to a parent process using a process hierarchy.

37. A computer program product embodied in a tangible computer readable storage medium and comprising computer instructions for:

receiving network activity data;

using the received network activity data to identify a user login activity on a first machine; and

generating a logical graph comprising a plurality of edges and nodes, wherein generating the logical graph includes linking the user login activity on the first machine to: at least one of: (1) a first node corresponding to a user associated with the user login activity on the first machine, and (2) a second node corresponding to a process executed on the first machine.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069113/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 18, 2018
From: BOG, MURAT; KAPOOR, VIKRAM; PULLARA, SAMUEL JOSEPH, III; CHEN, YIJOU; SINGH, HARISH KUMAR BHARAT
To: LACEWORK INC.
Reel/Frame 046904/0412 →
Continuity (2)
Provisional Application 62590986 · Nov 27, 2017
Provisional Application 62650971 · Mar 30, 2018
Cited By (86)
US 12,206,696 US 12,244,621 US 12,267,345 US 12,309,185 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,279 US 12,457,231 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,513,221 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,932 US 12,706,933 US 12,712,897 US 12,719,896