IP Library Granted Patent US 10,915,625
Granted Patent B2
US 10,915,625 · App. 16/161,701 · Granted Feb 9, 2021

Graph model for alert interpretation in enterprise security system

Inventors: LuAn Tang (Pennington, NJ); Zhengzhang Chen (Princeton Junction, NJ); Zhichun Li (Princeton, NJ); Zhenyu Wu (Plainsboro, NJ); Jumpei Kamimura (South Brunswick, NJ); Haifeng Chen (West Windsor, NJ)
G06F21/552G06F21/57H04L41/065H04L41/0613H04L41/142H04L63/1416H04L41/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,915,625
App. No.
16/161,701
Granted
Feb 9, 2021
Kind
B2
Abstract

A computer-implemented method for implementing alert interpretation in enterprise security systems is presented. The computer-implemented method includes employing a plurality of sensors to monitor streaming data from a plurality of computing devices, generating alerts based on the monitored streaming data, employing an alert interpretation module to interpret the alerts in real-time, matching problematic entities to the streaming data, retrieving following events, and generating an aftermath graph on a visualization component.

Claims (303)

1. A computer-implemented method executed on a processor for implementing alert interpretation in enterprise security systems, the method comprising:

employing a plurality of sensors to monitor streaming data from a plurality of computing devices;

generating alerts based on the monitored streaming data;

employing an alert interpretation module to interpret the alerts;

matching problematic entities to the streaming data;

retrieving following events; and

generating an aftermath graph on a visualization component,

wherein the problematic entities are stored in a memory by an alert aftermath tracer;

wherein the aftermath graph is constructed incrementally over the streaming data;

wherein the alert interpretation module includes a process-star graph constructor for retrieving relationships from the streaming data to construct process-star graph models;

wherein the alert interpretation module further includes an alert cause detector for analyzing the alerts based on the process-star graph models to determine an entity that causes an alert;

wherein the alert interpretation module further includes an information integrator for integrating alert cause, aftermath, and baseline information to generate a result graph on the visualization component to allow the users to interpret the alerts;

wherein the alert cause detector constructs a situation-aware graph based on retrieved process-star graph models, computes abnormal scores for each related entity, and determines a cause for the alert;

wherein the situation-aware graph is merged with the aftermath graph;

wherein the cause of the alert can be determined based on entity seniority, entity stability, and entity similarity; and

wherein the entity seniority is computed by

ρ

(

o

)

=

{

t

-

t

0

T

if

t

-

t

0

<

T

1

if

t

-

t

0

T

,

the entity stability is computed by

σ

(

v

)

=

Count

(

T

stable

)

Count

(

T

)

,

and the entity similarity is computed by

γ

src

(

o

1

,

o

2

)

=

dst

(

o

1

)

dst

(

o

2

)

dst

(

o

1

)

dst

(

o

2

)

and

γ

dst

(

o

1

,

o

2

)

=

src

(

o

1

)

src

(

o

2

)

src

(

o

1

)

src

(

o

2

)

,

where T is a time threshold, Count (T stable ) is a count of stable windows in which no edge connects from/to o, Count(T) is a total number of windows, and dst(o) and src(o) denote destinations/sources that have edges from/to v.

2. The method of claim 1 , wherein an entity abnormal score for a process node is computed by φ(p)=(1−σ(p))*(1−ρ(p))*(1−max o i ∈dst(p) γ dst (o, o i )) and an entity abnormal score for an object node is computed by φ(o)=(1−σ(o))*(1−ρ(o))*(1−max p j ∈src(o) γ src (p, p j )), where ρ is entity seniority, σ is entity stability, γ is entity similarity, and p is a process.

3. A system for implementing alert interpretation in enterprise security systems, the system comprising:

a memory; and

a processor device in communication with the memory, wherein the processor device is configured to:

employ a plurality of sensors to monitor streaming data from a plurality of computing devices;

generate alerts based on the monitored streaming data;

employ an alert interpretation module to interpret the alerts;

match problematic entities to the streaming data;

retrieve following events; and

generate an aftermath graph on a visualization component,

wherein the problematic entities are stored in a memory by an alert aftermath tracer;

wherein the aftermath graph is constructed incrementally over the streaming data;

wherein the alert interpretation module includes a process-star graph constructor for retrieving relationships from the streaming data to construct process-star graph models;

wherein the alert interpretation module further includes an alert cause detector for analyzing the alerts based on the process-star graph models to determine an entity that causes an alert;

wherein the alert interpretation module further includes an information integrator for integrating alert cause, aftermath, and baseline information to generate a result graph on the visualization component to allow the users to interpret the alerts;

wherein the alert cause detector constructs a situation-aware graph based on retrieved process-star graph models, computes abnormal scores for each related entity, and determines a cause for the alert;

wherein the situation-aware graph is merged with the aftermath graph;

wherein the cause of the alert can be determined based on entity seniority, entity stability, and entity similarity; and

wherein the entity seniority is computed by

ρ

(

o

)

=

{

t

-

t

0

T

if

t

-

t

0

<

T

1

if

t

-

t

0

T

,

the entity stability is computed by

σ

(

v

)

=

Count

(

T

stable

)

Count

(

T

)

,

and the entity similarity is computed by

γ

s

r

c

(

o

1

,

o

2

)

=

dst

(

o

1

)

dst

(

o

2

)

dst

(

o

1

)

dst

(

o

2

)

and

γ

dst

(

o

1

,

o

2

)

=

src

(

o

1

)

src

(

o

2

)

src

(

o

1

)

src

(

o

2

)

,

where T is a time threshold, Count(T stable ) is a count of stable windows in which no edge connects from/to o, Count(T) is a total number of windows, and dst(o) and src(o) denote destinations/sources that have edges from/to v.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 22, 2020
From: NEC LABORATORIES AMERICA, INC.
To: NEC CORPORATION
Reel/Frame 054724/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 16, 2018
From: TANG, LUAN; CHEN, ZHENGZHANG; LI, ZHICHUN; WU, ZHENYU; KAMIMURA, JUMPEI; CHEN, HAIFENG
To: NEC LABORATORIES AMERICA, INC.
Reel/Frame 047183/0103 →