IP Library Granted Patent US 10,277,618
Granted Patent B1
US 10,277,618 · App. 16/174,051 · Granted Apr 30, 2019

Privilege inference and monitoring based on network behavior

Inventors: Xue Jun Wu (Seattle, WA); Songqian Chen (Seattle, WA); Olga Kazakova (Lake Forest Park, WA)
Assignee: ExtraHop Networks, Inc.
H04L63/1425G06F16/245H04L43/062H04L63/102H04L63/105
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,277,618
App. No.
16/174,051
Granted
Apr 30, 2019
Kind
B1
Abstract

Embodiments are directed to monitoring network traffic. A monitoring engine may monitor network traffic associated with entities in one or more networks. A device relation model may be provided based on the entities and the network traffic. An inference engine associate the entities with privilege levels based on the device relation model based on an amount of access or an amount of control that source entities exert over the target entities. An anomaly engine may determine one or more interactions between the source entities and the target entities based on the monitored network traffic. The anomaly engine may generate escalation events based on the interactions associated with the source entities and the target entities where the target entities have a higher privilege level than the source entities. The anomaly engine may provide the escalation events to one or more users.

Claims (104)

1. A method for monitoring network traffic using one or more network computers, wherein execution of instructions by the one or more network computers perform the method comprising:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic associated with a plurality of entities in one or more networks; and

providing a device relation model based on the network traffic, the plurality of entities, and the one or more metrics based on the monitored network traffic; and

instantiating an inference engine to perform actions, including:

associating the plurality of entities with one or more privilege levels based on one or more device relation models and the one or more metrics; and

increasing the one or more privilege levels for a source entity based on one or more metric values that are associated with one or more target entities that are linked to the source entity; and

instantiating an anomaly engine to perform actions, including:

determining one or more interactions between one or more source entities and the one or more target entities;

providing one or more escalation events to one or more users based on the one or more interactions and the one or more privilege levels associated with the one or more source entities; and

employing related credential information employed with one or more different applications having related activity from the one or more other activities to identify one or more sources of privilege escalation.

2. The method of claim 1 , wherein the anomaly engine performs further actions, comprising:

determining each of the one or more users that is associated with one or more privilege policies; and

employing the one or more privilege policies to determine which of the one or more escalation events to provide to each of the one or more users.

3. The method of claim 1 , wherein the anomaly engine performs further actions, comprising:

employing one or more responses by the one or more users to the one or more provided escalation events to modify one or more privilege policies associated with the one or more users.

4. The method of claim 1 , further comprising:

employing the monitoring engine to perform further actions including discovering a new entity in the one or more networks based on privilege activity monitoring; and

employing the inference engine to perform further actions, including:

adding the new entity to a dependency graph as a critical entity based on one or more of network conditions, entity behavior, or entity characteristics; and

adding one or more inferred privilege levels to the critical entity in the dependency graph based on one or more of privilege activity information or privilege relation information.

5. The method of claim 1 , further comprising:

employing the monitoring engine to perform further actions including discovering a new entity in the one or more networks based on protocol analysis and identifying remote access behavior directed to the one or more entities; and

employing the inference engine to perform further actions, including:

adding the new entity to an administration graph based on one or more of relationship information detected during administrative activities by the new entity; and

adding one or more inferred privilege levels to the new entity in the administration graph based on one or more of privilege activity information or privilege relation information.

6. The method of claim 1 , wherein the anomaly engine performs further actions, comprising:

traversing the one or more device relation models to trace network flows that pass through the one or more entities; and

determine network traffic flows that are associated with one or more different applications having related activity from one or more other entities.

7. A system for monitoring network traffic in a network:

one or more network computers, comprising:

one or more memories that store instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic associated with a plurality of entities in one or more networks; and

providing a device relation model based on the network traffic, the plurality of entities, and the one or more metrics based on the monitored network traffic; and

instantiating an inference engine to perform actions, including:

associating the plurality of entities with one or more privilege levels based on one or more device relation models and the one or more metrics; and

increasing the one or more privilege levels for a source entity based on one or more metric values that are associated with one or more target entities that are linked to the source entity; and

instantiating an anomaly engine to perform actions, including:

determining one or more interactions between one or more source entities and the one or more target entities;

providing one or more escalation events to one or more users based on the one or more interactions and the one or more privilege levels associated with the one or more source entities; and

employing related credential information employed with one or more different applications having related activity from the one or more other activities to identify one or more sources of privilege escalation.

8. The system of claim 7 , wherein the anomaly engine performs further actions, comprising:

determining each of the one or more users that is associated with one or more privilege policies; and

employing the one or more privilege policies to determine which of the one or more escalation events to provide to each of the one or more users.

9. The system of claim 7 , wherein the anomaly engine performs further actions, comprising:

employing one or more responses by the one or more users to the one or more provided escalation events to modify one or more privilege policies associated with the one or more users.

10. The system of claim 7 , further comprising:

employing the monitoring engine to perform further actions including discovering a new entity in the one or more networks based on privilege activity monitoring; and

employing the inference engine to perform further actions, including:

adding the new entity to a dependency graph as a critical entity based on one or more of network conditions, entity behavior, or entity characteristics; and

adding one or more inferred privilege levels to the critical entity in the dependency graph based on one or more of privilege activity information or privilege relation information.

11. The system of claim 7 , further comprising:

employing the monitoring engine to perform further actions including discovering a new entity in the one or more networks based on protocol analysis and identifying remote access behavior directed to the one or more entities; and

employing the inference engine to perform further actions, including:

adding the new entity to an administration graph based on one or more of relationship information detected during administrative activities by the new entity; and

adding one or more inferred privilege levels to the new entity in the administration graph based on one or more of privilege activity information or privilege relation information.

12. The system of claim 7 , wherein the anomaly engine performs further actions, comprising:

traversing the one or more device relation models to trace network flows that pass through the one or more entities; and

determine network traffic flows that are associated with one or more different applications having related activity from one or more other entities.

13. A processor readable non-transitory storage media that includes instructions for monitoring network traffic using one or more network monitoring computers, wherein execution of the instructions by the one or more network computers perform the method comprising:

instantiating a monitoring engine to perform actions, including:

monitoring network traffic associated with a plurality of entities in one or more networks; and

providing a device relation model based on the network traffic, the plurality of entities, and the one or more metrics based on the monitored network traffic; and

instantiating an inference engine to perform actions, including:

associating the plurality of entities with one or more privilege levels based on one or more device relation models and the one or more metrics; and

increasing the one or more privilege levels for a source entity based on one or more metric values that are associated with one or more target entities that are linked to the source entity; and

instantiating an anomaly engine to perform actions, including:

determining one or more interactions between one or more source entities and the one or more target entities;

providing one or more escalation events to one or more users based on the one or more interactions and the one or more privilege levels associated with the one or more source entities; and

employing related credential information employed with one or more different applications having related activity from the one or more other activities to identify one or more sources of privilege escalation.

14. The media of claim 13 , wherein the anomaly engine performs further actions, comprising:

determining each of the one or more users that is associated with one or more privilege policies; and

employing the one or more privilege policies to determine which of the one or more escalation events to provide to each of the one or more users.

15. The media of claim 13 , wherein the anomaly engine performs further actions, comprising:

employing one or more responses by the one or more users to the one or more provided escalation events to modify one or more privilege policies associated with the one or more users.

16. The media of claim 13 , further comprising:

employing the monitoring engine to perform further actions including discovering a new entity in the one or more networks based on privilege activity monitoring; and

employing the inference engine to perform further actions, including:

adding the new entity to a dependency graph as a critical entity based on one or more of network conditions, entity behavior, or entity characteristics; and

adding one or more inferred privilege levels to the critical entity in the dependency graph based on one or more of privilege activity information or privilege relation information.

17. The media of claim 13 , further comprising:

employing the monitoring engine to perform further actions including discovering a new entity in the one or more networks based on protocol analysis and identifying remote access behavior directed to the one or more entities; and

employing the inference engine to perform further actions, including:

adding the new entity to an administration graph based on one or more of relationship information detected during administrative activities by the new entity; and

adding one or more inferred privilege levels to the new entity in the administration graph based on one or more of privilege activity information or privilege relation information.

18. The media of claim 13 , wherein the anomaly engine performs further actions, comprising:

traversing the one or more device relation models to trace network flows that pass through the one or more entities; and

determine network traffic flows that are associated with one or more different applications having related activity from one or more other entities.

19. A network computer for monitoring communication over a network between two or more other computers, comprising:

one or more memories that store instructions; and

one or more processors that execute instructions that perform actions, including:

instantiating a monitoring engine to perform actions, including:

providing one or more metrics for a plurality of entities in one or more networks based on monitored network traffic; and

instantiating an inference engine to perform actions, including:

associating the plurality of entities with one or more privilege levels based on one or more device relation models and the one or more metrics; and

increasing the one or more privilege levels for a source entity based on one or more metric values that are associated with one or more target entities that are linked to the source entity; and

instantiating an anomaly engine to perform actions, including:

determining one or more interactions between one or more source entities and the one or more target entities; and

providing one or more escalation events to one or more users based on the one or more interactions and the one or more privilege levels associated with the one or more source entities.

20. The network computer of claim 19 , wherein the anomaly engine performs further actions, comprising:

determining each of the one or more users that is associated with one or more privilege policies; and

employing the one or more privilege policies to determine which of the one or more escalation events to provide to each of the one or more users.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2018
From: WU, XUE JUN; CHEN, SONGQIAN; KAZAKOVA, OLGA
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 047374/0777 →
Continuity (1)
Continuation 15984197 · May 18, 2018
Cited By (9)
US 12,225,030 US 12,309,192 US 12,355,816 US 12,483,384 US 12,489,774 US 12,587,535 US 12,621,331 US 12,647,441 US 12,652,312