IP Library Granted Patent US 10,419,465
Granted Patent B2
US 10,419,465 · App. 16/182,469 · Granted Sep 17, 2019

Data retrieval in security anomaly detection platform with shared model state between real-time and batch paths

Inventors: Sudhakar Muddu (Cupertino, CA); Christos Tryfonas (Foster City, CA); Ravi Prasad Bulusu (San Jose, CA)
Assignee: SPLUNK INC.
H04L63/1416G06F3/0482G06F3/0484G06F3/04842G06F3/04847G06F16/24578G06F16/254G06F16/285G06F16/444G06F16/9024G06F17/2235G06K9/2063G06N5/022G06N5/04G06N7/005G06N20/00H04L41/0893H04L41/145H04L41/22H04L43/00H04L43/045H04L43/062H04L43/08H04L63/06H04L63/1408H04L63/1425H04L63/1433H04L63/1441H04L63/20H05K999/99H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,419,465
App. No.
16/182,469
Granted
Sep 17, 2019
Kind
B2
Abstract

A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.

Claims (80)

1. A method comprising:

implementing a batch event processing engine on a distributed data processing platform, wherein the batch event processing engine is configured to process a batch of historic event data;

performing an interaction with a datastore to retrieve specific event data;

scheduling the batch event processing engine to process the specific event data; and

enabling the batch event processing engine to share a model state of a particular machine learning model, with a real-time event processing engine on the distributed data processing platform, the real-time event processing engine being configured to process an unbounded stream of event data, the particular machine learning model being configured to process a time slice of data for detecting a security-related issue,

wherein the real-time event processing engine and the batch event processing engine each utilize the shared model state to share, with the other engine, security-related knowledge gained from processing respective data.

2. The method of claim 1 , wherein the interaction with a datastore includes sending, to the datastore, a query or a command to be executed by the datastore.

3. The method of claim 1 , wherein the interaction with a datastore includes specifying, in a query or a command to be executed by the datastore, a manner in which resulting data from the datastore is to be delivered.

4. The method of claim 1 , wherein the interaction with a datastore includes specifying, in a query or a command to be executed by the datastore, a manner in which resulting data from the datastore is to be delivered, and

wherein the manner includes selecting a particular set of the resulting data as the specific event data.

5. The method of claim 1 , wherein the interaction with a datastore includes specifying, in a query or a command to be executed by the datastore, a manner in which resulting data from the datastore is to be delivered, and

wherein the manner includes specifying a time range of the resulting data.

6. The method of claim 1 , wherein the interaction with a datastore includes specifying, in a query or a command to be executed by the datastore, a manner in which resulting data from the datastore is to be delivered, and

wherein the manner includes specifying an order of a set of the resulting data.

7. The method of claim 1 , wherein the interaction with a datastore includes specifying, in a query or a command to be executed by the datastore, a manner in which resulting data from the datastore is to be delivered, and

wherein the manner includes specifying an order of a set of the resulting data,

wherein the order includes one or more of: event time, data format, or a type of event that a particular resulting data represent.

8. The method of claim 1 , wherein the interaction with a datastore includes specifying, in a query or a command to be executed by the datastore, a manner in which resulting data from the datastore is to be delivered, and

wherein the manner includes specifying an order of a set of the resulting data,

wherein the order specifies that log files with device information are to be delivered first, followed by log files that associate user data with devices, followed by other files.

9. The method of claim 1 , wherein the interaction with a datastore includes specifying, in a query or a command to be executed by the datastore, a manner in which resulting data from the datastore is to be delivered, and

wherein the manner includes specifying an order of a set of the resulting data,

wherein the order specifies that DHCP logs are to be delivered first, followed by AD or VPN logs, followed by other files.

10. The method of claim 1 , wherein the interaction with a datastore includes specifying, in a query or a command to be executed by the datastore, a manner in which resulting data from the datastore is to be delivered, and

wherein the manner includes specifying that a particular type of the resulting data is to be delivered on a higher priority than another particular type.

11. The method of claim 1 , further comprising:

determining a priority of data type in the resulting data from the datastore; and

determining, based on the priority of the data type, a manner in which resulting data from the datastore is to be delivered.

12. The method of claim 1 , further comprising:

determining a priority of data type in the resulting data from the datastore; and

determining, based on the priority of the data type, a manner in which resulting data from the datastore is to be delivered,

wherein the interaction with a datastore includes specifying, in a query or a command to be executed by the datastore, the manner in which resulting data from the datastore is to be delivered.

13. The method of claim 1 , wherein said scheduling the batch event processing engine to process the specific event data includes:

initiating a job for the batch event processing engine with the specific event data;

tracking a progress of the job; and

recording, based on the progress, an analytical result for events represented by the specific event data.

14. The method of claim 1 , further comprising:

determining a time schedule for performing said interaction with the datastore.

15. The method of claim 1 , further comprising:

receiving an initial result from the datastore regarding the specific event data;

determining, based on the initial result, a subsequent interaction with the datastore.

16. The method of claim 1 , further comprising:

receiving an initial result from the datastore regarding the specific event data; and

determining, based on the initial result, a subsequent interaction with the datastore,

wherein the subsequent interaction with the datastore includes causing the datastore to modify a delivery order of resulting data.

17. The method of claim 1 , wherein the datastore is a Hadoop™ Distributed File System (HDFS) datastore.

18. The method of claim 1 , wherein the shared model state enables the batch event processing engine to use knowledge gained by the real-time event processing engine to discover a security-related issue in the historic event data that is undetectable by the batch event processing engine without the knowledge.

19. The method of claim 1 , further comprising:

performing, by the batch event processing engine, an analysis on the historic event data to detect a security-related issue, wherein the analysis includes at least one of: a lateral movement anomaly analysis, a behavioral peer analysis, a label propagation analysis, or a time-series anomaly analysis.

20. The method of claim 1 , further comprising:

locating, in the batch of historic event data, data representing a plurality of events associated with an entity; and

performing, by the batch event processing engine, a behavioral analysis of the entity to detect a behavioral anomaly.

21. The method of claim 1 , further comprising:

locating, in the batch of historic event data, data representing a plurality of events that are associated with behaviors performed by a plurality of entities; and

performing, by the batch event processing engine, anomaly analysis on the behaviors performed by a plurality of entities to detect a particular security-related anomaly.

22. The method of claim 1 , further comprising:

locating, by the batch event processing engine, a composite relationship graph associated with the historic event data; and

obtaining a projection of the composite relationship graph, based on a requirement of the particular machine learning model.

23. The method of claim 1 , further comprising:

receiving user feedback regarding a determination of a detected security-related issue; and

updating the particular machine learning model based on the user feedback.

24. The method of claim 1 , wherein the security-related issues include at least one of: a security-related anomaly or a security-related threat, wherein the security-related anomaly represents a detected fact, and wherein the security-related threat represents a security-related interpretation of one or more detected anomalies.

25. The method of claim 1 , wherein the event data comprise machine data.

26. The method of claim 1 , wherein the event data comprise timestamped machine data.

27. The method of claim 1 , wherein at least one of the event processing engines utilizes a particular machine learning model that is a reducible model.

28. The method of claim 1 , wherein at least one of the event processing engines utilizes a particular machine learning model that is a reducible model being reducible in at least one of: a training phase, or a scoring phase.

29. A computer system comprising:

a real-time event processing engine on the distributed data processing platform, the real-time event processing engine being configured to process an unbounded stream of event data; and

a batch event processing engine on a distributed data processing platform, wherein the batch event processing engine is configured to process a batch of historic event data;

wherein the system is configured to:

perform an interaction with a datastore to retrieve specific event data;

schedule the batch event processing engine to process the specific event data; and

enable the batch event processing engine to share a model state of a particular machine learning model, with the real-time event processing engine, the particular machine learning model being configured to process a time slice of data for detecting a security-related issue,

wherein the real-time event processing engine and the batch event processing engine each utilize the shared model state to share, with the other engine, security-related knowledge gained from processing respective data.

30. A non-transitory machine-readable storage medium for use in a processing system, the non-transitory machine-readable storage medium storing instructions, an execution of which in the processing system causes the processing system to perform operations comprising:

implementing a batch event processing engine on a distributed data processing platform, wherein the batch event processing engine is configured to process a batch of historic event data;

performing an interaction with a datastore to retrieve specific event data;

scheduling the batch event processing engine to process the specific event data; and

enabling the batch event processing engine to share a model state of a particular machine learning model, with a real-time event processing engine on the distributed data processing platform, the real-time event processing engine being configured to process an unbounded stream of event data, the particular machine learning model being configured to process a time slice of data for detecting a security-related issue,

wherein the real-time event processing engine and the batch event processing engine each utilize the shared model state to share, with the other engine, security-related knowledge gained from processing respective data.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0558 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 6, 2018
From: MUDDU, SUDHAKAR; TRYFONAS, CHRISTOS; BULUSU, RAVI PRASAD
To: SPLUNK INC.
Reel/Frame 047427/0389 →
Cited By (104)
US 12,206,696 US 12,244,621 US 12,261,866 US 12,267,345 US 12,284,197 US 12,309,181 US 12,309,182 US 12,309,185 US 12,309,236 US 12,309,660 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,381,901 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,272 US 12,452,279 US 12,457,231 US 12,463,994 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,489,771 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,511,110 US 12,511,159 US 12,513,221 US 12,526,297 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,932 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,614,139 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,640,918 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,931 US 12,706,932 US 12,706,933 US 12,706,980 US 12,712,897 US 12,719,896