IP Library Granted Patent US 10,666,668
Granted Patent B2
US 10,666,668 · App. 16/259,999 · Granted May 26, 2020

Interface providing an interactive trendline for a detected threat to facilitate evaluation for false positives

Inventors: Sudhakar Muddu (Cupertino, CA); Christos Tryfonas (Foster City, CA)
Assignee: Splunk Inc.
H04L63/1416G06F3/0482G06F3/0484G06F3/04842G06F3/04847G06F16/24578G06F16/254G06F16/285G06F16/444G06F16/9024G06F40/134G06K9/2063G06N5/022G06N5/04G06N7/005G06N20/00H04L41/0893H04L41/145H04L41/22H04L43/00H04L43/045H04L43/062H04L43/08H04L63/06H04L63/1408H04L63/1425H04L63/1433H04L63/1441H04L63/20H05K999/99H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,666,668
App. No.
16/259,999
Granted
May 26, 2020
Kind
B2
Abstract

A security platform employs a variety techniques and mechanisms to detect security related anomalies and threats in a computer network environment. The security platform is “big data” driven and employs machine learning to perform security analytics. The security platform performs user/entity behavioral analytics (UEBA) to detect the security related anomalies and threats, regardless of whether such anomalies/threats were previously known. The security platform can include both real-time and batch paths/modes for detecting anomalies and threats. By visually presenting analytical results scored with risk ratings and supporting evidence, the security platform enables network security administrators to respond to a detected anomaly or threat, and to take action promptly.

Claims (50)

1. A method comprising:

receiving event data generated by network activities of entities that interact with a computer network, wherein the event data comprises machine data, and the entities include computer users and/or devices in communication with the network;

based upon the received event data as it is received,

(i) automatically detecting anomalies indicating deviations from expected or permitted network activities, wherein each anomaly is classified by type and is associated with an entity or entities that participated in network activities and a date at which the detected anomaly occurred, and

(ii) automatically detecting threats based upon at least one of a number, type, or timing of detected anomalies, and generating a listing of detected threats as pending threats against the computer network;

upon receiving a user-selection of a detected threat, causing display, in a graphical user interface, of an interactive trendline, which indicates changes to the number of the occurrences of anomalies as a function of dates along the trendline to enable a user to visually depict a trend of the occurrences of the anomalies associated with the threat; and

upon receiving a user-selection, via the graphical user interface, to resolve the detected threat as a false positive, deleting the threat from the listing of pending threats.

2. The method of claim 1 , wherein the automated determinations result from execution of machine learning logic.

3. The method of claim 1 , wherein the trendline is a line connecting a set of points, wherein each point indicates a number of each anomalies occurring on a corresponding date.

4. The method of claim 1 , further comprising:

upon receiving a selection of a point on the trend line, identifying each anomaly occurring on the respective date; and

upon selection of an identified anomaly, causing display of the event data that triggered detection of the anomaly.

5. The method of claim 1 , further comprising:

upon receiving a selection of a point on the trend line, identifying each anomaly occurring on the respective date; and

upon receiving a selection of an anomaly from the listing of anomalies, causing display of a graphical representation of a relationship between the entities whose network activity triggered detection of the anomaly.

6. The method of claim 1 , wherein each anomaly is classified as a type from a set of anomaly types, the set of types including at least one type pertaining to an alarm, an excessive data transfer, or an unusual login time.

7. The method of claim 1 , further comprising:

upon receiving the selection of a threat, causing additional display of a graphical representation of a relationship between the entities participating in the network activities that triggered the threat, wherein the display includes one or more lines that connect the entities whose participation together in a network activity triggered an anomaly.

8. The method of claim 1 , wherein the anomalies are detected in real-time.

9. The method of claim 1 , wherein the anomalies are detected based on both real-time detection and batch detection.

10. A non-transitory, computer-readable storage medium storing instructions, an execution of which in a computer system causes the computer system to perform operations comprising:

receiving event data generated by network activities of entities that interact with a computer network, wherein the event data comprises machine data, and the entities include computer users and/or devices in communication with the network;

based upon the received event data as it is received,

(i) automatically detecting anomalies indicating deviations from expected or permitted network activities, wherein each anomaly is classified by type and is associated with an entity or entities that participated in network activities and a date at which the detected anomaly occurred, and

(ii) automatically detecting threats based upon at least one of a number, type, or timing of detected anomalies, and generating a listing of detected threats as pending threats against the computer network;

upon receiving a user-selection of a detected threat, causing display, in a graphical user interface, of an interactive trendline, which indicates changes to the number of the occurrences of anomalies as a function of dates along the trendline to enable a user to visually depict a trend of the occurrences of the anomalies associated with the threat; and

upon receiving a user-selection, via the graphical user interface, to resolve the detected threat as a false positive, deleting the threat from the listing of pending threats.

11. The computer-readable storage medium of claim 10 , wherein the automated determinations result from execution of machine learning logic.

12. The computer-readable storage medium of claim 10 , wherein the trendline is a line connecting a set of points, wherein each point indicates a number of each anomalies occurring on a corresponding date.

13. The computer-readable storage medium of claim 10 , performing operations further comprising:

upon receiving a selection of a point on the trend line, identifying each anomaly occurring on the respective date; and

upon selection of an identified anomaly, causing display of the event data that triggered detection of the anomaly.

14. The computer-readable storage medium of claim 10 , performing operations further comprising:

upon receiving a selection of a point on the trend line, identifying each anomaly occurring on the respective date; and

upon receiving a selection of an anomaly from the listing of anomalies, causing display of a graphical representation of a relationship between the entities whose network activity triggered detection of the anomaly.

15. The computer-readable storage medium of claim 10 , wherein each anomaly is classified as a type from a set of anomaly types, the set of types including at least one type pertaining to an alarm, an excessive data transfer, or an unusual login time.

16. The computer-readable storage medium of claim 10 , performing operations further comprising:

upon receiving the selection of a threat, causing additional display of a graphical representation of a relationship between the entities participating in the network activities that triggered the threat, wherein the display includes one or more lines that connect the entities whose participation together in a network activity triggered an anomaly.

17. The computer-readable storage medium of claim 10 , wherein the anomalies are detected in real-time.

18. The computer-readable storage medium of claim 10 , wherein the anomalies are detected based on both real-time detection and batch detection.

19. A computer system comprising:

computer memory for storing machine data; and

a processor for:

receiving event data generated by network activities of entities that interact with a computer network, wherein the event data comprises machine data, and the entities include computer users and/or devices in communication with the network;

based upon the received event data as it is received,

(i) automatically detecting anomalies indicating deviations from expected or permitted network activities, wherein each anomaly is classified by type and is associated with an entity or entities that participated in network activities and a date at which the detected anomaly occurred, and

(ii) automatically detecting threats based upon at least one of a number, type, or timing of detected anomalies, and generating a listing of detected threats as pending threats against the computer network;

upon receiving a user-selection of a detected threat, causing display, in a graphical user interface, of an interactive trendline, which indicates changes to the number of the occurrences of anomalies as a function of dates along the trendline to enable a user to visually depict a trend of the occurrences of the anomalies associated with the threat; and

upon receiving a user-selection, via the graphical user interface, to resolve the detected threat as a false positive, deleting the threat from the listing of pending threats.

20. The computer system of claim 19 , wherein the automated determinations result from execution of machine learning logic.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
CHANGE OF NAME Recorded Jan 6, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 069825/0558 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2019
From: MUDDU, SUDHAKAR; TRYFONAS, CHRISTOS
To: SPLUNK INC.
Reel/Frame 048727/0050 →
Cited By (102)
US 12,192,216 US 12,206,696 US 12,244,621 US 12,261,866 US 12,267,345 US 12,284,197 US 12,309,181 US 12,309,182 US 12,309,185 US 12,309,236 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,363,176 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,381,901 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,272 US 12,452,279 US 12,457,231 US 12,463,994 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,489,771 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,511,110 US 12,513,221 US 12,526,297 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,932 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,931 US 12,706,932 US 12,706,933 US 12,706,980 US 12,712,897 US 12,719,896