IP Library Granted Patent US 11,562,088
Granted Patent B2
US 11,562,088 · App. 16/383,315 · Granted Jan 24, 2023

Threat response using event vectors

Inventors: Joseph H. Levy (Farmington, UT); Andrew J. Thomas (Oxfordshire, GB); Daniel Salvatore Schiappa (Bedford, NH); Kenneth D. Ray (Seattle, WA)
Assignee: Sophos Limited
G06F21/6218G06F16/137G06F16/285G06F16/93G06F21/64G06N20/00H04L9/3265H04L41/20H04L41/22H04L63/08H04L63/0838H04L63/101H04L63/102H04L63/1408H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/20H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,562,088
App. No.
16/383,315
Granted
Jan 24, 2023
Kind
B2
Abstract

A security platform uses a sensor-event-analysis-response methodology to iteratively adapt to a changing security environment by continuously creating and updating entity models based on observed activities and detecting patterns of events that deviate from these entity models.

Claims (43)

1. A computer program product for assessing and responding to risk in an enterprise network, the computer program product comprising computer executable code embodied in a non-transitory computer-readable medium that, when executing on one or more computing devices, performs the steps of:

instrumenting a compute instance in the enterprise network with a number of sensors to detect events from a number of computing objects associated with the compute instance;

storing a first entity model for an entity associated with the compute instance at a local security agent for the compute instance, the entity including at least one of a domain controller, a physical device, a user, an operating system, or an application associated with the compute instance, and the first entity model characterizing a pattern of events expected from the number of sensors in a vector space;

receiving events from the number of computing objects at the local security agent on the compute instance;

collecting a plurality of the events into an event vector in the vector space;

calculating a first risk score with the local security agent based on a first distance between the event vector and the first entity model in the vector space, wherein the first risk score is indicative of deviations from an activity baseline for the event vectors for the compute instance;

when the first risk score exceeds a first threshold, deploying a first remedial action for the compute instance from the local security agent;

storing a second entity model for the entity at a threat management facility that has greater computational resources than the local security agent and that is remotely accessible by the local security agent through the enterprise network, the second entity model characterizing a second pattern of events expected from the number of sensors in the vector space wherein the second entity model for the entity is adapted for use by the greater computational resources of the threat management facility;

transmitting the event vector to the threat management facility;

calculating a second risk score with the threat management facility based on a second distance between the event vector and the second entity model in the vector space, wherein the second risk score is indicative of deviations from an activity baseline for the event vectors received at the threat management facility; and

when the second risk score exceeds a second threshold, deploying a second remedial action for the compute instance from the threat management facility.

2. The computer program product of claim 1 wherein at least one of the first threshold and the second threshold is algorithmically determined.

3. The computer program product of claim 1 wherein calculating the second risk score includes evaluating the second risk score based on an event stream from two or more compute instances within the enterprise network.

4. A method for assessing and responding to risk in an enterprise network, the method comprising:

instrumenting a compute instance in the enterprise network with a number of sensors to detect events from a number of computing objects associated with the compute instance;

providing a first entity model and a second entity model for an entity associated with the compute instance, the first entity model and the second entity model characterizing a pattern of events expected from the number of sensors in a vector space;

receiving events from the number of computing objects at a local security agent on the compute instance;

collecting a plurality of the events into an event vector in the vector space;

calculating a first risk score with the local security agent based on a first distance between the event vector and the first entity model in the vector space, wherein the first risk score is indicative of deviations from an activity baseline for the event vectors for the compute instance;

when the first risk score exceeds a first threshold, deploying a first remedial action for the compute instance from the local security agent;

transmitting the event vector to a threat management facility that has greater computational resources than the local security agent and that is remotely accessible by the local security agent through the enterprise network;

calculating a second risk score with the threat management facility based on a second distance between the event vector and the second entity model in the vector space, wherein the second risk score is indicative of deviations from an activity baseline for the event vectors received at the threat management facility, and wherein the second entity model for the entity is adapted for use by the greater computational resources of the threat management facility; and

when the second risk score exceeds a second threshold, deploying a second remedial action for the compute instance from the threat management facility.

5. The method of claim 4 wherein the second entity model includes one or more events from a second compute instance in the enterprise network.

6. The method of claim 4 wherein the second entity model includes one or more events from a second entity in the enterprise network.

7. A system comprising:

a memory;

a local security agent of a compute instance in an enterprise network, the local security agent executing on a processor of the compute instance and configured to receive events from sensors on the compute instance, to generate one or more event vectors each including a collection of events for an entity associated with the compute instance, to locally determine a first risk score based on a first deviation of one of the event vectors to an entity model for the entity associated with the compute instance, wherein the first risk score is indicative of deviations from an activity baseline for the event vectors for the compute instance, and to report each of the event vectors to a remote resource; and

a threat management facility for the enterprise network having greater computational resources than the local security agent, the threat management facility executing on a processor that is remote from the compute instance and configured to operate on an event stream including event vectors reported from each of a plurality of compute instances including the compute instance, and to calculate a second risk score based on a second deviation of one or more of the event vectors in the event stream from a second entity wherein the second risk score is indicative of deviations from an activity baseline for the event vectors received at the threat management facility, and wherein a second entity model for the entity is adapted for use by the greater computational resources of the threat management facility.

8. The system of claim 7 wherein the threat management facility is configured to deploy a remedial measure for the compute instance when at least one of the first risk score and the second risk score exceeds a threshold.

9. The system of claim 8 wherein the threshold is algorithmically determined.

10. The system of claim 7 wherein the activity baseline is determined based on a historical window of event vectors for the compute instance.

11. The system of claim 10 wherein the activity baseline is periodically recalculated for a new historical window.

12. The system of claim 7 wherein the second risk score is indicative of deviations from an activity baseline for the event stream received at the threat management facility.

13. The system of claim 12 wherein the activity baseline is determined based on a historical window for the event stream.

14. The system of claim 7 wherein the first risk score is calculated based on a distance between at least one of the event vectors and the entity model in a vector space.

15. The system of claim 7 wherein the first risk score is evaluated using a k-nearest neighbor algorithm.

16. The system of claim 7 wherein the second risk score is calculated based on a distance between the event stream and one or more corresponding entity models in a vector space.

17. The system of claim 7 wherein the second risk score is evaluated using a k-nearest neighbor algorithm.

18. The system of claim 7 wherein the entity of the entity model is at least one of a domain controller, a physical device, a user, an operating system, and an application associated with the compute instance.

19. The system of claim 7 wherein one or more corresponding entity models include models for a number of entities within the enterprise network selected from the group consisting of a domain controller, an identity and access management system, a physical device, a user, an operating system, and an application associated with the compute instance.

20. The system of claim 7 wherein the event stream includes a plurality of anonymized event vectors.

21. The system of claim 7 wherein event vectors in the event stream are at least one of tokenized, encrypted, compressed, and prioritized.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2019
From: LEVY, JOSEPH H.; THOMAS, ANDREW J.; SCHIAPPA, DANIEL SALVATORE; RAY, KENNETH D.
To: SOPHOS LIMITED
Reel/Frame 051219/0735 →
Cited By (1)
US 12,481,777