IP Library Granted Patent US 11,212,299
Granted Patent B2
US 11,212,299 · App. 16/401,052 · Granted Dec 28, 2021

System and method for monitoring security attack chains

Inventors: Jamie Gamble (Toronto, CA); Sahar Rahmani (Toronto, CA); Amitkumar Tiwari (Toronto, CA)
Assignee: Royal Bank of Canada
H04L63/1416G06F16/907G06F16/9024G06F21/552H04L63/1433G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,212,299
App. No.
16/401,052
Filed
May 1, 2019
Granted
Dec 28, 2021
Kind
B2
Examiner
DO, KHANG D
Art Unit
2492
USPC
726/23
Abstract

A cybersecurity platform is described that processes collected data using a data model to identify and link anomalies and in order to identify generate security events and intrusions. The platform generates graph data structures using the security anomalies extended using additional data. The graph data structures represent links between nodes, the links being events, the nodes being machines and user accounts. The platform processes the graph data structures by combining similar nodes or grouping security events with common features to behaviour indicative of a single or multiple security events to identify chains of events which together represent an attack.

Claims (51)

1. A cybersecurity computing system comprising a processor and a memory storing machine executable instructions to configure the processor to:

collect data from different data points in a network;

process the collected data using a data model to identify anomalies and generate security events, each event having descriptive data indicating a security threat;

correlate and store data elements representing the security events and the anomalies in a data store;

extract event metadata not considered to represent security incidents and combine the metadata with the security events;

generate graph data structures using the security events and the event metadata, the graph data structures indicating links between nodes, the links being events, the nodes being machines;

collect and store the graph data structures in the data store;

process the graph data structures by combining nodes or grouping security events with common features;

determine that a processed graph data structure represents an earlier stage of a stored graph data structure that represents an attack;

generate a confidence measure and a measure of stability of an internet protocol (IP) address associated with each event; and

generate and transmit security alerts using the processed graph data structures, based on the confidence measure and the measure of stability.

2. The cybersecurity computing system of claim 1 , wherein the descriptive data indicates the security threat comprising a potential severity of the event, a probability that the event is not security related, and a reference to a stage of an attack that the event can correspond to.

3. The cybersecurity computing system of claim 1 , wherein each security event indicating potential attack data, identification of users that may be implicated by the event, identification of machines that may be implicated by the event, and time data.

4. The cybersecurity computing system of claim 1 , wherein the processor is configured to label the graph data structures with the descriptive data.

5. The cybersecurity computing system of claim 4 , wherein the descriptive data comprises a risk rating, a weighting or probability indicating likelihood that the security event is a false positive, the time the security event occurred, what phase of an attack lifecycle the security event potentially corresponds to, and the frequency of observed occurrences.

6. The cybersecurity computing system of claim 1 , wherein the processor is configured to implement additional processing of the security events before storing in the data store by leveraging external and internal data linked to the events.

7. The cybersecurity computing system of claim 1 , wherein the collected data comprises machine relationship data indicating trust relationships between machines.

8. The cybersecurity computing system of claim 1 , wherein the processor is configured to process the graph data structures based on a time analysis of security events based on a relation to an attack framework.

9. The cybersecurity computing system of claim 1 , wherein the processor is configured to process the graph data structures based on a density of the nodes in the graph data structures.

10. The cybersecurity computing system of claim 1 , wherein the processor is configured to process the graph data structures based on graph outliers identified using clustering or neural networks.

11. The cybersecurity computing system of claim 1 , wherein the processor is configured to process the graph data structures by identifying graph outliers using statistical models.

12. The cybersecurity computing system of claim 1 , wherein the processor is configured to process the graph data structures by identifying graph data structures to known attacks using neural networks.

13. The cybersecurity computing system of claim 1 , wherein the processor is configured to process the graph data structures by classification of the graph data structures by the number and diversity of their nodes.

14. The cybersecurity computing system of claim 1 , wherein the processor is configured to process the graph data structures using predictions of likely future security events.

15. A method for monitoring cybersecurity attack chains, the method comprising:

at a processor,

collecting data from different data points in a network;

processing the collected data using a data model to identify anomalies and generate generating security events, each event having descriptive data indicating a security threat;

correlating and storing the data elements representing the security events and the anomalies in a data store, the data store storing previously generated security events;

extracting event metadata not considered to represent security incidents and combining the event metadata with the security events;

generating graph data structures using the security events and the event metadata, the graph data structures indicating links between nodes, the links being events, the nodes being machines;

collecting and storing the graph data structures in the data store;

processing the graph data structures by combining nodes or grouping security events with common features;

determining that a processed graph data structure represents an earlier stage of a stored graph data structure that represents an attack;

generating a confidence measure and a measure of stability of an internet protocol (IP) address associated with each event; and

generating and transmitting security alerts using the processed graph data structures, based on the confidence measure and the measure of stability.

16. The method of claim 15 , wherein the descriptive data indicates the security threat comprising a potential severity of the event, a probability that the event is not security related, and a reference to a stage of an attack that the event can correspond to.

17. The method of claim 15 , wherein each security event indicating potential attack data, identification of users that may be implicated by the event, identification of machines that may be implicated by the event, and time data.

18. The method of claim 15 , wherein the processor is configured to label the graph data structures with the descriptive data.

19. The method of claim 15 , wherein the descriptive data comprises a risk rating, a weighting or probability indicating likelihood that the security event is a false positive, the time the security event occurred, what phase of an attack lifecycle the security event potentially corresponds to, and the frequency of observed occurrences.

20. A non-transitory computer-readable medium storing machine executable instructions, which when executed on a processor, cause the processor to perform a method for monitoring cybersecurity attack chains, the method comprising:

collecting data from different data points in a network;

processing the collected data using a data model to identify anomalies and generating security events, each event having descriptive data indicating a security threat;

correlating and storing the data elements representing the security events and the anomalies in a data store, the data store storing previously generated security events;

extracting event metadata not considered to represent security incidents and combining the metadata with the security events;

generating graph data structures using the security events and the event metadata, the graph data structures indicating links between nodes, the links being events, the nodes being machines;

determining that a processed graph data structure represents an earlier stage of a stored graph data structure that represents an attack;

collecting and storing the graph data structures in the data store;

processing the graph data structures by combining nodes or grouping security events with common features;

generating a confidence measure and a measure of stability of an internet protocol (IP) address associated with each event; and

generating and transmitting security alerts using the processed graph data structures, based on the confidence measure and the measure of stability.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 28, 2021
From: GAMBLE, JAMIE; RAHMANI, SAHAR; TIWARI, AMITKUMAR
To: ROYAL BANK OF CANADA
Reel/Frame 056076/0001 →
Continuity (3)
Provisional Application 62665198 · May 1, 2018
Provisional Application 62665208 · May 1, 2018
Related Publication 20190342307A1 · Nov 7, 2019
Cited By (101)
US 12,206,696 US 12,244,621 US 12,261,866 US 12,267,345 US 12,284,197 US 12,309,181 US 12,309,182 US 12,309,185 US 12,309,236 US 12,323,449 US 12,335,286 US 12,335,348 US 12,341,797 US 12,348,545 US 12,355,626 US 12,355,787 US 12,355,793 US 12,363,148 US 12,368,745 US 12,368,746 US 12,368,747 US 12,375,573 US 12,381,901 US 12,395,573 US 12,401,669 US 12,405,849 US 12,407,701 US 12,407,702 US 12,418,552 US 12,418,555 US 12,425,428 US 12,425,430 US 12,445,474 US 12,452,272 US 12,452,279 US 12,457,231 US 12,463,994 US 12,463,995 US 12,463,996 US 12,463,997 US 12,464,003 US 12,470,577 US 12,470,578 US 12,483,576 US 12,489,770 US 12,489,771 US 12,495,052 US 12,500,910 US 12,500,911 US 12,500,912 US 12,505,126 US 12,506,762 US 12,511,110 US 12,513,221 US 12,526,297 US 12,537,836 US 12,537,837 US 12,537,839 US 12,537,840 US 12,537,884 US 12,549,575 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,060 US 12,563,064 US 12,563,071 US 12,563,072 US 12,580,932 US 12,580,934 US 12,580,935 US 12,580,936 US 12,580,937 US 12,587,553 US 12,592,950 US 12,598,205 US 12,613,930 US 12,615,271 US 12,621,324 US 12,621,329 US 12,627,686 US 12,627,687 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,659,325 US 12,659,326 US 12,659,327 US 12,659,333 US 12,676,874 US 12,689,638 US 12,689,640 US 12,695,768 US 12,706,931 US 12,706,932 US 12,706,933 US 12,706,980 US 12,712,897 US 12,719,896 US 12,726,495