IP Library Granted Patent US 10,411,982
Granted Patent B1
US 10,411,982 · App. 16/442,257 · Granted Sep 10, 2019

Automated risk assessment based on machine generated investigation

Inventors: Edmund Hope Driggs (Seattle, WA); Jesse Abraham Rothstein (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L43/0876H04L43/14H04L43/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,411,982
App. No.
16/442,257
Granted
Sep 10, 2019
Kind
B1
Abstract

Embodiments are directed to monitoring network traffic using a network computer. The network computer provides anomaly information associated with anomalies that may be associated with monitored network traffic. An inference engine may determine the users associated with the anomalies based on the monitored network traffic. A communication channel associated with the users may be determined based on the anomalies and the monitored network traffic such that the communication channel may be separate from the monitored network traffic. The communication channel may be employed to provide investigative agents to the users. Investigative information may be collected from the investigative agents over the communication channel. The inference engine may provide a risk value that is associated with the anomalies based on the investigative information.

Claims (87)

1. A method for monitoring network traffic using one or more network computers over one or more networks, wherein the execution of instructions by the one or more network computers perform the method comprising:

providing information that is associated with one or more anomalies that are associated with one or more users over one or more portions of the monitored network traffic;

annotating the provided information to include one or more attributes based on one or more metrics that are associated with the one or more portions of the monitored network traffic;

employing the annotated anomaly information to determine a communication channel that is separate from the monitored network traffic and associated with the one or more users;

determining one or more investigative agents based on the annotated anomaly information; and

providing a report based on an evaluation of investigative information provided by the one or more investigative agents.

2. The method of claim 1 , further comprising:

classifying the one or more anomalies based on one or more profiles, wherein the one or more profiles are associated with one or more risk levels.

3. The method of claim 1 , further comprising:

employing the investigative information and one or more profiles to classify the one or more anomalies, wherein the evaluation is further based on the classification of the one or more anomalies.

4. The method of claim 1 , further comprising;

annotating one or more profiles associated with the one or more anomalies, wherein the annotation of the one or more profiles is employed to provide one or more of classification the one or more anomalies or resolution of one or more subsequent anomalies.

5. The method of claim 1 , wherein determining the communication channel further comprises employing the one or more anomalies and the one or more portions of the monitored network traffic.

6. The method of claim 1 , further comprises:

employing the communication channel to:

provide the one or more investigative agents to the one or more users; or

provide the investigative information from the one or more investigative agents.

7. The method of claim 1 , further comprising:

determining one or more remediation actions based on the investigative information, wherein the one or more remediation actions includes one or more of quarantining an endpoint, blocking network traffic, or locking a user account.

8. A system for monitoring network traffic in one or more networks:

one or more network computers, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing information that is associated with one or more anomalies that are associated with one or more users over one or more portions of the monitored network traffic;

annotating the provided information to include one or more attributes based on one or more metrics that are associated with the one or more portions of the monitored network traffic;

employing the annotated anomaly information to determine a communication channel that is separate from the monitored network traffic and associated with the one or more users;

determining one or more investigative agents based on the annotated anomaly information; and

providing a report based on an evaluation of investigative information provided by the one or more investigative agents; and

one or more client computers, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing one or more of the one or more portions of the monitored network traffic.

9. The system of claim 8 , wherein the one or more processors of the one or more network computers perform further actions, comprising:

classifying the one or more anomalies based on one or more profiles, wherein the one or more profiles are associated with one or more risk levels.

10. The system of claim 8 , wherein the one or more processors of the one or more network computers perform further actions, comprising:

employing the investigative information and one or more profiles to classify the one or more anomalies, wherein the evaluation is further based on the classification of the one or more anomalies.

11. The system of claim 8 , wherein the one or more processors of the one or more network computers perform further actions, comprising:

annotating one or more profiles associated with the one or more anomalies, wherein the annotation of the one or more profiles is employed to provide one or more of classification the one or more anomalies or resolution of one or more subsequent anomalies.

12. The system of claim 8 , wherein the one or more processors of the one or more network computers perform further actions, comprising:

employing the one or more anomalies and the one or more portions of the monitored network traffic to further determine the communication channel.

13. The system of claim 8 , wherein the one or more processors of the one or more network computers perform further actions, comprising:

employing the communication channel to:

provide the one or more investigative agents to the one or more users; or

provide the investigative information from the one or more investigative agents.

14. The system of claim 8 , wherein the one or more processors of the one or more network computers perform further actions, comprising:

determining one or more remediation actions based on the investigative information, wherein the one or more remediation actions includes one or more of quarantining an endpoint, blocking network traffic, or locking a user account.

15. A network computer for monitoring network traffic in one or more networks, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing information that is associated with one or more anomalies that are associated with one or more users over one or more portions of the monitored network traffic;

annotating the provided information to include one or more attributes based on one or more metrics that are associated with the one or more portions of the monitored network traffic;

employing the annotated anomaly information to determine a communication channel that is separate from the monitored network traffic and associated with the one or more users;

determining one or more investigative agents based on the annotated anomaly information; and

providing a report based on an evaluation of investigative information provided by the one or more investigative agents.

16. The network computer of claim 15 , wherein the one or more processors perform further actions, comprising:

classifying the one or more anomalies based on one or more profiles, wherein the one or more profiles are associated with one or more risk levels.

17. The network computer of claim 15 , wherein the one or more processors perform further actions, comprising:

employing the investigative information and one or more profiles to classify the one or more anomalies, wherein the evaluation is further based on the classification of the one or more anomalies.

18. The network computer of claim 15 , wherein the one or more processors perform further actions, comprising:

annotating one or more profiles associated with the one or more anomalies, wherein the annotation of the one or more profiles is employed to provide one or more of classification the one or more anomalies or resolution of one or more subsequent anomalies.

19. The network computer of claim 15 , wherein the one or more processors perform further actions, comprising:

employing the one or more anomalies and the one or more portions of the monitored network traffic to further determine the communication channel.

20. The network computer of claim 15 , wherein the one or more processors perform further actions, comprising:

employing the communication channel to:

provide the one or more investigative agents to the one or more users; or

provide the investigative information from the one or more investigative agents.

21. The network computer of claim 15 , wherein the one or more processors perform further actions, comprising:

determining one or more remediation actions based on the investigative information, wherein the one or more remediation actions includes one or more of quarantining an endpoint, blocking network traffic, or locking a user account.

22. A processor readable non-transitory storage media that includes instructions for monitoring network traffic over one or more networks using one or more network monitoring computers, wherein execution of the instructions by the one or more network computers perform the method comprising:

providing information that is associated with one or more anomalies that are associated with one or more users over one or more portions of the monitored network traffic;

annotating the provided information to include one or more attributes based on one or more metrics that are associated with the one or more portions of the monitored network traffic;

employing the annotated anomaly information to determine a communication channel that is separate from the monitored network traffic and associated with the one or more users;

determining one or more investigative agents based on the annotated anomaly information; and

providing a report based on an evaluation of investigative information provided by the one or more investigative agents.

23. The processor readable non-transitory storage media of claim 22 , further comprising:

classifying the one or more anomalies based on one or more profiles, wherein the one or more profiles are associated with one or more risk levels.

24. The processor readable non-transitory storage media of claim 22 , further comprising:

employing the investigative information and one or more profiles to classify the one or more anomalies, wherein the evaluation is further based on the classification of the one or more anomalies.

25. The processor readable non-transitory storage media of claim 22 , further comprising;

annotating one or more profiles associated with the one or more anomalies, wherein the annotation of the one or more profiles is employed to provide one or more of classification the one or more anomalies or resolution of one or more subsequent anomalies.

26. The processor readable non-transitory storage media of claim 22 , wherein determining the communication channel further comprises employing the one or more anomalies and the one or more portions of the monitored network traffic.

27. The processor readable non-transitory storage media of claim 22 , further comprises:

employing the communication channel to:

provide the one or more investigative agents to the one or more users; or

provide the investigative information from the one or more investigative agents.

28. The processor readable non-transitory storage media of claim 22 , further comprising:

determining one or more remediation actions based on the investigative information, wherein the one or more remediation actions includes one or more of quarantining an endpoint, blocking network traffic, or locking a user account.

Assignments (6)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0488 →
RELEASE OF SECURITY INTEREST Recorded Jul 22, 2021
From: SILICON VALLEY BANK
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 056967/0530 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK
Reel/Frame 053756/0739 →
SECURITY INTEREST Recorded Sep 11, 2020
From: EXTRAHOP NETWORKS, INC.
To: SILICON VALLEY BANK, AS AGENT
Reel/Frame 053756/0774 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 14, 2019
From: DRIGGS, EDMUND HOPE; ROTHSTEIN, JESSE ABRAHAM
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 049478/0324 →
Continuity (1)
Continuation 16243001 · Jan 8, 2019
Cited By (7)
US 12,225,030 US 12,309,192 US 12,355,816 US 12,483,384 US 12,587,535 US 12,647,441 US 12,652,312