IP Library Granted Patent US 11,165,814
Granted Patent B2
US 11,165,814 · App. 16/525,290 · Granted Nov 2, 2021

Modifying triage information based on network monitoring

Inventors: Po-Shen Lee (Seattle, WA); Songqian Chen (Seattle, WA); Amanda Jewitt (Seattle, WA); Olga Kazakova (Kirkland, WA); Todd Kemmerling (Bainbridge Island, WA); Bhushan Prasad Khanal (Seattle, WA); Katherine Megan Porterfield (Seattle, WA); Jade Alexi Tabony (Seattle, WA); Karan Rajesh Thakker (Seattle, WA); Xue Jun Wu (Seattle, WA)
Assignee: ExtraHop Networks, Inc.
H04L63/1441H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,165,814
App. No.
16/525,290
Filed
Jul 29, 2019
Granted
Nov 2, 2021
Kind
B2
Art Unit
2439
USPC
726/23
Abstract

Embodiments are directed to monitoring network traffic using NMCs that may be arranged to provide scores based on threat assessments associated with anomaly classes such that the anomaly classes may be associated with types of anomalous activity. NMCs may employ the anomaly classes, the scores, characteristics of the anomaly classes, or the like, to determine triage models. The NMCs may modify the scores based on the triage models or archival information associated with the anomaly classes. The NMCs may associate the modified scores with the anomaly classes. In response to detecting anomalous activity, the NMCs may provide other scores based on the anomalous activity and provide a report that includes the other scores to a user.

Claims (129)

1. A method for monitoring network traffic on one or more networks using one or more network monitoring computers, comprising:

providing one or more capture agents that are selectively installed on a portion of a group of entities on the one or more networks, wherein the one or more capture agents collect activity information on network traffic for the portion of the group of entities that is used to infer activity associated with a remainder of the group of entities, wherein at least one capture agent is deactivated based on an amount of activity information that is collected;

providing one or more scores based on one or more threat assessments that are associated with one or more anomaly classes, wherein the one or more anomaly classes are associated with one or more types of anomalous activity determined by an assessment engine;

employing the one or more anomaly classes, the one or more scores, and one or more characteristics of the one or more anomaly classes to determine one or more triage models, and wherein each score for each threat assessment is based on separate triage models for each of a plurality of separately weighted factors that include two or more of a risk of harm by a threat, a sophistication of the threat, or a likelihood of occurrence of the threat, and wherein one or more of the separately weighted factors include a defined range of values;

modifying the one or more scores based on the one or more triage models and archival information associated with the one or more anomaly classes;

associating the one or more modified scores with the one or more anomaly classes;

in response to detecting anomalous activity in one or more monitored networks, providing one or more other scores based on the anomalous activity, wherein a report that includes the one or more other scores is provided to a user, and

employing the one or more other scores to associate the report with one or more of content, a delivery method to the user or a delivery destination for the user.

2. The method of claim 1 , wherein detecting the anomalous activity, further comprises:

generating anomaly information based on one or more of the anomalous activity, a portion of the monitored network traffic associated with the anomalous activity, one or more characteristics of the entities associated with anomalous activity, wherein the one or more characteristics of the entities associated with anomalous activity include one or more of one or more device properties, one or more cluster properties, one or more privilege rights, one or more users, or one or more user roles; and

providing the anomaly information to one or more triage engines that perform further actions, including:

determining one or more other triage models based on the anomaly information;

providing the one or more other scores based on the one or more other triage models and the anomaly information; and

associating the one or more other scores with the anomalous activity.

3. The method of claim 1 , further comprising:

monitoring user activity that is associated with the report and the one or more other scores;

determining one or more user characteristics based on the monitored user activity;

employing one or more of the monitored user activity or the one or more user characteristics to modify the one or more triage models associated with the anomalous activity; and

employing the one or more modified triage models to provide one or more new scores for newly determined anomalous activity that is associated with the one or more modified triage models.

4. The method of claim 1 , wherein providing the one or more other scores, further comprises:

providing meta-data that includes one or more of information associated with the monitored network traffic, information associated with threat characteristics, one or more characteristics of one or more entities associated with the anomalous activity, user information associated with the anomalous activity, one or more triage policies, or one or more triage rules, wherein one or more portions of the meta-data are obtained from one or more separate services; and

modifying the one or more other scores based on the meta-data.

5. The method of claim 1 , further comprises, providing the archival information based on archived data that is associated with one or more previously detected anomalies, wherein the archived data includes one or more of one or more metrics for the monitored network traffic, one or more timestamps, information associated with one or more anomalous devices, a count of devices in one or more monitored networks, a count of active devices associated with one or more protocols, a count of anomalies that previously occurred in the one or more monitored networks, other individual or aggregated information associated with one or more anomalous entities, or one or more characteristics of the monitored networks.

6. The method of claim 1 , further comprising:

evaluating at least one of one or more impacts, one or more harms, or one or more costs associated with the one or more types of anomalous activity based on the archival information; and

generating the one or more triage models based on the evaluation.

7. The method of claim 1 , further comprising:

monitoring other network traffic that occurs subsequent to providing the report;

modifying the one or more triage models that are associated with the anomalous activity based on the monitored other network traffic; and

employing the one or more modified triage models to provide one or more new scores for new anomalous activity that is associated with the one or more modified triage models.

8. A system for monitoring network traffic in one or more networks:

one or more network monitoring computers (NMCs), comprising:

memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing one or more capture agents that are selectively installed on a portion of a group of entities on one or more networks, wherein the one or more capture agents collect activity information on network traffic for the portion of the group of entities that is used to infer activity associated with a remainder of the group of entities, wherein at least one capture agent is deactivated based on an amount of activity information that is collected;

providing one or more scores based on one or more threat assessments that are associated with one or more anomaly classes, wherein the one or more anomaly classes are associated with one or more types of anomalous activity determined by an assessment engine;

employing the one or more anomaly classes, the one or more scores, and one or more characteristics of the one or more anomaly classes to determine one or more triage models, and wherein each score for each threat assessment is based on separate triage models for each of a plurality of separately weighted factors that include two or more of a risk of harm by a threat, a sophistication of the threat, or a likelihood of occurrence of the threat, and wherein one or more of the separately weighted factors include a defined range of values;

modifying the one or more scores based on the one or more triage models and archival information associated with the one or more anomaly classes;

associating the one or more modified scores with the one or more anomaly classes; and

in response to detecting anomalous activity in one or more monitored networks, providing one or more other scores based on the anomalous activity, wherein a report that includes the one or more other scores is provided to a user; and

employing the one or more other scores to associate the report with one or more of content, a delivery method to the user or a delivery destination for the user; and

one or more client computers, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing one or more of the one or more scores.

9. The system of claim 8 , wherein detecting the anomalous activity, further comprises:

generating anomaly information based on one or more of the anomalous activity, a portion of the monitored network traffic associated with the anomalous activity, one or more characteristics of the entities associated with anomalous activity, wherein the one or more characteristics of the entities associated with anomalous activity include one or more of one or more device properties, one or more cluster properties, one or more privilege rights, one or more users, or one or more user roles; and

providing the anomaly information to one or more triage engines that perform further actions, including:

determining one or more other triage models based on the anomaly information;

providing the one or more other scores based on the one or more other triage models and the anomaly information; and

associating the one or more other scores with the anomalous activity.

10. The system of claim 8 , wherein the one or more processors of the one or more NMCs execute instructions that perform actions further comprising:

monitoring user activity that is associated with the report and the one or more other scores;

determining one or more user characteristics based on the monitored user activity;

employing one or more of the monitored user activity or the one or more user characteristics to modify the one or more triage models associated with the anomalous activity; and

employing the one or more modified triage models to provide one or more new scores for newly determined anomalous activity that is associated with the one or more modified triage models.

11. The system of claim 8 , wherein providing the one or more other scores, further comprises:

providing meta-data that includes one or more of information associated with the monitored network traffic, information associated with threat characteristics, one or more characteristics of one or more entities associated with the anomalous activity, user information associated with the anomalous activity, one or more triage policies, or one or more triage rules, wherein one or more portions of the meta-data are obtained from one or more separate services; and

modifying the one or more other scores based on the meta-data.

12. The system of claim 8 , wherein the one or more processors of the one or more NMCs execute instructions that perform actions further comprising, providing the archival information based on archived data that is associated with one or more previously detected anomalies, wherein the archived data includes one or more of one or more metrics for the monitored network traffic, one or more timestamps, information associated with one or more anomalous devices, a count of devices in one or more monitored networks, a count of active devices associated with one or more protocols, or a count of anomalies that previously occurred in the one or more monitored networks, other individual or aggregated information associated with one or more anomalous entities, or one or more characteristics of the monitored networks.

13. The system of claim 8 , wherein the one or more processors of the one or more NMCs execute instructions that perform actions further comprising:

evaluating at least one of one or more impacts, one or more harms, or one or more costs associated with the one or more types of anomalous activity based on the archival information; and

generating the one or more triage models based on the evaluation.

14. The system of claim 8 , wherein the one or more processors of the one or more NMCs execute instructions that perform actions further comprising:

monitoring other network traffic that occurs subsequent to providing the report;

modifying the one or more triage models that are associated with the anomalous activity based on the monitored other network traffic; and

employing the one or more modified triage models to provide one or more new scores for new anomalous activity that is associated with the one or more modified triage models.

15. A network monitoring computer (NMC) for monitoring network traffic on one or more networks, comprising:

memory that stores at least instructions; and

one or more processors that execute instructions that perform actions, including:

providing one or more capture agents that are selectively installed on a portion of a group of entities on the one or more networks, wherein the one or more capture agents collect activity information on network traffic for the portion of the group of entities that is used to infer activity associated with a remainder of the group of entities, wherein at least one capture agent is deactivated based on an amount of activity information that is collected;

providing one or more scores based on one or more threat assessments that are associated with one or more anomaly classes, wherein the one or more anomaly classes are associated with one or more types of anomalous activity determined by an assessment engine;

employing the one or more anomaly classes, the one or more scores, and one or more characteristics of the one or more anomaly classes to determine one or more triage models, and wherein each score for each threat assessment is based on separate triage models for each of a plurality of separately weighted factors that include two or more of a risk of harm by a threat, a sophistication of the threat, or a likelihood of occurrence of the threat, and wherein one or more of the separately weighted factors include a defined range of values;

modifying the one or more scores based on the one or more triage models and archival information associated with the one or more anomaly classes;

associating the one or more modified scores with the one or more anomaly classes;

in response to detecting anomalous activity in one or more monitored networks, providing one or more other scores based on the anomalous activity, wherein a report that includes the one or more other scores is provided to a user; and

employing the one or more other scores to associate the report with one or more of content, a delivery method to the user or a delivery destination for the user.

16. The NMC of claim 15 , wherein detecting the anomalous activity, further comprises:

generating anomaly information based on one or more of the anomalous activity, a portion of the monitored network traffic associated with the anomalous activity, one or more characteristics of the entities associated with anomalous activity, wherein the one or more characteristics of the entities associated with anomalous activity include one or more of one or more device properties, one or more cluster properties, one or more privilege rights, one or more users, or one or more user roles; and

providing the anomaly information to one or more triage engines that perform further actions, including:

determining one or more other triage models based on the anomaly information;

providing the one or more other scores based on the one or more other triage models and the anomaly information; and

associating the one or more other scores with the anomalous activity.

17. The NMC of claim 15 , wherein the one or more processors execute instructions that perform actions, further comprising:

monitoring user activity that is associated with the report and the one or more other scores;

determining one or more user characteristics based on the monitored user activity;

employing one or more of the monitored user activity or the one or more user characteristics to modify the one or more triage models associated with the anomalous activity; and

employing the one or more modified triage models to provide one or more new scores for newly determined anomalous activity that is associated with the one or more modified triage models.

18. The NMC of claim 15 , wherein providing the one or more other scores, further comprises:

providing meta-data that includes one or more of information associated with the monitored network traffic, information associated with threat characteristics, one or more characteristics of one or more entities associated with the anomalous activity, user information associated with the anomalous activity, one or more triage policies, or one or more triage rules, wherein one or more portions of the meta-data are obtained from one or more separate services; and

modifying the one or more other scores based on the meta-data.

19. The NMC of claim 15 , wherein the one or more processors execute instructions that perform actions, further comprising, providing the archival information based on archived data that is associated with one or more previously detected anomalies, wherein the archived data includes one or more of one or more metrics for the monitored network traffic, one or more timestamps, information associated with one or more anomalous devices, a count of devices in one or more monitored networks, a count of active devices associated with one or more protocols, or a count of anomalies that previously occurred in the one or more monitored networks, other individual or aggregated information associated with one or more anomalous entities, or one or more characteristics of the monitored networks.

20. The NMC of claim 15 , wherein the one or more processors execute instructions that perform actions, further comprising:

evaluating at least one of one or more impacts, one or more harms, or one or more costs associated with the one or more types of anomalous activity based on the archival information; and

generating the one or more triage models based on the evaluation.

21. The NMC of claim 15 , wherein the one or more processors execute instructions that perform actions, further comprising:

monitoring other network traffic that occurs subsequent to providing the report;

modifying the one or more triage models that are associated with the anomalous activity based on the monitored other network traffic; and

employing the one or more modified triage models to provide one or more new scores for new anomalous activity that is associated with the one or more modified triage models.

22. A processor readable non-transitory storage media that includes instructions for monitoring network traffic on one or more networks using one or more network computers, wherein execution of the instructions by the one or more network computers performs the method comprising:

providing one or more capture agents that are selectively installed on a portion of a group of entities on one or more networks, wherein the one or more capture agents collect activity information on network traffic for the portion of the group of entities that is used to infer activity associated with a remainder of the group of entities, wherein at least one capture agent is deactivated based on an amount of activity information that is collected;

providing one or more scores based on one or more threat assessments that are associated with one or more anomaly classes, wherein the one or more anomaly classes are associated with one or more types of anomalous activity determined by an assessment engine;

employing the one or more anomaly classes, the one or more scores, and one or more characteristics of the one or more anomaly classes to determine one or more triage models, and wherein each score for each threat assessment is based on separate triage models for each of a plurality of separately weighted factors that include two or more of a risk of harm by a threat, a sophistication of the threat, or a likelihood of occurrence of the threat, and wherein one or more of the separately weighted factors include a defined range of values;

modifying the one or more scores based on the one or more triage models and archival information associated with the one or more anomaly classes;

associating the one or more modified scores with the one or more anomaly classes;

in response to detecting anomalous activity in one or more monitored networks, providing one or more other scores based on the anomalous activity, wherein a report that includes the one or more other scores is provided to a user; and

employing the one or more other scores to associate the report with one or more of content, a delivery method to the user or a delivery destination for the user.

23. The media of claim 22 , wherein detecting the anomalous activity, further comprises:

generating anomaly information based on one or more of the anomalous activity, a portion of the monitored network traffic associated with the anomalous activity, one or more characteristics of the entities associated with anomalous activity, wherein the one or more characteristics of the entities associated with anomalous activity include one or more of one or more device properties, one or more cluster properties, one or more privilege rights, one or more users, or one or more user roles; and

providing the anomaly information to one or more triage engines that perform further actions, including:

determining one or more other triage models based on the anomaly information;

providing the one or more other scores based on the one or more other triage models and the anomaly information; and

associating the one or more other scores with the anomalous activity.

24. The media of claim 22 , further comprising:

monitoring user activity that is associated with the report and the one or more other scores;

determining one or more user characteristics based on the monitored user activity;

employing one or more of the monitored user activity or the one or more user characteristics to modify the one or more triage models associated with the anomalous activity; and

employing the one or more modified triage models to provide one or more new scores for newly determined anomalous activity that is associated with the one or more modified triage models.

25. The media of claim 22 , wherein providing the one or more other scores, further comprises:

providing meta-data that includes one or more of information associated with the monitored network traffic, information associated with threat characteristics, one or more characteristics of one or more entities associated with the anomalous activity, user information associated with the anomalous activity, one or more triage policies, or one or more triage rules, wherein one or more portions of the meta-data are obtained from one or more separate services; and

modifying the one or more other scores based on the meta-data.

26. The media of claim 22 , further comprises, providing the archival information based on archived data that is associated with one or more previously detected anomalies, wherein the archived data includes one or more of one or more metrics for the monitored network traffic, one or more timestamps, information associated with one or more anomalous devices, a count of devices in one or more monitored networks, a count of active devices associated with one or more protocols, or a count of anomalies that previously occurred in the one or more monitored networks, other individual or aggregated information associated with one or more anomalous entities, or one or more characteristics of the monitored networks.

27. The media of claim 22 , further comprising:

evaluating at least one of one or more impacts, one or more harms, or one or more costs associated with the one or more types of anomalous activity based on the archival information; and

generating the one or more triage models based on the evaluation.

28. The media of claim 22 , further comprising:

monitoring other network traffic that occurs subsequent to providing the report;

modifying the one or more triage models that are associated with the anomalous activity based on the monitored other network traffic; and

employing the one or more modified triage models to provide one or more new scores for new anomalous activity that is associated with the one or more modified triage models.

Assignments (2)
SECURITY INTEREST Recorded Jul 27, 2021
From: EXTRAHOP NETWORKS, INC.
To: SIXTH STREET SPECIALTY LENDING, INC., AS THE COLLATERAL AGENT
Reel/Frame 056998/0590 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2019
From: LEE, PO-SHEN; CHEN, SONGQIAN; JEWITT, AMANDA; KAZAKOVA, OLGA; KEMMERLING, TODD; KHANAL, BHUSHAN PRASAD; PORTERFIELD, KATHERINE MEGAN; TABONY, JADE ALEXI; THAKKER, KARAN RAJESH; WU, XUE JUN
To: EXTRAHOP NETWORKS, INC.
Reel/Frame 049893/0482 →
Continuity (1)
Related Publication 20210037043A1 · Feb 4, 2021
Cited By (7)
US 12,225,030 US 12,309,192 US 12,355,816 US 12,483,384 US 12,587,535 US 12,647,441 US 12,652,312