IP Library Granted Patent US 11,153,339
Granted Patent B1
US 11,153,339 · App. 16/665,961 · Granted Oct 19, 2021

Using graph-based models to identify datacenter anomalies

Inventors: Vikram Kapoor (Cupertino, CA); Samuel Joseph Pullara, III (Los Altos, CA); Murat Bog (Fremont, CA); Yijou Chen (Cupertino, CA); Sanjay Kalra (San Jose, CA)
Assignee: Lacework Inc.
H04L63/1425H04L43/045H04L43/06G06F16/2456
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,153,339
App. No.
16/665,961
Granted
Oct 19, 2021
Kind
B1
Abstract

Activities within a network environment are monitored (e.g., using agents). At least a portion of the monitored activities are used to generate a logical graph model. The generated logical graph model is used to determine an anomaly. The detected anomaly is recorded and can be used to generate an alert.

Claims (59)

1. A system, comprising:

a processor configured to:

monitor activities within a network environment;

generate a multidimensional logical graph model comprising a set of nodes and a set of edges using at least a portion of the monitored activities; and

determine, using the generated logical graph model, an anomaly, and in response to detecting the anomaly, record the anomaly;

wherein a first node included in the set of nodes corresponds to an entity of a first type and wherein a second node included in the set of nodes corresponds to an entity of a second type that is different from the first type;

wherein the first node comprises a plurality of individual elements clustered together;

wherein a first edge connects the first node and the second node and wherein the first edge has a first edge type;

wherein a second edge connects the second node and a third node and wherein the second edge has a second edge type that is different from the first edge type; and

wherein the first edge type indicates a first type of behavioral relationship between arbitrary nodes interconnected by the first edge type and wherein the second edge type indicates a different type of behavioral relationship between two arbitrary nodes interconnected by the second edge type; and

a memory coupled to the processor and configured to provide the processor with instructions.

2. The system of claim 1 , wherein the graph comprises process information.

3. The system of claim 1 , wherein the generated logical graph model represents a baseline of behavior of nodes included in the network environment.

4. The system of claim 3 , wherein using the logical graph model to detect the anomaly includes comparing a current graph associated with the network environment against the baseline.

5. The system of claim 1 , wherein the network environment comprises a datacenter.

6. The system of claim 1 , wherein the detected anomaly is associated with identifying a security threat.

7. The system of claim 1 , wherein the logical graph model is generated at least in part by generating a graph of physical connection information.

8. The system of claim 1 , wherein the logical graph model is generated at least in part by performing a clustering operation.

9. The system of claim 8 , wherein clustering operation includes performing a Matching Neighbor clustering.

10. The system of claim 8 , wherein clustering operation includes performing a similarity clustering.

11. The system of claim 1 , wherein the logical graph model is generated at least in part by performing a split on a graph.

12. The system of claim 11 , wherein the split is based at least in part on an application type.

13. The system of claim 1 , wherein the processor is further configured to determine whether a process matches a predetermined application type included in a set of predetermined application types.

14. The system of claim 13 , wherein the processor is further configured to generate an alert in response to determining that the process does not match any members of the set of predetermined application types.

15. The system of claim 1 , wherein detecting the anomaly includes detecting a new node in the logical graph model.

16. The system of claim 1 , wherein detecting the anomaly includes detecting a new edge in the logical graph model.

17. A method, comprising:

monitoring activities within a network environment;

generating a multidimensional logical graph model comprising a set of nodes and a set of edges using at least a portion of the monitored activities; and

determining, using the generated logical graph model to detect an anomaly, and in response to detecting the anomaly, recording the anomaly;

wherein a first node included in the set of nodes corresponds to an entity of a first type and wherein a second node included in the set of nodes corresponds to an entity of a second type that is different from the first type;

wherein the first node comprises a plurality of individual elements clustered together;

wherein a first edge connects the first node and the second node and wherein the first edge has a first edge type;

wherein a second edge connects the second node and a third node and wherein the second edge has a second edge type that is different from the first edge type; and

wherein the first edge type indicates a first type of behavioral relationship between arbitrary nodes interconnected by the first edge type and wherein the second edge type indicates a different type of behavioral relationship between two arbitrary nodes interconnected by the second edge type.

18. The method of claim 17 , wherein the graph comprises process information.

19. The method of claim 17 , wherein the generated logical graph model represents a baseline of behavior of nodes included in the network environment.

20. The method of claim 19 , wherein using the logical graph model to detect the anomaly includes comparing a current graph associated with the network environment against the baseline.

21. The method of claim 17 , wherein the network environment comprises a datacenter.

22. The method of claim 17 , wherein the detected anomaly is associated with identifying a security threat.

23. The method of claim 17 , wherein the logical graph model is generated at least in part by generating a graph of physical connection information.

24. The method of claim 17 , wherein the logical graph model is generated at least in part by performing a clustering operation.

25. The method of claim 24 , wherein clustering operation includes performing a Matching Neighbor clustering.

26. The method of claim 24 , wherein clustering operation includes performing a similarity clustering.

27. The method of claim 17 , wherein the logical graph model is generated at least in part by performing a split on a graph.

28. The method of claim 27 , wherein the split is based at least in part on an application type.

29. The method of claim 17 , wherein the processor is further configured to determine whether a process matches a predetermined application type included in a set of predetermined application types.

30. The method of claim 29 , wherein the processor is further configured to generate an alert in response to determining that the process does not match any members of the set of predetermined application types.

31. The method of claim 17 , wherein detecting the anomaly includes detecting a new node in the logical graph model.

32. The method of claim 17 , wherein detecting the anomaly includes detecting a new edge in the logical graph model.

33. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

monitoring activities within a network environment;

generating a multidimensional logical graph model comprising a set of nodes and a set of edges using at least a portion of the monitored activities; and

determining, using the generated logical graph model to detect an anomaly, and in response to detecting the anomaly, recording the anomaly;

wherein a first node included in the set of nodes corresponds to an entity of a first type and wherein a second node included in the set of nodes corresponds to an entity of a second type that is different from the first type;

wherein the first node comprises a plurality of individual elements clustered together;

wherein a first edge connects the first node and the second node and wherein the first edge has a first edge type;

wherein a second edge connects the second node and a third node and wherein the second edge has a second edge type that is different from the first edge type; and

wherein the first edge type indicates a first type of behavioral relationship between arbitrary nodes interconnected by the first edge type and wherein the second edge type indicates a different type of behavioral relationship between two arbitrary nodes interconnected by the second edge type.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069113/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2021
From: KAPOOR, VIKRAM; PULLARA, SAMUEL JOSEPH, III; BOG, MURAT; CHEN, YIJOU; KALRA, SANJAY
To: LACEWORK INC.
Reel/Frame 057357/0279 →
Continuity (3)
Continuation 16134794 · Sep 18, 2018
Provisional Application 62590986 · Nov 27, 2017
Provisional Application 62650971 · Mar 30, 2018
Cited By (37)
US 12,261,866 US 12,267,345 US 12,284,197 US 12,309,185 US 12,309,236 US 12,323,449 US 12,335,348 US 12,348,545 US 12,355,626 US 12,355,793 US 12,363,148 US 12,418,555 US 12,470,577 US 12,470,578 US 12,489,770 US 12,489,771 US 12,495,052 US 12,506,762 US 12,526,297 US 12,549,577 US 12,556,548 US 12,556,559 US 12,563,071 US 12,592,950 US 12,613,930 US 12,621,324 US 12,621,332 US 12,627,686 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,689,640 US 12,695,768 US 12,706,980 US 12,712,897 US 12,719,896