IP Library Granted Patent US 11,063,985
Granted Patent B2
US 11,063,985 · App. 16/718,990 · Granted Jul 13, 2021

Methods and apparatus for graphical user interface environment for creating threat response courses of action for computer networks

Inventors: Christopher Nelson Bailey (Adamstown, MD); Bernd Constant (Arlington, VA); Juan Manuel Vela (Woodbridge, VA)
Assignee: FireEye, Inc.
H04L63/20G06F3/0482G06F3/04842G06F21/554G06F21/57G06T11/206G06F3/0483G06F3/0486H04L63/0236H04L63/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,063,985
App. No.
16/718,990
Granted
Jul 13, 2021
Kind
B2
Abstract

A graphical user interface provides network security administrators a tool to quickly and easily create one or more courses of action for automatic response to a network threat. The courses of action are hardware and system agnostic, which allows a common response task to be implemented by an underlying response engine for any or multiple similar-function devices regardless of brand or version. The course of action builder allows the administrator to use a simple, graphic-based, business modeling concept to craft and design security response processes rather than having to hard code response routines specific to each piece of hardware on the network. The graphic interface model allows the user of the threat response software incorporating the course of action builder to easily understand the overall flow and paths the response may take, as well as understand the data requirements and dependencies that will be evaluated.

Claims (62)

1. A method, comprising:

receiving, at a graphical user interface implemented by one or more processors, from a user a selection of a first task stencil from a plurality of task stencils and a second task stencil from the plurality of task stencils, each task stencil from the plurality of task stencils representing a task from a plurality of tasks, the first task stencil graphically representing a first task from the plurality of tasks, the second task stencil graphically representing a second task from the plurality of tasks, the plurality of tasks associated with responses executable by a plurality of network devices to a security event, the plurality of network devices operatively coupled to the one or more processors via a computer network;

receiving, at the graphical user interface, from the user (1) a selection of a first plug-in module from a plurality of plug-in modules, the first plug-in module being associated with the first task, and (2) a selection of a second plug-in module from the plurality of plug-in modules, the second plug-in module being associated with the second task, each plug-in module from the plurality of plug-in modules associated with at least one network device from the plurality of network devices;

associating a first activation command of the first plug-in module with the first task and a second activation command of the second plug-in module with the second task;

generating a workflow including the first activation command associated with a first network device from the plurality of network devices and the second activation command associated with a second network device from the plurality of network devices and in an order relative to the first activation command, input data associated with the second activation command associated with output data from the first activation command; and

sending the first activation command to the first network device for execution in response to the security event and the second activation command to the second network device for execution in response to the security event.

2. A system, comprising:

a memory; and

a processor operatively coupled to the memory, the processor configured to:

receive, at a graphical user interface, from a user a selection of a first task stencil from a plurality of task stencils and a second task stencil from the plurality of task stencils, each task stencil from the plurality of task stencils representing a task from a plurality of tasks, the first task stencil graphically representing a first task from the plurality of tasks, the second task stencil graphically representing a second task from the plurality of tasks, the plurality of tasks associated with responses executable by a plurality of network devices to a security event, the plurality of network devices operatively coupled to the processor via a computer network;

receive, at the graphical user interface, from the user (1) a selection of a first plug-in module from a plurality of plug-in modules, the first plug-in module being associated with the first task, and (2) a selection of a second plug-in module from the plurality of plug-in modules, the second plug-in module being associated with the second task, each plug-in module from the plurality of plug-in modules associated with least one network device from the plurality of network devices;

associate a first activation command of the first plug-in module with the first task and a second activation command of the second plug-in module with the second task;

generate a workflow including the first activation command associated with a first network device from the plurality of network devices and the second activation command associated with a second network device from the plurality of network devices and in an order relative to the first activation command;

send the first activation command to the first network device for execution in response to the security event and the second activation command to the second network device for execution in response to the security event.

3. The method of claim 1 , wherein:

each plug-in module from the plurality of plug-in modules is configured to interact with at least one network device from the plurality of network devices using application program interface (API) protocols associated with that corresponding plug-in module.

4. The method of claim 1 , further comprising:

receiving, via the graphical user interface, from the user a selection of the first network device from a subset of network devices (1) associated with the first plug-in module and (2) of the plurality of network devices.

5. The method of claim 1 , further comprising:

receiving, via the graphical user interface and prior to associating the first activation command with the first task, from the user a selection of the first activation command from a plurality of activation commands associated with the first plug-in module.

6. The method of claim 1 , further comprising:

receiving, via the graphical user interface, from the user a selection of a start node stencil representing an adaptor, the adaptor being a condition, when satisfied, configured to trigger execution of the first activation command to respond to the security event to protect the computer network.

7. The method of claim 1 , further comprising:

presenting the plurality of task stencils at the graphical user interface as representational elements having “drag and drop” features.

8. The method of claim 1 , wherein the graphical user interface references a device table containing information regarding an association of the first network device with the first plug-in module and an association of the second network device with the second plug-in module.

9. The method of claim 1 , wherein the first activation command includes at least one of an instruction to block an Internet Protocol (IP) address, or an instruction to activate a firewall.

10. The method of claim 1 , further comprising:

receiving, via the graphical user interface, from the user a selection of an end node stencil graphically representing an end node of the workflow, the end node representing an end of the workflow.

11. The method of claim 1 , wherein the sending the first activation command and the second activation command triggers execution of the first activation command and the second activation command in response to the security event to protect the computer network.

12. A non-transitory processor-readable medium storing code representing instructions to be executed by a processor, the code comprising code to cause the processor to:

receive, at a graphical user interface, from a user a selection of a first task stencil from a plurality of task stencils and a second task stencil from the plurality of task stencils, the first task stencil graphically representing a first task from the plurality of tasks, the second task stencil graphically representing a second task from the plurality of tasks, the plurality of tasks associated with responses executable by a plurality of network devices to a security event,

receive, at the graphical user interface, from the user (1) a selection of a first plug-in module from a plurality of plug-in modules, the first plug-in module being associated with the first task, and (2) a selection of a second plug-in module from the plurality of plug-in modules, the second plug-in module being associated with the second task, each plug-in module from the plurality of plug-in modules associated with at least one network device from the plurality of network devices;

associate a first activation command of the first plug-in module with the first task and a second activation command of the second plug-in module with the second task;

generate a workflow including the first activation command associated with a first network device from the plurality of network devices and the second activation command associated with a second network device from the plurality of network devices and in an order relative to the first activation command; and

send the first activation command to the first network device and the second activation command to the second network device to trigger execution of the first activation command and the second activation command to block or remediate the security event to protect a computer network.

13. The non-transitory processor-readable medium of claim 12 , wherein:

each plug-in module from the plurality of plug-in modules is configured to interact with at least one network device from the plurality of network devices using application program interface (API) protocols associated with that corresponding plug-in module.

14. The non-transitory processor-readable medium of claim 12 , wherein the code further comprises code to cause the processor to:

receive, via the graphical user interface, from the user a selection of the first network device from a subset of network devices (1) associated with the first plug-in module and (2) of the plurality of network devices.

15. The non-transitory processor-readable medium of claim 12 , wherein the code further comprises code to cause the processor to:

receive, via the graphical user interface and prior to associating the first activation command with the first task, from the user a selection of the first activation command from a plurality of activation commands associated with the first plug-in module.

16. The non-transitory processor-readable medium of claim 12 , wherein the code further comprises code to cause the processor to:

receive, via the graphical user interface, from the user a selection of a start node stencil representing an adaptor, the adaptor being a condition, when satisfied, configured to trigger execution of the first activation command to respond to the security event to protect the computer network.

17. The non-transitory processor-readable medium of claim 12 , wherein the code further comprises code to cause the processor to:

present the plurality of task stencils at the graphical user interface as representational elements having “drag and drop” features.

18. The non-transitory processor-readable medium of claim 12 , wherein the graphical user interface references a device table containing information regarding an association of the first network device with the first plug-in module and an association of the second network device with the second plug-in module.

19. The non-transitory processor-readable medium of claim 12 , wherein the first activation command includes at least one of an instruction to block an Internet Protocol (IP) address, or an instruction to activate a firewall.

20. The non-transitory processor-readable medium of claim 12 , wherein the code further comprises code to cause the processor to:

receive, via the graphical user interface, from the user a selection of an end node stencil graphically representing an end node of the workflow, the end node representing an end of the workflow.

21. The method of claim 1 , wherein:

the first task is associated with the first network device; and

the second task is associated with the second network device.

22. The method of claim 1 , further comprising:

presenting the workflow at the graphical user interface.

23. The method of claim 1 , wherein:

the second activation command is executable by the second network device in the order in parallel with the first activation command executable by the first network device.

24. The method of claim 1 , wherein:

the order in which the second activation command is executable relative to the first activation command is configurable by the one or more processors.

25. The method of claim 1 , wherein:

the first network device is different from the second network device.

26. The method of claim 1 , wherein:

the first network device is the same as the second network device.

Assignments (15)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
MERGER AND CHANGE OF NAME Recorded May 31, 2023
From: FIREEYE SECURITY HOLDINGS US LLC; MUSARUBRA US LLC
To: MUSARUBRA US LLC
Reel/Frame 063814/0320 →
CHANGE OF NAME Recorded Dec 15, 2021
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 058519/0913 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2021
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 058399/0269 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2019
From: BAILEY, CHRISTOPHER NELSON; CONSTANT, BERND; VELA, JUAN MANUEL
To: CSG CYBER SOLUTIONS, INC.
Reel/Frame 051331/0377 →
CHANGE OF NAME Recorded Dec 19, 2019
From: CSG CYBER SOLUTIONS, INC.
To: INVOTAS CYBER SOLUTIONS, INC.
Reel/Frame 051376/0096 →
MERGER AND CHANGE OF NAME Recorded Dec 19, 2019
From: INVOTAS CYBER SOLUTIONS, INC.; FIREEYE, INC.
To: FIREEYE, INC.
Reel/Frame 051331/0428 →