IP Library Granted Patent US 11,025,664
Granted Patent B2
US 11,025,664 · App. 16/736,120 · Granted Jun 1, 2021

Identifying security actions for responding to security threats based on threat state information

Inventors: Sourabh Satish (Fremont, CA); Oliver Friedrichs (Woodside, CA); Atif Mahadik (Fremont, CA); Govind Salinas (Sunnyvale, CA)
Assignee: SPLUNK INC.
H04L63/1441G06F16/285G06F21/554H04L63/0236H04L63/1416H04L63/1425H04L63/1433H04L63/20H04L47/2425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,025,664
App. No.
16/736,120
Granted
Jun 1, 2021
Kind
B2
Abstract

Systems, methods, and software described herein provide security actions based on the current state of a security threat. In one example, a method of operating an advisement system in a computing environment with a plurality of computing assets includes identifying a security threat within the computing environment. The method further includes, in response to identifying the security threat, obtaining state information for the security threat within the computing environment, and determining a current state for the security threat within the computing environment. The method also provides obtaining enrichment information for the security threat and determining one or more security actions for the security threat based on the enrichment information and the current state for the security threat.

Claims (50)

1. A computer-implemented method performed by an advisement system coupled to a computing environment, the computing environment comprising a plurality of computing assets, the method comprising:

identifying a security threat involving the computing environment;

obtaining state information for the security threat, including monitoring incoming connections to the computing environment from external computing systems;

determining, based on the state information, that the security threat comprises a malicious process in a persist state in which the malicious process is attempting to remain active on a computing asset of the plurality of computing assets;

identifying a security action for responding to the security threat based on determining that the security threat comprises a malicious process in a persist state in which the malicious process is attempting to remain active on the computing asset of the plurality of computing assets;

translating the security action into a process implemented on the computing asset of the plurality of computing assets; and

initiating implementation of the security action at the computing asset of the plurality of computing assets.

2. The method of claim 1 , wherein identifying the security action for responding to the security threat comprises:

identifying a rule set based on enrichment information obtained for the security threat; and

identifying the security action associated with the rule set.

3. The method of claim 1 , further comprising:

identifying a plurality of security actions for responding to the security threat; and

initiating implementation of the plurality of security actions at the plurality of computing assets in the computing environment.

4. The method of claim 1 , further comprising:

in response to identifying the security action for responding to the security threat, providing the security action to an administrator of the computing environment; and

after providing the security action to the administrator, receiving input selecting the security action for implementation in the computing environment.

5. The method of claim 4 , wherein identifying the security action for responding to the security threat comprises ranking the security action relative to one or more other security actions for responding to the security threat.

6. The method of claim 1 , further comprising obtaining enrichment information for the security threat from at least one internal or external database.

7. The method of claim 1 , wherein the state information for the security threat further indicates identifiers of assets targeted by communications of the security threat.

8. The method of claim 1 , wherein the security threat includes at least one of a virus or a malware attack.

9. The method of claim 1 , wherein determining, based on the state information, that the security threat comprises a malicious process in a persist state comprises determining, based on the state information, that the malicious process is attempting to install software or execute another process on the computing asset of the plurality of computing assets.

10. A non-transitory computer-readable storage medium storing instructions which, when executed by one or more processors, cause performance of operations comprising:

identifying a security threat involving the computing environment;

obtaining state information for the security threat, including monitoring incoming connections to the computing environment from external computing systems;

determining, based on the state information, that the security threat comprises a malicious process in a persist state in which the malicious process is attempting to remain active on a computing asset of the plurality of computing assets;

identifying a security action for responding to the security threat based on determining that the security threat comprises a malicious process in a persist state in which the malicious process is attempting to remain active on the computing asset of the plurality of computing assets;

translating the security action into a process implemented on the computing asset of the plurality of computing assets; and

initiating implementation of the security action at the computing asset of the plurality of computing assets.

11. The non-transitory computer-readable storage medium of claim 10 , wherein identifying the security action for responding to the security threat comprises:

identifying a rule set based on enrichment information obtained for the security threat; and

identifying the security action associated with the rule set.

12. The non-transitory computer-readable storage medium of claim 10 , wherein the instructions, when executed by the one or more processors, cause performance of further operations comprising obtaining enrichment information for the security threat from at least one internal or external database.

13. The non-transitory computer-readable storage medium of claim 10 , wherein the security threat includes at least one of a virus or a malware attack.

14. The non-transitory computer-readable storage medium of claim 10 , wherein identifying the security action for responding to the security threat comprises ranking the security action relative to one or more other security actions for responding to the security threat.

15. The non-transitory computer-readable storage medium of claim 10 , wherein determining, based on the state information, that the security threat comprises a malicious process in a persist state comprises determining, based on the state information, that the malicious process is attempting to install software or execute another process on the computing asset of the plurality of computing assets.

16. An apparatus, comprising:

one or more processors;

a non-transitory computer-readable storage medium storing instructions which, when executed by the one or more processors, cause the apparatus to:

identify a security threat involving a computing environment;

obtain state information for the security threat, including monitoring incoming connections to the computing environment from external computing systems;

determine, based on the state information, that the security threat comprises a malicious process in a persist state in which the malicious process is attempting to remain active on a computing asset of the plurality of computing assets;

identify a security action for responding to the security threat based on determining that the security threat comprises a malicious process in a persist state in which the malicious process is attempting to remain active on a computing asset of the plurality of computing assets;

translate the security action into a process implemented on the computing asset of the plurality of computing assets; and

initiate implementation of the security action at the computing asset of the plurality of computing assets.

17. The apparatus of claim 16 , wherein identifying the security action for responding to the security threat comprises:

identifying a rule set based on enrichment information obtained for the security threat; and

identifying the security action associated with the rule set.

18. The apparatus of claim 16 , wherein the instructions, when executed by the one or more processors, cause performance of further operations comprising obtaining enrichment information for the security threat from at least one internal or external database.

19. The apparatus of claim 16 , wherein the security threat includes at least one of a virus or a malware attack.

20. The apparatus of claim 16 , wherein identifying the security action for responding to the security threat comprises ranking the security action relative to one or more other security actions for responding to the security threat.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2021
From: SATISH, SOURABH; FRIEDRICHS, OLIVER; MAHADIK, ATIF; SALINAS, GOVIND
To: PHANTOM CYBER CORPORATION
Reel/Frame 055233/0489 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2021
From: PHANTOM CYBER CORPORATION
To: SPLUNK INC.
Reel/Frame 055233/0515 →
Continuity (7)
Continuation 16107979 · Aug 21, 2018
Continuation 15886183 · Feb 1, 2018
Continuation 14824262 · Aug 12, 2015
Provisional Application 62106830 · Jan 23, 2015
Provisional Application 62106837 · Jan 23, 2015
Provisional Application 62087025 · Dec 3, 2014
Related Publication 20200287930A1 · Sep 10, 2020