IP Library › Granted Patent US 11,489,851
Granted Patent B2
US 11,489,851 · App. 16/758,363 · Granted Nov 1, 2022

Methods and systems for monitoring cyber-events

Inventor: Tiago Alves De Jesus (Ottawa, CA)
Assignee: Cyber Defence QCD Corporation
H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,489,851
App. No.
16/758,363
Granted
Nov 1, 2022
Kind
B2
Abstract

The present invention provides a method of monitoring a computer network, the method comprising: providing a plurality of sensors, wherein said sensors form a meshed network of sensors which monitor cyber-event(s); detecting, by the plurality of sensors, cyber-event(s); linking cyber-event(s) to subsequent cyber-event(s) into branches to form/extend a cyber-event tree; comparing said cyber-event tree to a baseline cyber-event tree; determining if there is any differences in said cyber-event tree to said baseline cyber-event tree to identify a cyber-event tree or a branch thereof as anomalous and thereby identify potential anomalous event(s) and/or a cyber-attack.

Claims (10)

1. A method of detecting anomalous cyber-events and/or cyber-attack, said method comprising:

providing a plurality of sensors, wherein said sensors form a meshed network of sensors which monitor cyber-event(s), wherein each sensor of said plurality of sensors in said meshed network is monitored by nearest-neighbour sensors and a central authority through its relays such that when a sensor is non-responsive the sensor is automatically restarted or re-installed by the nearest-neighbour sensors or the central authority;

detecting, by the plurality of sensors, cyber-event(s);

linking detected cyber-event(s) to subsequently detected related cyber-event(s) to form/extend a cyber-event tree;

comparing said cyber-event tree to a baseline cyber-event tree of normal cyber-events; and

in response to determination that a difference exists between said cyber-event tree to and said baseline cyber-event tree, to identifying said cyber-event tree or a branch thereof as anomalous and thereby identify potential anomalous event(s) and/or a cyber-attack.

2. The method of claim 1 , wherein said baseline cyber-event tree evolves over time.

3. The method of claim 2 , where evolution of the baseline cyber-event tree is in response to user context specific behaviour changes, legitimate modifications to the operating system and/or applications.

4. The method of claim 1 , wherein said sensors are built from native operating system capabilities and/or external tools.

5. The method of claim 1 , wherein probabilistic modeling of the cyber-event tree or a branch thereof identifies the potential anomalous event(s) and/or a cyber-attack.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 4, 2020
From: DE JESUS, TIAGO ALVES
To: CYBER DEFENCE QCD CORPORATION
Reel/Frame 054271/0646 →
Continuity (2)
Provisional Application 62581805 · Nov 6, 2017
Related Publication 20200344248A1 · Oct 29, 2020