IP Library Granted Patent US 11,811,788
Granted Patent B2
US 11,811,788 · App. 16/810,988 · Granted Nov 7, 2023

Method of threat detection in a computer network security system

Inventor: Matti Aksela (Helsinki, FI)
Assignee: WITHSECURE CORPORATION
H04L63/1408G06F18/2148G06F18/24323G06N3/08G06N5/048G06N7/01G06N20/00H04L63/0227H04L63/1416H04L63/1425H04L63/1433H04L63/1441H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,811,788
App. No.
16/810,988
Granted
Nov 7, 2023
Kind
B2
Abstract

A method comprising: receiving raw data related to one or more network nodes, wherein dissimilar data types are aligned as input events; filtering one or more of the input events by using an adjustable threshold that is based on a filtering score, wherein the filtering score is an estimate of the likelihood that the input event is followed by a security related detection; processing only input events passed through the filtering by an enrichment process; and analysing the data received from the enrichment process for generating a security related decision.

Claims (46)

1. A method of threat detection, the method comprising:

receiving raw data related to one or more network nodes, wherein dissimilar data types are aligned as input events;

filtering, based on a modifiable filtering model, one or more of the input events by using an adjustable threshold that is based on a filtering score, wherein the filtering score is an estimate of a likelihood that the input event is followed by a security related detection;

processing input events passed through the filtering by an enrichment process;

analysing the data received from the enrichment process for generating a security related decision for positive impact on a state of a protected Information Technology (IT) infrastructures in real time, said analysing the data comprises using at least one of the following processes for generating the security related decision: predetermined rules, heuristics, machine learning models, fuzzy logic based models, statistical inference based model; and said enrichment process comprises extending a structure and context of events with previously collected data based on analysing the data; and

controlling the modifiable filtering model based on analysis of the data based on at least one of said processes for generating the security related decision: predetermined rules, heuristics, machine learning models, fuzzy logic based models, statistical inference based model.

2. The method according to claim 1 , wherein the filtering of the one or more of the input events is further based on one or more of: a self-learning rule set, a decision tree, a deep learning neural network or another machine learning model.

3. The method according to claim 2 , wherein the machine learning model is trained on a set of data received from a plurality of network nodes.

4. The method according to claim 1 , wherein the raw data is received, by a security server backend, from a plurality of network nodes of a computer network.

5. The method according to claim 1 , wherein the raw data is received by a network node of a computer network.

6. The method according to claim 1 , wherein the filtering of the input events is executed by a security server backend or by a network node of a computer network.

7. The method according to claim 1 , further comprising: implementing an off-line process for separate analysis of unfiltered input events for ensuring optimal performance and detection capabilities for the threat detection and updating used machine learning model used to generate the filtering score regularly on a basis of a result of the separate analysis.

8. The method according to claim 1 , further comprising: taking further action to secure the computer network and/or any related network node, wherein the further action comprises any one or more of:

preventing one or more of the network nodes from being switched off;

switching on a firewall at one or more of the network nodes;

slowing down or blocking network connectivity of one or more of the network nodes;

removing or placing into quarantine suspicious files;

collecting logs from network nodes;

executing sets of command on network nodes;

warning a user of one or more of the network nodes that signs of a security breach have been detected; and/or

sending a software update to one or more of the network nodes.

9. An apparatus in a computer network system comprising:

one or more processors and a memory comprising computer readable code which, when run on the one or more processors, causes the apparatus to:

receive raw data related to one or more network nodes, wherein dissimilar data types are aligned as input events;

filter, based on a modifiable filtering model, one or more of the input events by using an adjustable threshold that is based on a filtering score, wherein the filtering score is an estimate of a likelihood that the input event is followed by a security related detection;

process input events passed through the filtering by an enrichment process;

analyse the data received from the enrichment process for generating a security related decision for positive impact on a state of a protected Information Technology (IT) infrastructures in real time, wherein the data is analysed using at least one of the following processes for generating the security related decision: predetermined rules, heuristics, machine learning models, fuzzy logic based models, statistical inference based model; and said enrichment process comprises extending a structure and context of events with previously collected data based on analysing the data; and

control the modifiable filtering model based on analysis of the data based on at least one of said processes for generating the security related decision: predetermined rules, heuristics, machine learning models, fuzzy logic based models, statistical inference based model.

10. The apparatus according to claim 9 , wherein the filtering of the one or more of the input events is further based on one or more of: a self-learning rule set, a decision tree, a deep learning neural network or another machine learning model.

11. The apparatus according to claim 10 , wherein the machine learning model is trained on a set of data received from a plurality of network nodes.

12. The apparatus according to claim 9 , wherein the raw data is received, by a security server backend, from a plurality of network nodes of the computer network.

13. The apparatus according to claim 9 , wherein the raw data is received by a network node of a computer network.

14. The apparatus according to claim 9 , wherein the filtering score is generated by a security server backend.

15. The apparatus according to claim 14 , the processor being further configured to generate one or more filtering rules or models on a basis of the generated filtering score and to deploy the generated one or more filtering rules or models to one or more endpoints of the computer network.

16. The apparatus according to claim 9 , wherein the filtering of the input events is executed by at least one of: a security server backend, a network node, an endpoint of a computer network.

17. The apparatus according to claim 9 , the processor being further configured to: implement an off-line process for separate analysis of unfiltered input events for ensuring optimal performance and detection capabilities for and update used machine learning model used to generate the filtering score regularly on a basis of a result of the separate analysis.

18. The apparatus according to claim 9 , the processor being further configured to: take further action to secure the computer network and/or any related network node, wherein the further action comprises any one or more of:

preventing one or more of the network nodes from being switched off;

switching on a firewall at one or more of the network nodes;

slowing down or blocking network connectivity of one or more of the network nodes;

removing or placing into quarantine suspicious files;

collecting logs from network nodes;

executing sets of command on network nodes;

warning a user of one or more of the network nodes that signs of a security breach have been detected; and/or

sending a software update to one or more of the network nodes.

19. A computer program product comprising a non-transitory computer readable medium storing a computer program comprising computer readable code which, when run on a computer system or server, causes the computer system or server to act as the apparatus according to claim 9 .

Assignments (2)
CHANGE OF NAME Recorded Jun 7, 2022
From: F-SECURE CORPORATION (A/K/A F-SECURE CORPORATION OYJ)
To: WITHSECURE CORPORATION (A/K/A WITHSECURE OYJ)
Reel/Frame 060302/0690 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2020
From: AKSELA, MATTI
To: F-SECURE CORPORATION
Reel/Frame 053078/0739 →
Priority Claims (1)
GB 1903035 · Mar 7, 2019 · national
Continuity (1)
Related Publication 20200287916A1 · Sep 10, 2020