IP Library Granted Patent US 11,588,832
Granted Patent B2
US 11,588,832 · App. 16/943,949 · Granted Feb 21, 2023

Malicious incident visualization

Inventors: Daniel W. Brown (Beverly, MA); Thomas R. Hobson (Boston, MA); Hyacinth D. Diehl (Minneapolis, MN); Alexander J. Graul (London, GB)
Assignee: CrowdStrike, Inc.
H04L63/1416H04L63/1425H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,588,832
App. No.
16/943,949
Granted
Feb 21, 2023
Kind
B2
Abstract

Techniques to provide visualizations of possible malicious incidents associated with an event on a host device may include causing presentation of graphics of a process or thread in a user interface. Information about detected events may be transmitted to a computing device that generates the visualizations for presentation to an analyst to verify the malicious incidents. Based on patterns and information conveyed in the visualizations, the computer device or host device may take action to protect operation of the host device caused by the event.

Claims (73)

1. A method comprising:

receiving event data associated with an event on a first host device;

detecting, based at least in part on the event data, an incident associated with the event;

determining a first value to visually represent the incident in a user interface based at least in part on an incident score representative of a likelihood for the incident to impact operation of the first host device;

determining that the event on the first host device initiates a process or a thread on a second host device;

determining, based at least in part on determining that the event on the first host device initiates the process or the thread on the second host device, a second value to visually represent the process or the thread on the second host device in the user interface;

outputting, based at least in part on the first value and the second value, an image in the user interface that represents the incident on the first host device and the process or the thread on the second host device, the image comprising a connector between the first host device and the second host device to visually represent the incident on the first host device and the process or the thread on the second host device; and

determining, based at least in part on the image, whether or not the incident associated with the event is a malicious incident.

2. The method as recited in claim 1 , further comprising:

generating a first graph based at least in part on the first value;

generating a second graph based at least in part on the second value; and

outputting the connector in the user interface between a portion of the first graph and a portion of the second graph, and

wherein determining whether or not the incident associated with the event is the malicious incident is further based at least in part on outputting the connector in the user interface.

3. The method as recited in claim 2 , wherein:

the first graph is associated with a pre-boot activity on the first host device, and

the second graph is associated with a post-boot activity on the first host device.

4. The method as recited in claim 2 , wherein:

the first graph is associated with user authentication activity on the first host device, and

the second graph is associated with activity on the second host device that is initiated by the user authentication activity on the first host device.

5. The method as recited in claim 2 , wherein outputting the connector in the user interface comprises:

outputting a first end of the connector for presentation at the portion of the first graph corresponding to the incident; and

outputting a second end of the connector for presentation at the portion of the second graph corresponding to an activity on the second host device associated with the event on the first host device.

6. The method as recited in claim 5 , wherein at least one of:

the first end of the connector comprises one or more symbols to communicate an activity type for the incident, a related event, or a level of suspicious activity for the incident, or

the second end of the connector comprises one or more symbols to communicate a level of suspicious activity for the process or the thread on the second host device.

7. The method as recited in claim 1 , wherein determining whether or not the incident associated with the event is malicious comprises at least one of:

receiving input via the user interface verifying that a pattern in the image is suspicious and determining that the incident associated with the event is malicious based at least in part on the input; or

receiving input via the user interface verifying that the pattern in the image is not suspicious and determining that the incident associated with the event is not malicious based at least in part on the input.

8. The method as recited in claim 1 , wherein determining the second value to visually represent the process or the thread on the second host device in the user interface is performed independent of analyzing network activity between the first host device and the second host device.

9. The method as recited in claim 1 , further comprising:

determining a pattern associated with the event, the pattern including a visual representation of the event over a time interval;

determining a time within the time interval at which the incident occurs; and

verifying that the incident score satisfies a confidence threshold, and

wherein determining the first value to represent the incident based at least in part on the incident score comprises modifying the pattern to represent the incident at the time within the time interval at which the incident occurs.

10. The method as recited in claim 1 , wherein determining that the event on the first host device initiates the process or the thread on the second host device is based at least in part on an activity type associated with the incident.

11. The method as recited in claim 10 , wherein the activity type associated with the incident comprises at least one of: user authentication activity, service activity, or scheduled task activity.

12. The method as recited in claim 1 , wherein:

the event comprises a thread or a process;

the incident comprises a portion of the thread or the process; and

the image output in the user interface communicates a level of impact of the portion of the thread or the process associated with the event on operation of the first host device or the second host device.

13. A system comprising:

one or more processors; and

one or more computer-readable media storing instructions that, when executed by the one or more processors, cause the one or more processors to perform operations comprising:

receiving event data associated with an event on a first host device;

detecting, based at least in part on the event data, an incident associated with the event;

determining a first value to visually represent the incident in a user interface based at least in part on an incident score representative of a likelihood for the incident to impact operation of the first host device;

determining that the event on the first host device initiates a process or a thread on a second host device;

determining, based at least in part on determining that the event on the first host device initiates the process or the thread on the second host device, a second value to visually represent, in the user interface, the process or the thread on the second host device associated with the event;

outputting, based at least in part on the first value and the second value, an image in the user interface that represents a connection between the incident on the first host device and the process or the thread on the second host device; and

determining, based at least in part on the image, whether or not the incident associated with the event is a malicious incident.

14. The system as recited in claim 13 , further comprising correlating the event on the first host device with the process or the thread on the second host device based at least in part on determining that the event on the first host device initiates the process or the thread on the second host device.

15. The system as recited in claim 13 , wherein determining whether or not the incident associated with the event is malicious comprises at least one of:

receiving input via the user interface verifying that a pattern in the image is suspicious and determining that the incident associated with the event is malicious based at least in part on the input; or

receiving input via the user interface verifying that the pattern in the image is not suspicious and determining that the incident associated with the event is not malicious based at least in part on the input.

16. The system as recited in claim 13 , the operations further comprising:

generating a first graph based at least in part on the first value;

generating a second graph based at least in part on the second value;

combining the first graph and the second graph as a combined graph; and

outputting the image in the user interface comprises outputting the combined graph.

17. The system as recited in claim 13 , wherein determining the second value to visually represent the process or the thread on the second host device comprises determining that the process or the thread is suspicious based at least in part on the first value.

18. A non-transitory computer-readable storage media storing instructions that, when executed, cause one or more processors to perform operations comprising:

receiving event data associated with an event on a first host device;

detecting, based at least in part on the event data, an incident associated with the event;

determining a first value to visually represent the incident in a user interface based at least in part on an incident score representative of a likelihood for the incident to impact operation of the first host device;

determining that the event on the first host device initiates a process or a thread on a second host device;

determining, based at least in part on determining that the event on the first host device initiates the process or the thread on the second host device, a second value to visually represent the process or the thread on the second host device in the user interface;

outputting, based at least in part on the first value and the second value, an image in the user interface that represents the incident on the first host device and the process or the thread on the second host device, the image comprising a connector between the first host device and the second host device to visually represent the incident on the first host device and the process or the thread on the second host device; and

determining, based at least in part on the image, whether or not the incident associated with the event is malicious.

19. The non-transitory computer-readable storage media of claim 18 , wherein outputting, based at least in part on the first value and the second value, the image in the user interface comprises:

determining an activity connecting a first graph associated with the first value and a second graph associated with the second value;

combining, as a combined graph, the first graph and the second graph; and

outputting the image in the user interface comprises outputting the combined graph to indicate the activity connecting the first graph and the second graph.

20. The non-transitory computer-readable storage media of claim 19 , wherein the first graph or the second graph comprises one or more of: a process tree or one or more symbols to represent activity by a processor of the first host device.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Jan 6, 2026
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.
Reel/Frame 074202/0710 →
PATENT SECURITY AGREEMENT Recorded Jan 5, 2021
From: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 054899/0848 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 13, 2020
From: BROWN, DANIEL W.; DIEHL, HYACINTH D; HOBSON, THOMAS R; GRAUL, ALEXANDER J
To: CROWDSTRIKE, INC.
Reel/Frame 054362/0567 →
Continuity (2)
Provisional Application 62882339 · Aug 2, 2019
Related Publication 20210037027A1 · Feb 4, 2021
Cited By (1)
US 12,712,887