IP Library Granted Patent US 11,582,246
Granted Patent B2
US 11,582,246 · App. 16/944,052 · Granted Feb 14, 2023

Advanced incident scoring

Inventor: Daniel W. Brown (Beverly, MA)
Assignee: Crowd Strike, Inc.
H04L63/1408G06F16/26
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,582,246
App. No.
16/944,052
Granted
Feb 14, 2023
Kind
B2
Abstract

Techniques and systems to provide a more intuitive user overview of events data by mapping unbounded incident scores to a fixed range and aggregating incident scores by different schemes. The system may detect possible malicious incidents associated with events processing on a host device. The events data may be gathered from events detected on the host device. The incident scores for incidents may be determined from the events data. The incident scores may be mapped to bins of a fixed range to highlight the significance of the incident scores. For instance, a first score mapped to a first bin may be insignificant while a second score mapped to a last bin may require urgent review. The incident scores may also be aggregated at different levels (e.g., host device, organization, industry, global, etc.) and at different time intervals to provide insights to the data.

Claims (65)

1. A system comprising:

one or more processors; and

one or more non-transitory computer-readable media comprising programming instructions configured to be executed by the one or more processors to perform operations comprising:

receiving, from one or more host devices associated with an organization, data associated with events detected at the one or more host devices, wherein the events are produced by at least one process or at least one thread;

determining a plurality of the events from the data for a time interval;

identifying at least one malicious event within the plurality of the events based at least in part on the data indicating malicious activity;

determining an incident score for an incident including the at least one malicious event, the incident score being based at least in part on the at least one malicious event;

determining a start time for the incident based at least in part on determining that the incident score meets or exceeds a predetermined threshold score at the start time; and

determining, based at least in part on incident scores, an aggregate score in accordance to an aggregation scheme.

2. The system of claim 1 , wherein the operations further include:

outputting a visualization in a user interface that represents a change in the aggregate score over the time interval.

3. The system of claim 1 , wherein the operations further include:

determining the incident scores associated with incidents based at least in part on base scores and surprisal values associated with the incidents, wherein the surprisal values are based at least in part on respective relative frequencies of occurrence of the incidents for the aggregation scheme.

4. The system of claim 1 , wherein the aggregation scheme includes:

determining the aggregate score based at least in part on determining a predetermined number of top incidents scores from the one or more host devices on an entity network associated with the organization, wherein the organization is associated with an industry;

determining a second aggregate score based at least in part on determining a second predetermined number of top incidents scores from host devices associated with the industry, wherein the host devices include the one or more host devices; and

outputting a visualization in a user interface that represents a first change in the aggregate score over the time interval and a second change in the second aggregate score over the time interval.

5. The system of claim 1 , wherein the aggregation scheme includes:

determining the aggregate score based at least in part on aggregating incidents scores from the one or more host devices on an entity network over the time interval.

6. A method comprising:

receiving events data associated with events detected at one or more host devices associated with an organization;

detecting incidents from the events based at least in part on the events data indicating malicious activity;

determining incident scores associated with the incidents, wherein an incident score of the incident scores is based at least in part on a base score and a surprisal value associated with the events;

determining a start time for an incident of the incidents based at least in part on determining that the incident score meets or exceeds a predetermined threshold score at the start time; and

determining, based at least in part on the incident scores, an aggregate score in accordance to an aggregation scheme.

7. The method of claim 6 , further comprising:

outputting a first visualization in a user interface that represents a first change in the aggregate score for the organization during a time interval; and

outputting a second visualization in the user interface that represents a second change in a second aggregate score for an industry associated with the organization during the time interval.

8. The method of claim 6 , wherein the aggregation scheme is organization based and the aggregate score is determined by aggregating incidents scores from the one or more host devices associated with the organization over a time interval.

9. The method of claim 6 , further comprising:

tagging the incident with a timestamp;

decreasing a weighted contribution of the incident over time based at least in part on applying a decay function with the timestamp; and

determining a change in the aggregate score over time based at least in part on the weighted contribution of the incident decreasing over time.

10. The method of claim 6 , further comprising:

receiving a user input indicating the incident has been resolved, wherein the user input is associated with a user from the organization; and

determining, based at least in part on the incident score, to decrease the aggregate score.

11. The method of claim 6 , further comprising:

receiving a user input indicating the incident was a false positive;

tagging the incident as a false positive; and

storing data associated with the incident to train models to detect malicious activity.

12. The method of claim 6 , wherein the aggregation scheme is industry based and the aggregate score is determined based at least in part on aggregating events from host devices associated with organizations associated with an industry, and wherein the surprisal value associated with the events are determined for the industry.

13. The method of claim 6 , wherein the aggregation scheme is global based and the aggregate score is determined based at least in part on aggregating events from all host devices globally, and wherein the surprisal value associated with the events are determined globally.

14. The method of claim 6 , wherein the aggregation scheme is organization based and the aggregate score is determined based at least in part on a predetermined number of top incident scores from the one or more host devices associated with the organization and further comprising:

determining a likelihood that the organization is under attack based at least in the part on the aggregate score.

15. One or more non-transitory computer-readable media having computer executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving, from a monitored computing device, data associated with events detected at the monitored computing device during a time interval;

determining malicious events from the events;

determining incidents from the malicious events;

determining incident scores associated with the incidents based at least in part on respective relative frequencies of occurrence of the malicious events;

determining a start time for an incident of the incidents based at least in part on determining that an incident score of the incident scores meets or exceeds a predetermined threshold score at the start time;

determining an aggregate score based at least in part on the incident scores; and

generating a time series graph to present the aggregate score.

16. The one or more non-transitory computer-readable media as recited in claim 15 , operations further comprise:

determining an end time for the incident based at least in part on determining that a second incident score of the incident scores is below the predetermined threshold score at the end time.

17. The one or more non-transitory computer-readable media as recited in claim 15 , operations further comprise:

determining a decay function for the incident based at least in part on the time interval; and

decreasing, based at least in part on the decay function, a contribution of the incident score to the aggregate score.

18. The one or more non-transitory computer-readable media as recited in claim 15 , wherein the operations further comprise:

ranking the incidents based on associated incident scores; and

determining a predetermined number of the incidents to present based at least in part on the ranking.

19. The one or more non-transitory computer-readable media as recited in claim 18 , wherein the operations further comprise generating a second time series graph to present the predetermined number of the incidents.

20. The one or more non-transitory computer-readable media as recited in claim 18 , wherein the operations further comprise:

determining an average incident score based at least in part on the predetermined number of the incidents;

determining the aggregate score based at least in part on the average incident score; and

determining a likelihood that the monitored computing device in under attack based at least in part on the aggregate score.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Jan 6, 2026
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.
Reel/Frame 074202/0710 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2021
From: BROWN, DANIEL W.
To: CROWDSTRIKE, INC.
Reel/Frame 055236/0286 →
PATENT SECURITY AGREEMENT Recorded Jan 5, 2021
From: CROWDSTRIKE HOLDINGS, INC.; CROWDSTRIKE, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 054899/0848 →
Continuity (2)
Provisional Application 62882339 · Aug 2, 2019
Related Publication 20210037024A1 · Feb 4, 2021