IP Library Granted Patent US 12,212,582
Granted Patent B2
US 12,212,582 · App. 17/130,334 · Granted Jan 28, 2025

Cyber defense system

Inventors: David Atkinson (London, GB); James Mistry (London, GB)
Assignee: Senseon Tech Ltd
H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,212,582
App. No.
17/130,334
Granted
Jan 28, 2025
Kind
B2
Abstract

In one aspect, a computer-implemented method of detecting network security threats comprises the following steps: receiving at an analysis engine events relating to a monitored network; analysing the received events to identify at least one event that meets a case creation condition and, in response, creating a case in an experience database, the case being populated with data of the identified at least one event; assigning a threat score to the created case based on the event data; matching at least one further event to the created case and populating the case with data of the at least one further event, the threat score assigned to that case being updated in response; and in response to the threat score for one of the cases meeting a significance condition, rendering that case accessible via a case interface.

Claims (28)

1. A method of detecting security threats, the method comprising: receiving, at a data processing system, events relating to a monitored network, the events comprising (i) network events generated by monitoring network traffic within the network, and (ii) endpoint events generated using endpoint agents executed on endpoints of the monitored network to monitor local activity at those endpoints, wherein each of the network and endpoint events comprises: (i) event description data, (ii) an associated timestamp, and (iii) one or more related entity identifiers;

processing the network and endpoint events to link each of at least some of the endpoint events to at least one of the network events, based on the timestamps and the entity identifiers in those events; and

analysing the events to detect security threat conditions indicated by the events, wherein at least one security threat condition is detected based on an endpoint event and a network event to which the endpoint event has been linked, wherein the analysis comprises creating, in an experience database, cases in response to the events, wherein at least some of the events are linked together by associating them with a common case.

2. The method according to claim 1 , wherein at least some of the events are linked by joining the events together, in a joining phase performed prior to the analysis.

3. The method according to claim 1 , wherein the case is populated with data of the events associated with it.

4. The method according to claim 1 , wherein each case is assigned a threat score, the security threat conditions being detected based on the threat scores.

5. The method according to claim 1 , comprising standardizing the events according to a predetermined data model.

6. The method according to claim 1 , wherein the one or more related entity identifiers comprise one or more of: a network address, a user identifier, a device identifier, and an identifier of a process.

7. The method according to claim 1 , wherein at least one of the endpoint events is linked to at least one of the network events based on respective network connection identifiers in those events.

8. The method according to claim 7 , wherein the event description data of the at least one endpoint event associates at least one of the following with the network connection identifier: a socket on the endpoint, a host name of the endpoint, a process running on the endpoint, and a user account on the endpoint, which is thereby linked to the at least one network event.

9. The method according to claim 8 , wherein the event description data of the endpoint event is thereby linked to the event description data of the network event, which denotes network activity associated with the identified network connection.

10. The method according to claim 7 , wherein each of those events comprises multiple entity identifiers, which constitute the network connection identifier.

11. The method according to claim 10 , wherein the multiple entity identifiers are in the form of a five-tuple formed of: a source IP address, a source port, a destination IP address, a destination port and a transport protocol.

12. The method according to claim 10 , comprising hashing the multiple entity identifiers in the events to create respective identifier hashes, wherein the events are linked based on the identifier hashes.

13. A data processing system comprising:

least one input configured to receive events relating to a monitored network, the events comprising (i) network events generated by monitoring network traffic within the network, and (ii) endpoint events generated using endpoint agents executed on endpoints of the monitored network to monitor local activity at those endpoints, wherein each of the network and endpoint events comprises: (i) event description data, (ii) an associated timestamp, and (iii) one or more related entity identifiers at least one memory configured to store computer-readable instructions;

at least one hardware processor coupled to the at least one memory and configured to execute the computer-readable instructions, which upon execution cause the at least one hardware processor to:

process the network and endpoint events to link each of at least some of the endpoint events to at least one of the network events, based on the timestamps and the entity identifiers in those events; and

analyse the events to detect security threat conditions indicated by the events, wherein at least one security threat condition is detected based on an endpoint event and a network event to which the endpoint event has been linked, wherein at least one of the endpoint events is linked to at least one of the network events based on respective network connection identifiers in those events, the network connection identifier being a five-tuple formed of: a source IP address, a source port, a destination IP address, a destination port and a transport protocol.

14. The data processing system of claim 13 , wherein the one or more processors are configured to link at least some of the events by joining the events together, in a joining phase performed prior to the analysis.

15. The data processing system of claim 13 , wherein the analysis comprises creating, in an experience database, cases in response to the events, wherein at least some of the events are linked together by associating them with a common case.

16. The data processing system of claim 15 , wherein the one or more processors are configured to populate the case with data of the events associated with it.

17. The data processing system of claim 15 , wherein the one or more processors are configured to assign each case a threat score, the security threat conditions being detected based on the threat scores.

18. The data processing system of claim 13 , wherein the one or more processors are configured to standardize the events according to a predetermined data model.

19. One or more non-transitory computer-readable media comprising instructions that, when executed on one or more processors, cause the one or more processors to:

receive events relating to a monitored network, the events comprising (i) network events generated by monitoring network traffic within the network, and (ii) endpoint events generated using endpoint agents executed on endpoints of the monitored network to monitor local activity at those endpoints, wherein each of the network and endpoint events comprises: (i) event description data, (ii) an associated timestamp, and (iii) one or more related entity identifiers;

process the network and endpoint events to link each of at least some of the endpoint events to at least one of the network events, based on the timestamps and the entity identifiers in those events; and

analyse the events to detect security threat conditions indicated by the events, wherein at least one security threat condition is detected based on an endpoint event and a network event to which the endpoint event has been linked, wherein at least one of the endpoint events is linked to at least one of the network events based on respective network connection identifiers in those events, wherein each of those events comprises multiple entity identifiers, which constitute the network connection identifier, the instructions causing the one or more processors to hash ng the multiple entity identifiers in the events to create respective identifier hashes, wherein the events are linked based on the identifier hashes.

Assignments (3)
SECURITY INTEREST Recorded Dec 24, 2025
From: SENSEON TECH LTD
To: HSBC INNOVATION BANK LIMITED
Reel/Frame 073311/0164 →
SECURITY INTEREST Recorded Nov 14, 2022
From: SENSEON TECH LTD
To: SILICON VALLEY BANK UK LIMITED
Reel/Frame 061934/0626 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2021
From: ATKINSON, DAVID; MISTRY, JAMES
To: SENSEON TECH LTD
Reel/Frame 056628/0898 →
Priority Claims (1)
GB 1810294 · Jun 22, 2018 · national
Continuity (2)
Continuation PCTEP2019066479 · Jun 21, 2019
Related Publication 20210329016A1 · Oct 21, 2021
References Cited (124)
US 8131846B1 · Hernacki et al. · 2012 [cited by applicant]
US 8239668B1 · Chen et al. · 2012 [cited by applicant]
US 9069954B2 · Anurag · 2015 [cited by applicant]
US 9571524B2 · Dotan et al. · 2017 [cited by applicant]
US 9749342B1 · Krage et al. · 2017 [cited by applicant]
US 9767663B2 · Reske · 2017 [cited by applicant]
US 9773112B1 · Rathor et al. · 2017 [cited by applicant]
US 9800605B2 · Baikalov et al. · 2017 [cited by applicant]
US 9998425B2 · Raman et al. · 2018 [cited by applicant]
US 10091235B1 · Kushwaha et al. · 2018 [cited by applicant]
US 10104118B2 · Wang et al. · 2018 [cited by applicant]
US 10109166B1 · Selinger et al. · 2018 [cited by applicant]
US 11228604B2 · Mistry et al. · 2022 [cited by applicant]
US 11265339B1 · Mistry · 2022 [cited by applicant]
US 20030070003A1 · Chong et al. · 2003 [cited by applicant]
US 20050050336A1 · Liang et al. · 2005 [cited by applicant]
US 20080155517A1 · Yan et al. · 2008 [cited by applicant]
US 20110173699A1 · Figlin et al. · 2011 [cited by applicant]
US 20120151588A1 · Wang et al. · 2012 [cited by applicant]
US 20120174228A1 · Giakouminakis et al. · 2012 [cited by applicant]
US 20120192003A1 · Akiyama et al. · 2012 [cited by applicant]
US 20120287793A1 · Monk · 2012 [cited by examiner]
US 20130097660A1 · Pas et al. · 2013 [cited by applicant]
US 20130298192A1 · Kumar et al. · 2013 [cited by applicant]
US 20140165200A1 · Singla · 2014 [cited by applicant]
US 20150135262A1 · Porat et al. · 2015 [cited by applicant]
US 20150205956A1 · Sakurai et al. · 2015 [cited by applicant]
US 20150281287A1 · Gill et al. · 2015 [cited by applicant]
US 20150341376A1 · Nandy et al. · 2015 [cited by applicant]
US 20160006753A1 · McDaid et al. · 2016 [cited by applicant]
US 20160021056A1 · Chesla · 2016 [cited by applicant]
US 20160149887A1 · Katmor et al. · 2016 [cited by applicant]
US 20160232353A1 · Gupta et al. · 2016 [cited by applicant]
US 20160234241A1 · Talamanchi et al. · 2016 [cited by applicant]
US 20160285858A1 · Li et al. · 2016 [cited by applicant]
US 20160308898A1 · Teeple et al. · 2016 [cited by applicant]
US 20160344762A1 · Jou et al. · 2016 [cited by applicant]
US 20160373477A1 · Moyle et al. · 2016 [cited by applicant]
US 20160381049A1 · Akhani et al. · 2016 [cited by applicant]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063917A1 · Chesla · 2017 [cited by applicant]
US 20170093902A1 · Roundy et al. · 2017 [cited by applicant]
US 20170124127A1 · Fitterer · 2017 [cited by examiner]
US 20170214702A1 · Moscovici et al. · 2017 [cited by applicant]
US 20170220801A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170251012A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170359376A1 · Evron et al. · 2017 [cited by applicant]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180041537A1 · Bloxham et al. · 2018 [cited by applicant]
US 20180046928A1 · Jang et al. · 2018 [cited by applicant]
US 20180091559A1 · Luger et al. · 2018 [cited by applicant]
US 20180123864A1 · Tucker et al. · 2018 [cited by applicant]
US 20180183680A1 · Chen et al. · 2018 [cited by applicant]
US 20180183940A1 · Kosseifi et al. · 2018 [cited by applicant]
US 20180212879A1 · Toit et al. · 2018 [cited by applicant]
US 20180255076A1 · Paine · 2018 [cited by applicant]
US 20180316705A1 · Tsironis · 2018 [cited by examiner]
US 20180316713A1 · Tsironis · 2018 [cited by applicant]
US 20180316727A1 · Tsironis · 2018 [cited by applicant]
US 20180332062A1 · Ford · 2018 [cited by applicant]
US 20180375886A1 · Kirti et al. · 2018 [cited by applicant]
US 20190014141A1 · Segal et al. · 2019 [cited by applicant]
US 20190052659A1 · Weingarten et al. · 2019 [cited by applicant]
US 20190089678A1 · Lam et al. · 2019 [cited by applicant]
US 20190173917A1 · Sites · 2019 [cited by applicant]
US 20190220626A1 · LeMasters et al. · 2019 [cited by applicant]
US 20190258800A1 · Ladnai et al. · 2019 [cited by applicant]
US 20190260764A1 · Humphrey et al. · 2019 [cited by applicant]
US 20190260785A1 · Jenkinson et al. · 2019 [cited by applicant]
US 20190266324A1 · Edwards et al. · 2019 [cited by applicant]
US 20190332690A1 · Gutman et al. · 2019 [cited by applicant]
US 20190372934A1 · Yehudai · 2019 [cited by examiner]
US 20200143041A1 · Jung et al. · 2020 [cited by applicant]
US 20200186465A1 · Venkata et al. · 2020 [cited by applicant]
US 20200236120A1 · Monteil et al. · 2020 [cited by applicant]
US 20200244673A1 · Stockdale et al. · 2020 [cited by applicant]
US 20200274870A1 · Zinar et al. · 2020 [cited by applicant]
US 20200285737A1 · Kraus et al. · 2020 [cited by applicant]
US 20200372150A1 · Salem et al. · 2020 [cited by applicant]
US 20200396190A1 · Pickman et al. · 2020 [cited by applicant]
US 20210036002A1 · Lee · 2021 [cited by applicant]
US 20210064762A1 · Salji · 2021 [cited by applicant]
US 20210120027A1 · Dean et al. · 2021 [cited by applicant]
US 20210250365A1 · Atkinson et al. · 2021 [cited by applicant]
US 20210273691A1 · Huang et al. · 2021 [cited by applicant]
US 20210273949A1 · Howlett et al. · 2021 [cited by applicant]
US 20210273950A1 · Lawson · 2021 [cited by applicant]
US 20210273953A1 · Fellows et al. · 2021 [cited by applicant]
US 20210273957A1 · Boyer et al. · 2021 [cited by applicant]
US 20210273958A1 · McLean · 2021 [cited by applicant]
US 20210273959A1 · Salji · 2021 [cited by applicant]
US 20210273960A1 · Humphrey et al. · 2021 [cited by applicant]
US 20210273961A1 · Humphrey et al. · 2021 [cited by applicant]
US 20210273973A1 · Boyer et al. · 2021 [cited by applicant]
US 20210360027A1 · Boyer et al. · 2021 [cited by applicant]
US 20210397710A1 · Cohen et al. · 2021 [cited by applicant]
US 20220019659A1 · Salem et al. · 2022 [cited by applicant]
EP 3772209A1 · 2021 [cited by applicant]
EP 3800863A1 · 2021 [cited by applicant]
KR 20160011261A · 2016 [cited by applicant]
WO 2015191052A1 · 2015 [cited by applicant]
WO 2017160760A1 · 2017 [cited by applicant]
WO 2017160770A1 · 2017 [cited by applicant]
WO 2019038527A1 · 2019 [cited by applicant]
WO 2019243579A1 · 2019 [cited by applicant]
WO 2020021100A1 · 2020 [cited by applicant]
WO 2021171090A1 · 2021 [cited by applicant]
WO 2021171092A2 · 2021 [cited by applicant]
WO 2021171093A1 · 2021 [cited by applicant]
WO 2021171092A3 · 2021 [cited by applicant]
WO 2021236661A1 · 2021 [cited by applicant]
WO 2021236663A1 · 2021 [cited by applicant]
Balasubramaniyan et al., “An architecture for intrusion detection using autonomous agents.” Proceedings 14th annual computer security applications conference (Cat. No. 98EX217). IEEE, 1998. 19 pages. [cited by applicant]
Extended European Search Report in European Patent Application No. 20217813.3 dated Jun. 28, 2021. 11 pages. [cited by applicant]
Snapp et al., “The {DIDS}(Distributed Intrusion Detection System) Prototype.” {USENIX} Summer 1992 Technical Conference ({USENIX} Summer 1992 Technical Conference). 1992. 7 pages. [cited by applicant]
Caithness et al. “Anomaly detection for industrial big data.” arXiv preprint arXiv: 1804.02998 (2018) 9 pages. [cited by applicant]
International Search Report and Written Opinion in International Application No. PCT/EP2020/078643, mailed Feb. 1, 2021, 21 pages. [cited by applicant]
Ranshous et al. “Anomaly detection in dynamic networks: a survey.” Wiley Interdisciplinary Reviews: Computational Statistics 7.3 (2015): 223-247 26 pages. [cited by applicant]
Search Report under Section 17 in United Kingdom Patent Application No. GB2200435.2 dated Feb. 18, 2022, 4 pages. [cited by applicant]
Xie et al. “Fast low-rank matrix approximation with locality sensitive hashing for quick anomaly detection.” IEEE Infocom 2017-IEEE Conference on Computer Communications. IEEE, 2017 10 pages. [cited by applicant]
Hindy et al., “A taxonomy of malicious traffic for intrusion detection systems.” 2018 International Conference On Cyber Situational Awareness, Data Analytics And Assessment (Cyber SA). IEEE, 2018. 4 pages. [cited by applicant]
International Search Report and Written Opinion in International Patent Application No. PCT/EP2019/066479 mailed Oct. 9, 2019. 14 pages. [cited by applicant]
International Search Report and Written Opinion in International Patent Application No. PCT/EP2019/070256 mailed Oct. 24, 2019. 17 pages. [cited by applicant]
Extended European Search Report in European Patent Application No. 23170093.1 dated Jul. 7, 2023, 8 pages. [cited by applicant]