IP Library Granted Patent US 12,395,501
Granted Patent B2
US 12,395,501 · App. 17/470,818 · Granted Aug 19, 2025

Security event connectivity generated by linking enitities and actions from process tracking

Inventors: Marc Willebeek-LeMair (Austin, TX); Brian Smith (Ft. Worth, TX); Ian Spencer Nelson (Mead, CO); David Tyree (Evergreen, CO); Seth Goldhammer (Boulder, CO)
Assignee: Spyderbat, Inc.
H04L63/1416H04L63/10H04L63/1425H04L2463/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,395,501
App. No.
17/470,818
Filed
Sep 9, 2021
Granted
Aug 19, 2025
Kind
B2
Art Unit
2498
USPC
726/23
Abstract

A system and method automatically links security events associated with a computer network and system calls of plural networked computers interfaced with the computer network. System call information of the system calls of the plural networked computers are communicated to a network location to associate security events with system calls across the networked computers and provide a causal graph that reconstructs a sequence of events with precise attribution and timing to comprehend entities and actions associated with the security event.

Claims (44)

1. A method for automatically linking security events associated with a computer network having plural networked computers including server computers and client computers, the method comprising:

monitoring system calls at each of the plural networked computers;

aggregating system call information of the monitoring with an agent at each of the plural networked computers, the system call information including at least start time, stop time, parent process and spawn events;

monitoring the network for security events;

identifying a security event;

communicating the system call information from each agent through the network to a network location;

comparing the system call information of the plural networked computers at the network location to identify causal relationships of the security event with the system call information, the comparing including at least comparing start time, stop time, parent process and spawn events of first and second of the plural networked computers to monitor process life cycles that include initiation and termination of network sockets, the network sockets having address buffers tracked by a hash, the network sockets applied to mirror structures from an operating system of each of the plural networked computers and temporally track network interfaces between the server computers and the client computers;

presenting the causal relationships as a causal graph that interrelates the security event and the system call information with the server computers and the client computers; and

blocking at least one of the plural networked computers associated with a causal relationship from a predetermined network access.

2. The method of claim 1 further comprising:

tracking temporal references of the plural security events and the system call information; and

determining the causal relationships of the security events and the system call information by the temporal references.

3. The method of claim 2 wherein at least one of the plural networked computers comprises networked storage and the causal relationship includes a system call to access information in the networked storage.

4. The method of claim 2 wherein a system call comprises a process initiation at the first of the plural networked computers associated with a system call at the second of the plural networked computers.

5. The method of claim 2 wherein the security events comprise one or more of intrusion detection system (IDS) alerts, endpoint detection and response (EDR) alerts, firewall alerts and anomaly detection alerts.

6. The method of claim 2 wherein the comparing system call information further comprises comparing one or more of Internet Protocol (IP) addresses, connection 5-tuples, timestamps, users, file names, and file checksums.

7. The method of claim 2 wherein at least some of the plural networked computers comprise virtual machines and at least some of the plural networked computers comprises physical machines.

8. The method of claim 2 further comprising:

rating a severity of each of the plural causal relationships; and

presenting the severity as plural severity levels, each severity level associated with a color of the causal graph.

9. The method of claim 2 wherein a system call comprises initiation of a network socket.

10. A system for automatically linking security events associated with a computer network having plural networked computers including server computers and client computers, the system comprising:

a first non-transitory memory included in each of the plural networked computers storing first instructions that when executed on a processor of the plural networked computers cause:

monitoring of system calls at the each of the plural networked computers;

aggregating system call information of the monitoring with an agent at each of the plural networked computers, the system call information including at least start time, stop time, parent process and spawn events; and

communicating the system call information from each agent through the network to a network location;

a second non-transitory memory included in the network location and storing second instructions that when executed on a processor of the network location cause:

monitoring the network for a security event;

detecting the security event;

comparing the system call information of the plural networked computers at the network location to identify causal relationships of the security event with the system call information, the comparing including at least comparing start time, stop time, parent process and spawn events of first and second of the plural networked computers to monitor process life cycles that include initiation and termination of network sockets, the network sockets having address buffers tracked by a hash, the network sockets applied to mirror structures from an operating system of each of the plural networked computers and temporally track network interfaces between the server computers and the client computers;

presenting the causal relationships as a causal graph that interrelates the security event and the system call information with the server computers and the client computers; and

blocking at least one of the plural networked computers associated with a causal relationship from a predetermined network access.

11. The system of claim 10 wherein the second instructions further cause:

tracking temporal references of the plural security events and the system call information; and

determining the causal relationships of the security events and the system call information by the temporal references.

12. The system of claim 11 wherein at least one of the plural networked computers comprises networked storage and the causal relationship includes a system call to access information in the networked storage.

13. The system of claim 11 wherein a system call comprises a process initiation at the first of the plural networked computers associated with a system call at the second of the plural networked computers.

14. The system of claim 11 wherein the security events comprise one or more of intrusion detection system (IDS) alerts, endpoint detection and response (EDR) alerts, firewall alerts and anomaly detection alerts.

15. The system of claim 11 wherein the comparing system call information further comprises comparing one or more of Internet Protocol (IP) addresses, connection 5-tuples, timestamps, users, file names, and file checksums.

16. The system of claim 11 wherein at least some of the plural networked computers comprise virtual machines and at least some of the plural networked computers comprises physical machines.

17. The system of claim 11 further comprising:

rating a severity of each of the plural causal relationships; and

presenting the severity as plural severity levels, each severity level associated with a color of the causal graph.

18. The system of claim 11 wherein a system call comprises initiation of a network socket.

Assignments (3)
SECURITY INTEREST Recorded Apr 30, 2025
From: SPYDERBAT, INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 070989/0116 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2021
From: NELSON, IAN SPENCER; TYREE, DAVID; GOLDHAMMER, SETH
To: SPYDERBAT, INC.
Reel/Frame 057988/0565 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 9, 2021
From: WILLEBEEK-LEMAIR, MARC; SMITH, BRIAN
To: SPYDERBAT, INC.
Reel/Frame 057432/0317 →
Continuity (2)
Provisional Application 62706763 · Sep 9, 2020
Related Publication 20220078199A1 · Mar 10, 2022
References Cited (21)
US 8973141B2 · Rowland et al. · 2015 [cited by applicant]
US 9071637B2 · Smith et al. · 2015 [cited by applicant]
US 10630703B1 · Ghosh · 2020 [cited by examiner]
US 20070107052A1 · Cangini · 2007 [cited by examiner]
US 20140157407A1 · Krishnan · 2014 [cited by examiner]
US 20150074808A1 · Quinn · 2015 [cited by examiner]
US 20150264077A1 · Berger · 2015 [cited by examiner]
US 20160191465A1 · Thomas · 2016 [cited by examiner]
US 20160373476A1 · Dell'Anno · 2016 [cited by examiner]
US 20170032120A1 · Tolpin · 2017 [cited by examiner]
US 20180351979A1 · Mandrychenko · 2018 [cited by examiner]
US 20200059481A1 · Sekar · 2020 [cited by examiner]
US 20200120118A1 · Shu · 2020 [cited by examiner]
US 20200201989A1 · Shu · 2020 [cited by examiner]
US 20210105613A1 · San Miguel · 2021 [cited by examiner]
US 20210409981A1 · Yan · 2021 [cited by examiner]
CN 1488097A · 2004 [cited by examiner]
C. Xosanavongsa, E. Totel and O. Bettan, “Discovering Correlations: A Formal Definition of Causal Dependency Among Heterogeneous Events,” 2019 IEEE European Symposium on Security and Privacy (EuroS&P), Stockholm, Sweden… [cited by examiner]
Infoq, “A Gentle Introduction to eBPF,” May 3, 2021, downloaded from https://www.infoq.com/articles/gentle-linux-ebpf-introduction/ on Feb. 22, 2022, 9 pages. [cited by applicant]
New Relic, “What is eBPF and Why Does it Matter for Observability?,” Apr. 23, 2021, downloaded from https://hewrelic.com/blog/best-practices/what-is-ebpf on Feb. 22, 2022, 8 pages. [cited by applicant]
Lwn, “A Thorough Introduction to eBPF,” downloaded from https://lwn.net/Articles/740157/ on Feb. 22, 2022, 6 pages. [cited by applicant]