IP Library › Granted Patent US 12,231,447
Granted Patent B2
US 12,231,447 · App. 17/496,519 · Granted Feb 18, 2025

Graph analytics and visualization for cyber situational understanding

Inventors: Steven E. Noel (Woodbridge, VA); Man M. Sapra (Aldie, VA); Stephen F. Purdy (Springfield, VA); Jeremy T. Martin (Bel Air, MD); Mandira D. Hegde (Rosedale, MD); Brianna L. Chen (Arlington, VA)
Assignee: THE MITRE CORPORATION
H04L63/1425G06N5/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,447
App. No.
17/496,519
Filed
Oct 7, 2021
Granted
Feb 18, 2025
Kind
B2
Art Unit
2433
USPC
726/23
Abstract

Disclosed herein are system, method, and computer program product embodiments for creating cyber situational understanding in an operational environment. An embodiment operates by normalizing streaming cyber information for a plurality of cyberspace entities and generating cyber-graphs based on relationships between two or more of the plurality of cyberspace entities. A cyber-threat inquiry of the cyber-graphs returns potential cyber-threats that are subsequently visualized as an overlay on a corresponding operational environment.

Claims (86)

1. A computer implemented method comprising:

normalizing, by at least one processor, cyber information received for a plurality of cyberspace entities;

generating, by the at least one processor, cyber-graphs based on relationships between two or more of the plurality of cyberspace entities;

receiving, by the at least one processor, a cyber-threat inquiry of the cyber-graphs;

selecting, based on the cyber-threat inquiry, one or more cyber-graphs that represent impacts on a plurality of functions critical to organization mission operations associated with a plurality of selected IP addresses suspected to be compromised by a cyber-threat actor;

generating, by the at least one processor, a visualization of a result of the cyber-threat inquiry within a corresponding operational environment, wherein the visualization comprises one or more graphical layers rendered over imagery of a corresponding geographical environment; and

wherein at least one of the normalizing, generating, and receiving are performed by one or more computers.

2. The method of claim 1 , further comprising:

aggregating the cyber-graphs into an active knowledge database.

3. The method of claim 2 , the generating the cyber-graphs further comprising:

selecting the cyber-graphs related to the cyber-threat inquiry from the active knowledge database.

4. The method of claim 1 , further comprising:

generating the cyber-threat inquiry by converting a natural language inquiry to a formal query language.

5. The method of claim 1 , further comprising:

receiving location information associated with the plurality of cyberspace entities.

6. The method of claim 5 , further comprising:

filtering the location information associated with the plurality of cyberspace entities to match a location of the corresponding operational environment.

7. The method of claim 1 , the normalizing further comprising:

capturing the cyber information from streaming data.

8. The method of claim 1 , further comprising:

configuring the one or more cyber-graphs as nodes represented by the plurality of cyberspace entities and edges represented by relationships between the plurality of cyberspace entities.

9. The method of claim 8 , further comprising:

configuring the nodes to represent functions critical to the organization mission operations and further linking to nodes configured to represent network services used by the functions.

10. The method of claim 8 , further comprising:

configuring the nodes to represent network services and further linking to nodes configured to represent virtual machines that are depended on by the network services.

11. The method of claim 8 , further comprising:

configuring the nodes to represent network services and further linking to nodes configured to represent deployment platforms that are depended on by those network services.

12. The method of claim 8 , further comprising:

configuring the nodes to represent organizational units and further linking to nodes configured to represent subordinate organizational units.

13. The method of claim 8 , further comprising:

configuring the nodes to represent organizational units and further linking to nodes configured to represent deployment platforms that are contained by the organizational units.

14. The method of claim 8 , further comprising:

configuring the nodes to represent deployment platforms and further linking to nodes configured to represent virtual machines that are managed by the deployment platforms.

15. The method of claim 8 , further comprising:

configuring the nodes to represent virtual machines and further linking to nodes configured to represent unmanaged IP addresses assigned to the virtual machines.

16. The method of claim 8 , further comprising:

configuring the nodes to represent virtual machines and further linking to nodes configured to represent managed IP addresses assigned to the virtual machines.

17. The method of claim 8 , further comprising:

configuring the nodes to represent deployment platforms and further linking to nodes configured to represent unmanaged IP addresses assigned to the deployment platforms.

18. The method of claim 8 , further comprising:

configuring the nodes to represent deployment platforms and further linking to nodes configured to represent managed IP addresses assigned to the deployment platforms.

19. The method of claim 8 , further comprising:

configuring the nodes to represent unmanaged IP addresses and further linking to nodes configured to represent unmanaged IP addresses that receive network flows from the unmanaged IP addresses.

20. The method of claim 8 , further comprising:

configuring the nodes to represent unmanaged IP addresses and further linking to nodes configured to represent managed IP addresses that receive network flows from the unmanaged IP addresses.

21. The method of claim 8 , further comprising:

configuring the nodes to represent managed IP addresses and further linking to nodes configured to represent unmanaged IP addresses that receive network flows from the managed IP addresses.

22. The method of claim 8 , further comprising:

configuring the nodes to represent managed IP addresses and further linking to nodes configured to represent managed IP addresses that receive network flows from the managed IP addresses.

23. The method of claim 8 , further comprising:

configuring the nodes to represent unmanaged IP addresses and further linking to nodes configured to represent cyberattack alerts that are associated with the unmanaged IP addresses.

24. The method of claim 8 , further comprising:

configuring the nodes to represent managed IP addresses and further linking to nodes configured to represent cyberattack alerts that are associated with the managed IP addresses.

25. The method of claim 1 , further comprising:

selecting the one or more cyber-graphs that represent traffic communication for a plurality of the selected IP addresses.

26. The method of claim 1 , further comprising:

selecting the one or more cyber-graphs that represent traffic communication for a plurality of the selected IP addresses suspected to be compromised by the cyber-threat actor.

27. The method of claim 1 , further comprising:

selecting the one or more cyber-graphs that represent the impacts on a plurality of organizational units associated with a plurality of the selected IP addresses suspected to be compromised by the cyber-threat actor.

28. The method of claim 1 , wherein the cyber information includes any of: network infrastructure, security posture, cyber threats, or operational dependencies.

29. The method of claim 1 , wherein the plurality of cyberspace entities are represented as Internet Protocol (IP) addresses for virtual machines.

30. The method of claim 1 , wherein the imagery of the corresponding geographical environment comprises a terrain map selected from satellite imagery.

31. A system, comprising:

a memory; and

at least one processor coupled to the memory and configured to:

normalize cyber information available for a plurality of cyberspace entities;

generate cyber-graphs based on relationships between two or more of the plurality of cyberspace entities;

receive a location-based cyber-threat inquiry of the cyber-graphs;

select, based on the location-based cyber-threat inquiry, one or more cyber-graphs that represent impacts on a plurality of functions critical to organization mission operations associated with a plurality of selected IP addresses suspected to be compromised by a cyber-threat actor;

generate a visualization of a result of the location-based cyber-threat inquiry; and

wherein the visualization comprises one or more graphical layers rendered over imagery of a corresponding geographical environment.

32. The system of claim 31 , the at least one processor further configured to:

aggregate the cyber-graphs into an active knowledge database.

33. The system of claim 32 , the at least one processor further configured to:

select the one or more cyber-graphs related to the location-based cyber-threat inquiry from the active knowledge database.

34. The system of claim 31 , wherein the cyber information includes any of network infrastructure, security posture, cyber threats, or mission dependencies.

35. The system of claim 31 , wherein the plurality of cyberspace entities are represented as Internet Protocol (IP) addresses for virtual machines.

36. The system of claim 31 , wherein the cyber-graphs are configured as nodes represented by the plurality of cyberspace entities and edges represented by the relationships.

37. A non-transitory computer-readable device having instructions stored thereon that, when executed by at least one computing device, cause the at least one computing device to perform operations comprising:

receiving cyber information for a plurality of cyberspace assets;

generating cyber-graphs based on relationships between the plurality of cyberspace assets;

receiving a cyber-threat inquiry of the cyber-graphs;

selecting, based on the cyber-threat inquiry, one or more cyber-graphs that represent impacts on a plurality of functions critical to organization mission operations associated with a plurality of selected IP addresses suspected to be compromised by a cyber-threat actor;

generating a visualization of a result of the cyber-threat inquiry, wherein the visualization comprises one or more graphical layers rendered over imagery of a corresponding geographical environment; and

wherein the one or more graphical layers include a graph of the plurality of cyberspace assets and the relationships between the plurality of cyberspace assets.

38. The system of claim 31 , wherein the imagery of the corresponding geographical environment comprises a terrain map selected from satellite imagery.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2021
From: NOEL, STEVEN E.; SAPRA, MAN M.; PURDY, STEPHEN F.; MARTIN, JEREMY T.; HEGDE, MANDIRA D.; CHEN, BRIANNA L.
To: THE MITRE CORPORATION
Reel/Frame 057741/0456 →
Continuity (1)
Related Publication 20230111177A1 · Apr 13, 2023
References Cited (46)
US 7530105B2 · Gilbert et al. · 2009 [cited by applicant]
US 7624448B2 · Coffman · 2009 [cited by applicant]
US 8468244B2 · Redlich et al. · 2013 [cited by applicant]
US 10313382B2 · Noel et al. · 2019 [cited by applicant]
US 10521747B2 · Warner et al. · 2019 [cited by applicant]
US 10609059B2 · Apostolopoulos · 2020 [cited by applicant]
US 10630704B1 · Ghosh et al. · 2020 [cited by applicant]
US 10630716B1 · Ghosh et al. · 2020 [cited by applicant]
US 10771492B2 · Hudis et al. · 2020 [cited by applicant]
US 10887337B1 · Kim et al. · 2021 [cited by applicant]
US 20170280107A1 · Wood · 2017 [cited by examiner]
US 20180159876A1 · Park · 2018 [cited by examiner]
US 20210019674A1 · Crabtree · 2021 [cited by examiner]
U.S. Army Training and Doctrine Command (TRADOC), “The U.S. Army Operating Concept: Win in a Complex World,” (2020-2040). Pamphlet 525-3-1. TRADOC; 2014; Retrieved Oct. 7, 2021; 56 pages. [cited by applicant]
Eimers J., “Prototype Cyber Software Delivers CEMA Dashboard to Tactical Commanders,” [Online].; 2020 [cited Nov. 30, 2020. Available from: https://www.army.mil/article/238095/prototype_cyber_software_delivers_cema_dash… [cited by applicant]
Pomerleau M., “Army Gets Prototype for Cyber Visualization Tool,” [Online].; 2020 [cited Nov. 30, 2020. Available from: https://www.c4isrnet.com/cyber/2020/08/14/army-gets-prototype-for-cyber-visualization-tool/; Retrie… [cited by applicant]
U.S. Army Acquisition Support Center (USAASC), “Command Post Computing Environment (CPCE),” [Online].; 2020 [cited Dec. 1, 2020. Available from: https://asc.army.mil/ web/portfolio-item/command-post-computing-environmen… [cited by applicant]
Noel S, Harley E, Tam KH, Limiero M, Share M., “CyGraph: Graph-Based Analytics and Visualization for Cybersecurity,” In Gudivada V, Raghavan V, Govindaraju V, Rao CR, editors. Cognitive Computing: Theory and Application… [cited by applicant]
Noel S, Harley E, Tam KH, Gyor G., “Big-Data Architecture for Cyber Attack Graphs: Representing Security Relationships in NoSQL Graph Databases,” In IEEE Symposium on Technologies for Homeland Security; 2015; Boston; Re… [cited by applicant]
“The MITRE Corporation. Caldera™,” [Online].; 2020 [cited Dec. 1, 2020. Available from: https://github.com/mitre/caldera; Retrieved Oct. 7, 2021; 4 pages. [cited by applicant]
Internet Engineering Task Force (IETF), “The LDAP Data Interchange Format (LDIF)—Technical Specification,” [Online].; 2000 [cited Dec. 2, 2020. Available from: https://tools.ietf.org/html/rfc2849; Retrieved Oct. 7, 2021… [cited by applicant]
“Apache Kafka®: A Distributed Streaming Platform,” [Online].; 2017 [cited Dec. 2, 2020. Available from: https://kafka.apache.org; Retrieved Oct. 7, 2021; 4 pages. [cited by applicant]
“Docker, Inc. Docker: Empowering App Development for Developers,” [Online].; 2020 [cited Dec. 6, 2020. Available from: https://www.docker.com; Retrieved Oct. 7, 2021; 8 pages. [cited by applicant]
“The Apache Software Foundation. Apache ZooKeeper,” [Online].; 2010-2020 [cited Dec. 7, 2020]. Available from: https://zookeeper.apache.org; Retrieved Oct. 7, 2021; 1 page. [cited by applicant]
Yahoo, “Cluster Manager for Apache Kafka,” [Online].; 2020 [cited Dec. 7, 2020]. Available from: https://github.com/yahoo/CMAK; Retrieved Oct. 7, 2021; 12 pages. [cited by applicant]
Noel S., “A Review of Graph Approaches to Network Security Analytics,” In From Databases to Cyber Security (Lecture Notes in Computer Science).: Springer; 2018; Retrieved Oct. 7, 2021; 24 pages. [cited by applicant]
The PostgreSQL Global Development Group, “PostgreSQL: The world's most advanced open source database,” [Online].; 1996-2020 [cited Dec. 4, 2020]. Available from: https://www.postgresql.org; Retrieved Oct. 7, 2021; 4 pag… [cited by applicant]
Neo4j, Inc, “Neo4j Graph Platform—The Leader in Graph Databases,” [Online].; 2020 [cited Dec. 4, 2020]. Available from: https://neo4j.com; Retrieved Oct. 7, 2021; 15 pages. [cited by applicant]
OpenJS Foundation, “Node.js® is a JavaScript Runtime Built on Chrome's V8 JavaScript Engine,” [Online].; 2020 [cited Dec. 4, 2020]. Available from: https://nodejs.org/; Retrieved Oct. 7, 2021; 1 page. [cited by applicant]
Internet Engineering Task Force (IETF), “The WebSocket Protocol,” [Online].; 2011 [cited Dec. 4, 2020]. Available from: https://tools.ietf.org/html/rfc6455; Retrieved Oct. 7, 2021; 71 pages. [cited by applicant]
DiFonzo C, Noel S., “DeCypher: Human Machine Interaction for Graph-Based Cyber Situational Understanding,” In publication review; 2020; Retrieved Oct. 7, 2021; 3 pages. [cited by applicant]
Neo4j, Inc, “Cypher Query Language,” [Online].; 2020 [cited Dec. 4, 2020]. Available from: https://neo4j.com/developer/cypher/; Retrieved Oct. 7, 2021; 7 pages. [cited by applicant]
Seffers G., “U.S. Army Conducts Final Cyber Blitz,” [Online].; 2020 [cited Dec. 7, 2020]. Available from: https://www.afcea.org/content/us-army-conducts-final-cyber-blitz; Retrieved Oct. 7, 2021; 3 pages. [cited by applicant]
Abney C., “Cyber Quest,” [Online].; 2019 [cited 2020 Dec. 2020]. Available from: https://asc.army.mil/web/news-alt-ond19-cyber-quest/; Retrieved Oct. 7, 2021; 9 pages. [cited by applicant]
Douglas J., “Army Explores Network Resiliency during Annual Experiment,” [Online].; 2020 [cited Dec. 7, 2020]. Available from: https://www.army.mil/article/237419/army_explores_network_resiliency_during_annual_experimen… [cited by applicant]
Program Executive Office Command Control Communications—Tactical (PEO C3T), “Tactical Network Initialization and Configuration,” [Online].; 2020 [cited Dec. 7, 2020]. Available from: https://peoc3t.army.mil/i2s/tnic.php… [cited by applicant]
Tenable, “Tenable Network Security Named Assured Compliance Assessment Solution for the Defense Information Systems Agency,” [Online].; 2012 [cited Dec. 3, 2020]. Available from: https://www.tenable.com/press-releases/t… [cited by applicant]
Elastic. https://www.elastic.co/beats/winlogbeat. [Online].; 2020 [cited Dec. 3, 2020]. Available from: “Winlogbeat—Lightweight Shipper for Windows Event Logs,” Retrieved Oct. 7, 2021; 3 pages. [cited by applicant]
“Splunk: The Data-to-Everything Platform Built for the Cloud,” [Online].; 2005-2020 [cited Dec. 3, 2020]. Available from: https://www.splunk.com; Retrieved Oct. 7, 2021; 6 pages. [cited by applicant]
Palo Alto Networks, “NetFlow Monitoring,” [Online].; 2020 [cited Dec. 3, 2020]. Available from: https://docs.paloaltonetworks.com/pan-os/8-1/pan-os-admin/monitoring/netflow-monitoring; Retrieved Oct. 7, 2021; 2 pages. [cited by applicant]
Multi-Service Tactics, Techniques, and Procedures (MTTP), “Tactical Chat: MTTP for Internet Tactical Chat in Support of Operations,” 2009; Retrieved Oct. 7, 2021; 88 pages. [cited by applicant]
The MITRE Corporation, “MITRE ATT&CK®,” [Online].; 2015-2020 [cited Dec. 7, 2020]. Available from: https://attack.mitre.org; Retrieved Oct. 7, 2021; 2 pages. [cited by applicant]
Heinbockel W, Noel S, Curbo J., “Mission Dependency Modeling for Cyber Situational Awareness,” In NATO IST-148 Symposium on Cyber Defence Situation Awareness; 2016; Sofia; Retrieved Oct. 7, 2021; 14 pages. [cited by applicant]
Noel S, Bodeau D, McQuaid R., “Big-Data Graph Knowledge Bases for Cyber Resilience,” In NATO IST-153 Workshop on Cyber Resilience; 2017; Munich; Retrieved Oct. 7, 2021; 16 pages. [cited by applicant]
U.S. Army, “Engineers Highlight Importance of Field-Based Experimentation, Like NetModX, on ‘CCDC in the Lab’” [Online].; 2019 [cited Dec. 7, 2020]. Available from: https://www.army.mil/article/225812/engineers_highligh… [cited by applicant]
Martin; W. J. et al., “Cyberspace Situational Understanding for Tactical Army Commanders The Army Is Swinging for the Fence, but It Just Needs a Single,” Cyberspace Understanding, Military Review, 18-24, United States(2… [cited by applicant]