IP Library Granted Patent US 11,677,772
Granted Patent B1
US 11,677,772 · App. 17/504,311 · Granted Jun 13, 2023

Using graph-based models to identify anomalies in a network environment

Inventors: Vikram Kapoor (Cupertino, CA); Samuel Joseph Pullara, III (Los Altos, CA); Murat Bog (Fremont, CA); Yijou Chen (Cupertino, CA); Sanjay Kalra (San Jose, CA)
Assignee: Lacework Inc.
H04L63/1425G06F9/455G06F9/545G06F16/9024G06F16/9038G06F16/9535G06F16/9537G06F21/57H04L43/045H04L43/06H04L63/10H04L67/306H04L67/535G06F16/2456
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,677,772
App. No.
17/504,311
Filed
Oct 18, 2021
Granted
Jun 13, 2023
Kind
B1
Art Unit
2442
USPC
709/224
Abstract

Activities within a network environment are monitored (e.g., using agents). At least a portion of the monitored activities are used to generate a logical graph model. The generated logical graph model is used to determine an anomaly. The detected anomaly is recorded and can be used to generate an alert.

Claims (40)

1. A method comprising:

monitoring activities within a network environment;

generating a logical graph model comprising a set of nodes and a set of edges using at least a portion of the monitored activities, the set of edges comprising a first edge having a first edge type that indicates a first type of relationship between nodes interconnected by the first edge and a second edge having a second edge type that indicates a second type of relationship between nodes interconnected by the second edge; and

using the generated logical graph model to detect an anomaly in the network environment, wherein the anomaly is detected based on an addition of a new edge to the set of edges of the logical graph model, the new edge representing a user privilege change.

2. The method of claim 1 , further comprising generating an alert based on the detected anomaly.

3. The method of claim 2 , wherein the alert indicates a severity level.

4. The method of claim 1 , wherein a combination of edges in the set of edges indicates a threat.

5. The method of claim 1 , wherein:

a single edge in the set of edges indicates a threat having a first severity level; and

a combination of edges in the set of edges indicates the threat having a second severity level that is higher than the first severity level.

6. The method of claim 1 , wherein the generated logical graph model represents a baseline of behavior in the network environment.

7. The method of claim 6 , wherein using the generated logical graph model to detect the anomaly includes comparing a current graph associated with the network environment against the baseline, wherein the comparing identifies the addition of the new edge to the set of edges of the logical graph model.

8. The method of claim 1 , wherein the detected anomaly is associated with a security threat.

9. The method of claim 1 , wherein:

the first edge type indicates a first type of behavioral relationship between the nodes

interconnected by the first edge; and

the second edge type indicates a different type of behavioral relationship between the nodes interconnected by the second edge.

10. A system comprising:

a processor; and

a memory storing instructions configured to direct the processor to:

monitor activities within a network environment;

generate a multidimensional logical graph model comprising a set of nodes and a set of edges using at least a portion of the monitored activities, the set of edges comprising a first edge having a first edge type that indicates a first type of relationship between nodes interconnected by the first edge and a second edge having a second edge type that indicates a second type of relationship between nodes interconnected by the second edge; and

use the generated logical graph model to detect an anomaly in the network environment, wherein the anomaly is detected based on an addition of a new edge to the set of edges of the logical graph model, the new edge representing a user privilege change.

11. The method of claim 1 , wherein the user privilege change comprises a privilege escalation.

12. The system of claim 10 , further comprising generating an alert based on the detected anomaly.

13. The system of claim 12 , wherein the alert indicates a severity level.

14. The system of claim 10 , wherein the detected anomaly is associated with a security threat.

15. The system of claim 10 , wherein:

the generated logical graph model represents a baseline of behavior in the network environment; and

using the generated logical graph model to detect the anomaly includes comparing a current graph associated with the network environment against the baseline, wherein the comparing identifies the addition of the new edge to the set of edges of the logical graph model.

16. A computer program product embodied in a non-transitory computer-readable storage medium and comprising computer instructions for:

monitoring activities within a network environment;

generating a logical graph model comprising a set of nodes and a set of edges using at least a portion of the monitored activities, the set of edges comprising a first edge having a first edge type that indicates a first type of relationship between nodes interconnected by the first edge and a second edge having a second edge type that indicates a second type of relationship between nodes interconnected by the second edge; and

using the generated logical graph model to detect an anomaly in the network environment, wherein the anomaly is detected based on an addition of a new edge to the set of edges of the logical graph model, the new edge representing a user privilege change.

17. The computer program product of claim 16 , further comprising generating an alert based on the detected anomaly.

18. The computer program product of claim 17 , wherein the alert indicates a severity level.

19. The computer program product of claim 16 , wherein the detected anomaly is associated with a security threat.

20. The computer program product of claim 16 , wherein:

the generated logical graph model represents a baseline of behavior in the network environment; and

using the generated logical graph model to detect the anomaly includes comparing a current graph associated with the network environment against the baseline, wherein the comparing identified the addition of the new edge to the set of edges of the logical graph model.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069113/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2021
From: KAPOOR, VIKRAM; PULLARA, SAMUEL JOSEPH, III; BOG, MURAT; CHEN, YIJOU; KALRA, SANJAY
To: LACEWORK INC.
Reel/Frame 057824/0990 →
Continuity (4)
Continuation 16665961 · Oct 28, 2019
Continuation 16134794 · Sep 18, 2018
Provisional Application 62650971 · Mar 30, 2018
Provisional Application 62590986 · Nov 27, 2017
Cited By (22)
US 12,309,185 US 12,323,449 US 12,335,348 US 12,348,545 US 12,355,626 US 12,355,793 US 12,363,176 US 12,368,736 US 12,418,555 US 12,549,571 US 12,549,577 US 12,563,071 US 12,592,950 US 12,613,930 US 12,621,324 US 12,627,686 US 12,627,690 US 12,634,312 US 12,634,376 US 12,652,302 US 12,712,897 US 12,719,896