SYSTEMS, DEVICES, AND METHODS FOR OBSERVING A COMPUTER NETWORK AND/OR SECURING DATA ACCESS TO A COMPUTER NETWORK
Observing and/or monitoring a computer network that includes a plurality of nodes may involve detecting one or more data flows, or communications, between two or more nodes of the computer network. The data flow(s) may be associated with a user of the computer network. The user may be an individual person, an entity, and/or a software application. A characteristic of the data flow and the user may be determined and these characteristics may be used to determine a level of security risk caused by the data flow in the network. Then, when the level of security risk is above a risk threshold, an alert may be communicated to an operator of the computer network. The alert may be, for example, a message (e.g., email, SMS text message, etc.) and/or display of an icon, or an aspect (e.g., size, color, and/or location) of an icon provided on a graphical user interface (GUI).
1 - 52 . (canceled)
53 . A method for monitoring a computer network including a plurality of nodes, the method comprising:
detecting, by a computer monitoring system, a data flow between a sequence of nodes of the computer network, the data flow being associated with a user of the computer network;
determining, by the computer monitoring system, a characteristic of the data flow and a characteristic of the user;
determining, by the computer monitoring system, a level of security risk caused by the data flow responsively to a determined characteristic of the data flow and a determined characteristic of the user; and
determining, by the computer monitoring system, whether the level of security risk is above a risk threshold and, if so, communicate an alert to an operator of the computer network.
54 . The method for monitoring the computer network including a plurality of nodes of claim 53 , further comprising:
determining, by the computer monitoring system, a characteristic of at least one of the nodes, wherein the determining of the level of security risk caused by the data flow is further responsive to the characteristic of the at least one of the nodes.
55 . The method for monitoring the computer network including a plurality of nodes of claim 53 , further comprising:
executing, by the computer monitoring system, a remedial action responsively to a determination that the level of security risk is above the risk threshold.
56 . The method for monitoring the computer network including a plurality of nodes of claim 3 , wherein the remedial action includes at least one of user's access to any of the nodes in the path of the data flow, redacting of data provided to a user, masking data provided to the user, displaying an error message, and providing an alert to the operator.
57 . The method for monitoring the computer network including a plurality of nodes of claim 53 , further comprising:
receiving, by the computer monitoring system, a trace log for the computer network; and
sampling, by the computer monitoring system, data from the trace log to create a plurality of trace log samples, wherein the classifying of the data flow further uses the plurality of trace log samples.
58 . The method for monitoring the computer network including a plurality of nodes of claim 57 , wherein an analysis of the trace log samples includes performing predictive path progress analysis.
59 . The method for monitoring the computer network including a plurality of nodes of claim 53 , further comprising:
receiving, by the computer monitoring system, a software application transaction log for the computer network; and
sampling, by the computer monitoring system, data from the software application transaction log to create a plurality of software application transaction log samples, wherein the classifying of the data flow further uses the plurality of software application transaction log samples.
6 . The method for monitoring the computer network including a plurality of nodes of claim 59 , wherein an analysis of the software application transaction log samples includes performing predictive path progress analysis.
61 . The method for monitoring the computer network including a plurality of nodes of claim 53 , wherein the alert is communicated to the operator via a graphical user interface showing the nodes of the computer network.
62 . A method for monitoring a computer network including a plurality of nodes, the method comprising:
detecting, by a computer monitoring system, a data flow between a sequence of nodes of the computer network, the data flow being associated with a data source;
sampling, by the computer monitoring system, data from the data flow to create a plurality of data flow samples;
classifying, by the computer monitoring system, the data flow using the plurality of data flow samples; and
communicating, by the computer monitoring system, an indication of the classification to an operator of the computer network.
63 . The method for monitoring the computer network including a plurality of nodes of claim 62 , further comprising:
receiving, by the computer monitoring system, a trace log for the computer network; and
sampling, by the computer monitoring system, data from the trace log to create a plurality of trace log samples, wherein the classifying of the data flow further uses the plurality of trace log samples, wherein an analysis of the trace log samples includes performing predictive path progress analysis.
64 . The method for monitoring the computer network including a plurality of nodes of any of claims 62 , further comprising:
receiving, by the computer monitoring system, a software application transaction log for the computer network; and
sampling, by the computer monitoring system, data from the software application transaction log to create a plurality of software application transaction log samples, wherein the classifying of the data flow further uses the plurality of software application transaction log samples, wherein an analysis of the software application transaction log samples includes performing predictive path progress analysis.
65 . The method for monitoring the computer network including a plurality of nodes of claim 62 , wherein the alert is communicated to the operator via a graphical user interface showing the nodes of the computer network.
66 . A method for monitoring a computer network including a plurality of nodes, the method comprising:
receiving, by the computer monitoring system, a software application transaction log from a software application running within the computer network;
receiving, by the computer monitoring system, a data source transaction log from a data source communicatively coupled to the computer network;
comparing, by the computer monitoring system, the software application transaction log and the data source transaction log to identify a data source transaction log entry that does not have a corresponding software application transaction log entry;
flagging, by the computer monitoring system, an identified data source transaction log entry that does not have a corresponding software application transaction log entry; and
communicating, by the computer monitoring system, an indication of a flagged data source transaction log entry to an operator.
67 . The method for monitoring the computer network including a plurality of nodes of claim 66 , further comprising:
preparing, by the computer monitoring system, a rule regarding a flow of data within the computer network responsively to the comparing of the software application transaction log and the data source transaction log; and
providing, by the computer monitoring system, an indication of the rule to the operator.
68 . The method for monitoring the computer network including a plurality of nodes of claim 66 , further comprising:
preparing, by the computer monitoring system, a rule regarding a flow of data within the computer network responsively to the comparing of the software application transaction log and the data source transaction log; and
implementing, by the computer monitoring system, the rule within the computer network.
69 . The method for monitoring the computer network including a plurality of nodes of claim 66 , further comprising:
modifying, by the computer monitoring system, an operation of the software application responsively to the comparing of the software application transaction log and the data source transaction log.
70 . The method for monitoring the computer network including a plurality of nodes of claim 66 , further comprising:
preparing, by the computer monitoring system, a proposed modification of an operation of the software application responsively to the comparing of the software application transaction log and the data source transaction log; and.
providing, by the computer monitoring system, an indication of the proposed modification to the operator.
71 . The method for monitoring the computer network including a plurality of nodes of claim 66 , further comprising:
preparing, by the computer monitoring system, a proposed modification of an operation of the computer network responsively to the comparing of the software application transaction log and the data source transaction log; and.
providing, by the computer monitoring system, an indication of the proposed modification of an operation of the computer network to the operator.
72 . A method for monitoring a computer network including a plurality of nodes, the method comprising:
receiving, by the computer monitoring system, a set of software application transaction logs, each software application transaction log being received from a software application running within the computer network;
receiving, by the computer monitoring system, a set of data source transaction logs, each data source transaction log being received from a data source associated with the computer network;
comparing, by the computer monitoring system, the set of software application transaction logs and the set of data source transaction logs;
flagging, by the computer monitoring system, any data source transaction log entry that does not have a corresponding software application transaction log entry; and
communicating, by the computer monitoring system, an indication of a flagged data source transaction log entry to an operator.
73 . The method for monitoring the computer network including a plurality of nodes of claim 72 , further comprising:
executing, by the computer monitoring system, distributed tracing within the computer network, a result of the distributed tracing being trace log generation;
comparing, by the computer monitoring system, the software transaction log with the trace log;
flagging, by the computer monitoring system, any software transaction that does not have a corresponding trace log entry; and
communicating, by the computer monitoring system, an indication of a flagged software transaction to an operator.
74 . The method for monitoring the computer network including a plurality of nodes of claim 72 , further comprising:
executing, by the computer monitoring system, distributed tracing within the computer network, a result of the distributed tracing being trace log generation;
comparing, by the computer monitoring system, the software transaction log with the trace log;
flagging, by the computer monitoring system, any software transaction that does not have a corresponding trace log entry; and
communicating, by the computer monitoring system, an indication of a flagged software transaction to an operator;
sampling, by the computer monitoring system, a trace log;
determining, by the computer monitoring system, a security sensitivity of a trace log entry included within a sample of the trace log, wherein the determining of the security sensitivity of the trace log entry include execution of predictive path progress analysis; and
communicating, by the computer monitoring system, an indication of a result of a security sensitivity determination for the trace log sample to the operator.
75 . The method for monitoring the computer network including a plurality of nodes of claim 72 , further comprising:
sampling, by the computer monitoring system, a data flow within the computer network, the data flow being associated with at least one of a data source log and a software application transaction log;
determining, by the computer monitoring system, a security sensitivity of the sampled data flow; and
communicating, by the computer monitoring system, an indication of a result of a security sensitivity determination for the one or more data sources to the operator.
76 . The method for monitoring the computer network including a plurality of nodes of claim 72 , further comprising:
executing, by the computer monitoring system, distributed tracing within the computer network, a result of the distributed tracing being trace log generation;
executing, by the computer monitoring system, a user behavior analysis program on at least one of the data transaction logs, the software application transaction logs, and the trace logs;
creating, by the computer monitoring system, a reference model for data flows within the computer network using a result of the user behavior analysis;
receiving, by the computer monitoring system, an indication of a data flow corresponding to data flowing between a sequence of nodes of the computer network;
analyzing, by the computer monitoring system, the indication of the data flow using the reference model; and
providing, by the computer monitoring system, a result of an analysis of the indication of the data flow to the operator.
77 . The method for monitoring the computer network including a plurality of nodes of claim 72 , further comprising:
sampling, by the computer monitoring system, a data flow within the computer network, the data flow being associated with at least one of a data source log and a software application transaction log;
determining, by the computer monitoring system, a security sensitivity of the sampled data flow; and
communicating, by the computer monitoring system, an indication of a result of a security sensitivity determination for the one or more data sources to the operator, wherein the determining of the security sensitivity of the sample data flow includes execution of predictive path progress analysis.
78 . The method for monitoring the computer network including a plurality of nodes of claim 76 , wherein the reference model models authorized user behavior in compliance with one or more policies of the computer network and the result of the analysis of the indication of the data flow is an indication of whether a user associated with the data flow is authorized to access data included within the data flow.
79 . The method for monitoring the computer network including a plurality of nodes of claim 76 , wherein the reference model models an authorized data access pattern and the result of the analysis of the indication of the data flow is an indication of whether a data access pattern of the data flow is an authorized data access pattern.
80 . The method for monitoring the computer network including a plurality of nodes of claim 76 , further comprising:
determining, by the computer monitoring system, a risk severity indicator for the reference model, wherein analysis of the indication of the data flow using the reference model uses the risk severity indicator for the reference model.
81 . The method for monitoring the computer network including a plurality of nodes of claim 72 , further comprising:
automatically generating, by the computer monitoring system, a policy for communication between nodes in the computer network responsively to a result of the analysis of the indication of the data flow; and
providing, by the computer monitoring system, the policy to the operator.