IP Library Granted Patent US 12,267,350
Granted Patent B2
US 12,267,350 · App. 17/635,699 · Granted Apr 1, 2025

Systems, devices, and methods for observing and/or performing data access compliance to a computer network

Inventors: Manjit Gombra Singh (Saratoga, CA); Gouse Basha Mahammad (San Jose, CA)
Assignee: ARETE SECURITY INC.
H04L63/1433G06F21/554G06F21/577H04L63/0236H04L63/102H04L63/1416H04L63/1425H04L63/20G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,350
App. No.
17/635,699
Granted
Apr 1, 2025
Kind
B2
Abstract

Observing and/or monitoring a computer network that includes a plurality of nodes may involve detecting one or more data flows, or communications, between two or more nodes of the computer network. The data flow(s) may be associated with a user of the computer network. The user may be an individual person, an entity, and/or a software application. A characteristic of the data flow and the user may be determined and these characteristics may be used to determine a level of security risk caused by the data flow in the network. Then, when the level of security risk is above a risk threshold, an alert may be communicated to an operator of the computer network. The alert may be, for example, a message (e.g., email, SMS text message, etc.) and/or display of an icon, or an aspect (e.g., size, color, and/or location) of an icon provided on a graphical user interface (GUI).

Claims (58)

1. A computer-implemented system comprising at least one computing device comprising at least one processor and instructions executable by the at least one processor to cause the at least one processor to perform operations comprising:

a) detecting a data flow between a sequence of nodes of a computer network, the data flow associated with a user of the computer network;

b) determining a characteristic of the data flow and a characteristic of the user;

c) receiving a software application transaction log for the computer network;

d) sampling data from the software application transaction log to create a plurality of software application transaction log samples, wherein frequency of the sampling is automatically adjusted responsive to security risk associated with the data flow;

e) classifying the data flow responsive to the plurality of software application transaction log samples;

f) applying a machine learning algorithm configured to perform predictive path progress analysis in order to determine a level of security risk caused by the data flow responsive to the determined characteristic of the data flow, the determined characteristic of the user, and the classification of the data flow;

g) generating a plurality of transaction maps, each transaction map comprising icons representing the nodes of the computer network and the data flow between the nodes over a configurable time interval starting at a point in time and a visual indicator of the level of security risk;

h) comparing two or more of the transaction maps representing different time intervals, different points in time, or both to detect a change between the transaction maps; and

j) generating an alert notification of the change.

2. The system of claim 1 , wherein the operations further comprise: determining a characteristic of at least one of the nodes, wherein the determining of the level of security risk caused by the data flow is further responsive to the characteristic of the at least one of the nodes.

3. The system of claim 1 , wherein the data flow is associated with a data source, and wherein the operations further comprise:

a) determining a characteristic of the data source; and

b) classifying the data flow responsive to the characteristic of the data source,

wherein the determining of the level of security risk caused by the data flow is further responsive to the classification.

4. The system of claim 1 , wherein the operations further comprise:

a) receiving a trace log for the computer network;

b) sampling data from the trace log to create a plurality of trace log samples; and

c) classifying the data flow responsive to the plurality of trace log samples,

wherein the determining of the level of security risk caused by the data flow is further responsive to the classification.

5. The system of claim 4 , wherein the operations further comprise: executing, prior to receipt of the trace log, distributed tracing within the computer network to generate the trace log.

6. The system of claim 1 , wherein the data flow is detected by using at least one of a user name, a user identifier, a uniform resource locator (URL), a service sequence, a data source, an Internet protocol (IP) address, and a node identifier.

7. The system of claim 1 , wherein the operations further comprise: scanning the computer network to discover the sequence of nodes of the computer network prior to detecting the data flow between the sequence of nodes of the computer network.

8. The system of claim 1 , wherein the operations further comprise: receiving a standard for data protection, wherein the determining of the characteristic of the data flow and the level of risk caused by the data flow is determined, at least in part, using the standard for data protection.

9. The system of claim 1 , wherein determining the characteristic of the data flow includes determining what nodes the data is flowing through.

10. The system of claim 1 , wherein the operations further comprise:

a) receiving an indication of a threshold level of security risk; and

b) executing a remedial action responsively to a determination that the level of security risk is above the threshold level of security risk.

11. The system of claim 1 , wherein one or more of the transaction maps further comprises an icon representing the user.

12. One or more non-transitory computer-readable storage media encoded with instructions executable by one or more processors to provide an application comprising:

a) a software module detecting a data flow between a sequence of nodes of a computer network, the data flow associated with a user of the computer network;

b) a software module determining a characteristic of the data flow and a characteristic of the user;

c) a software module receiving a software application transaction log for the computer network;

d) a software module sampling data from the software application transaction log to create a plurality of software application transaction log samples, wherein frequency of the sampling is automatically adjusted responsive to security risk associated with the data flow;

e) a software module classifying the data flow responsive to the plurality of software application transaction log samples;

f) a software module applying a machine learning algorithm configured to perform predictive path progress analysis in order to determine a level of security risk caused by the data flow responsive to the determined characteristic of the data flow, the determined characteristic of the user, and the classification of the data flow;

g) a software module generating a plurality of transaction maps, each transaction map comprising icons representing the nodes of the computer network and the data flow between the nodes over a configurable time interval starting at a point in time and a visual indicator of the level of security risk;

h) a software module comparing two or more of the transaction maps representing different time intervals, different points in time, or both to detect a change between the transaction maps; and

j) a software module generating an alert notification of the change.

13. The media of claim 12 , wherein the application further comprises: a software module determining a characteristic of at least one of the nodes, wherein the determining of the level of security risk caused by the data flow is further responsive to the characteristic of the at least one of the nodes.

14. The media of claim 12 , wherein the data flow is associated with a data source, and wherein the application further comprises:

a) a software module determining a characteristic of the data source; and

b) a software module classifying the data flow responsive to the characteristic of the data source,

wherein the determining of the level of security risk caused by the data flow is further responsive to the classification.

15. The media of claim 12 , wherein the application further comprises:

a) a software module receiving a trace log for the computer network;

b) a software module sampling data from the trace log to create a plurality of trace log sample; and

c) a software module classifying the data flow responsive to the plurality of trace log samples,

wherein the determining of the level of security risk caused by the data flow is further responsive to the classification.

16. The media of claim 15 , wherein the application further comprises: a software module executing, prior to receipt of the trace log, distributed tracing within the computer network to generate the trace log.

17. The media of claim 12 , wherein the data flow is detected by using at least one of a user name, a user identifier, a uniform resource locator (URL), a service sequence, a data source, an Internet protocol (IP) address, and a node identifier.

18. The media of claim 12 , wherein the application further comprises: a software module scanning the computer network to discover the sequence of nodes of the computer network prior to detecting the data flow between the sequence of nodes of the computer network.

19. The media of claim 12 , wherein the application further comprises: a software module receiving a standard for data protection, wherein the determining of the characteristic of the data flow and the level of risk caused by the data flow is determined, at least in part, using the standard for data protection.

20. The media of claim 12 , wherein determining the characteristic of the data flow includes determining what nodes the data is flowing through.

21. The media of claim 12 , wherein the application further comprises:

a) a software module receiving an indication of a threshold level of security risk; and

b) a software module executing a remedial action responsively to a determination that the level of security risk is above the threshold level of security risk.

22. The media of claim 12 , wherein one or more of the transaction maps further comprises an icon representing the user.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2022
From: MAHAMMAD, GOUSE BASHA
To: ARETE SECURITY INC. DBA DRUVSTAR
Reel/Frame 059617/0118 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2022
From: SINGH, MANJIT GOMBRA
To: ARETE SECURITY INC. DBA DRUVSTAR
Reel/Frame 059617/0121 →
Continuity (2)
Provisional Application 63134545 · Jan 6, 2021
Related Publication 20230027733A1 · Jan 26, 2023
References Cited (49)
US 7296288B1 · Hill et al. · 2007 [cited by applicant]
US 8488963B2 · Kunjidhapatham · 2013 [cited by examiner]
US 8595834B2 · Xie et al. · 2013 [cited by applicant]
US 8726376B2 · Rieschick et al. · 2014 [cited by applicant]
US 9311476B2 · Stolfo et al. · 2016 [cited by applicant]
US 9787581B2 · Dosovitsky · 2017 [cited by applicant]
US 10237240B2 · Phillips · 2019 [cited by examiner]
US 10250623B1 · Patton · 2019 [cited by examiner]
US 10904277B1 · Sharifi Mehr · 2021 [cited by applicant]
US 20030101341A1 · Kettler, III · 2003 [cited by examiner]
US 20050102159A1 · Mondshine · 2005 [cited by applicant]
US 20120233656A1 · Rieschick et al. · 2012 [cited by applicant]
US 20130305357A1 · Ayyagari et al. · 2013 [cited by applicant]
US 20150254158A1 · Puri et al. · 2015 [cited by applicant]
US 20160343100A1 · Davenport et al. · 2016 [cited by applicant]
US 20160371613A1 · Ulrich · 2016 [cited by examiner]
US 20170163674A1 · Yu · 2017 [cited by applicant]
US 20170180418A1 · Shen et al. · 2017 [cited by applicant]
US 20170206376A1 · Sher-Jan · 2017 [cited by applicant]
US 20170223030A1 · Merza · 2017 [cited by applicant]
US 20180227322A1 · Luo · 2018 [cited by examiner]
US 20180248902A1 · Dãnilã-Dumitrescu · 2018 [cited by examiner]
US 20180359172A1 · Yadav · 2018 [cited by applicant]
US 20190138542A1 · Van Beest et al. · 2019 [cited by applicant]
US 20190171169A1 · Di Pietro et al. · 2019 [cited by applicant]
US 20190253443A1 · Vasudevan et al. · 2019 [cited by applicant]
US 20190260787A1 · Zou · 2019 [cited by applicant]
US 20190261222A1 · Raleigh et al. · 2019 [cited by applicant]
US 20190342311A1 · Muddu · 2019 [cited by examiner]
US 20190392351A1 · Zuluaga · 2019 [cited by examiner]
US 20200076846A1 · Pandian et al. · 2020 [cited by applicant]
US 20200186547A1 · Bartos et al. · 2020 [cited by applicant]
US 20200204574A1 · Christian · 2020 [cited by applicant]
US 20200244673A1 · Stockdale et al. · 2020 [cited by applicant]
US 20210084073A1 · Crabtree et al. · 2021 [cited by applicant]
US 20210092129A1 · Aksela · 2021 [cited by applicant]
US 20210258305A1 · Crabtree et al. · 2021 [cited by applicant]
US 20210336962A1 · Mulampaka · 2021 [cited by examiner]
US 20210377288A1 · Chen Kaidi · 2021 [cited by applicant]
US 20220147638A1 · Brannon et al. · 2022 [cited by applicant]
US 20220224711A1 · Singh et al. · 2022 [cited by applicant]
WO WO2022150513A1 · 2022 [cited by applicant]
Co-pending U.S. Appl. No. 17/635,695, inventors Singh; Manjit Gombra et al., filed Feb. 15, 2022. [cited by applicant]
PCT/US2022/011496 International Search Report and Written Opinion dated Apr. 7, 2022. [cited by applicant]
U.S. Appl. No. 17/671,577 Non-Final Office Action dated Jun. 10, 2022. [cited by applicant]
EP22737128.3 Extended European Search Report dated Nov. 4, 2024. [cited by applicant]
U.S. Appl. No. 17/635,695 Office Action dated Sep. 5, 2024. [cited by applicant]
U.S. Appl. No. 17/635,695 Office Action dated Jan. 30, 2024. [cited by applicant]
U.S. Appl. No. 17/635,695 Office Action dated Jan. 8, 2025. [cited by applicant]
Cited By (1)
US 12,615,285