IP Library Granted Patent US 12,328,322
Granted Patent B2
US 12,328,322 · App. 17/711,811 · Granted Jun 10, 2025

Method, product, and system for network security management using software representation that embodies network configuration and policy data

Inventors: Nicolas Beauchesne (Honolulu, HI); Sohrob Kazerounian (Brookline, MA); William Stow Finlayson, IV (Cherry Hill, NJ); Karl Matthew Lynn (San Jose, CA)
Assignee: Vectra AI, Inc.
H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,328,322
App. No.
17/711,811
Filed
Apr 1, 2022
Granted
Jun 10, 2025
Kind
B2
Art Unit
2408
USPC
726/23
Abstract

Disclosed is an approach for network security management using software representation that embodies network configuration and policy data. In some embodiments, the approach includes a process to generate a software representation of what is possible based on a network configuration and policy data. The software representation comprises a state machine where different states can be reached using respective transitions or properties why are possible as determined based on the network configuration and policy data. The states correspond to respective entities on the network which may comprise resources that are identifiable for protection. The software representation can then be stimulated to identify sequences of state-to-state transitions which may in turn be processed to generate corresponding detection signatures for use in monitoring the network.

Claims (38)

1. A method comprising:

identifying network configuration data and network policy data for a computer network;

generating a software representation of the computer network based on the network configuration data and network policy data, wherein crash statements are inserted into the software representation to identify states that represent a protected resource;

analyzing the software representation to identify possible attack paths in the computer network using inputs generated by a fuzzer, and wherein the possible attach paths are identified at least by executing at least one of the crash statements inserted into the software representation in response to the inputs generated by the fuzzer; and

monitoring the computer network using detection signatures that detect traversal of at least a subset of one or more attack paths.

2. The method of claim 1 , wherein the network configuration data specifies access rights allocated to respective groups and the network policy data specifies a set of access rights for group members to access network resources.

3. The method of claim 1 , wherein the software representation comprises a source code representation or an executable compiled from the source code representation and represents a plurality of states and transitions between states.

4. The method of claim 1 , wherein the software representation comprises a source code representation or an executable compiled from the source code representation and encapsulates a bitmap representing a plurality of states and transitions between states.

5. The method of claim 1 , wherein analyzing the software representation to identify possible attack paths in the computer network comprises stimulating the software representation using a plurality of inputs to identify sets of one or more state changes that reach a target state from a starting state, and an attack path comprises at least a sequence of state changes.

6. The method of claim 1 , wherein respective crash statements are associated with a corresponding state that represents a protected resource and the respective crash statements are executed when the corresponding state that represents the protected resource is reached.

7. The method of claim 1 , wherein a detection signature comprises one or more atomic rules that detect an occurrence that satisfies the one or more atomic rules on the computing network.

8. The method of claim 1 , wherein monitoring the computer network using detection signatures that detect traversal of at least a subset of one or more attack paths comprises processing a triggering event received in response to a detection signature detecting an occurrence that satisfies one or more atomic rules by applying a second set of rules to the triggering event to determine whether to generate an alert.

9. A non-transitory computer readable medium having stored thereon a set of instructions, the set of instructions, when executed by a processor, causing a set of acts comprising:

identifying network configuration data and network policy data for a computer network;

generating a software representation of the computer network based on the network configuration data and network policy data, wherein crash statements are inserted into the software representation to identify states that represent a protected resource;

analyzing the software representation to identify possible attack paths in the computer network using inputs generated by a fuzzer, and wherein the possible attach paths are identified at least by executing at least one of the crash statements inserted into the software representation in response to the inputs generated by the fuzzer; and

monitoring the computer network using detection signatures that detect traversal of at least a subset of one or more attack paths.

10. The computer readable medium of claim 9 , wherein the network configuration data specifies access rights allocated to respective groups and the network policy data specifies a set of access rights for group members to access network resources.

11. The computer readable medium of claim 9 , wherein the software representation comprises a source code representation or an executable compiled from the source code representation and represents a plurality of states and transitions between states.

12. The computer readable medium of claim 9 , wherein the software representation comprises a source code representation or an executable compiled from the source code representation and encapsulates a bitmap representing a plurality of states and transitions between states.

13. The computer readable medium of claim 9 , wherein analyzing the software representation to identify possible attack paths in the computer network comprises stimulating the software representation using a plurality of inputs to identify sets of one or more state changes that reach a target state from a starting state, and an attack path comprises at least a sequence of state changes.

14. The computer readable medium of claim 9 , wherein respective crash statements are associated with a corresponding state that represents a protected resource and the respective crash statements are executed when the corresponding state that represents the protected resource is reached.

15. The computer readable medium of claim 9 , wherein a detection signature comprises one or more atomic rules that detect an occurrence that satisfies the one or more atomic rules on the computing network.

16. The computer readable medium of claim 9 , wherein monitoring the computer network using detection signatures that detect traversal of at least a subset of one or more attack paths comprises processing a triggering event received in response to a detection signature detecting an occurrence that satisfies one or more atomic rules by applying a second set of rules to the triggering event to determine whether to generate an alert.

17. A computing system comprising:

a memory storing a set of instructions; and

a processor to execute the set of instructions to perform a set of acts comprising:

identifying network configuration data and network policy data for a computer network;

generating a software representation of the computer network based on the network configuration data and network policy data, wherein crash statements are inserted into the software representation to identify states that represent a protected resource;

analyzing the software representation to identify possible attack paths in the computer network using inputs generated by a fuzzer, and wherein the possible attach paths are identified at least by executing at least one of the crash statements inserted into the software representation in response to the inputs generated by the fuzzer; and

monitoring the computer network using detection signatures that detect traversal of at least a subset of one or more attack paths.

18. The computing system of claim 17 , wherein the network configuration data specifies access rights allocated to respective groups and the network policy data specifies a set of access rights for group members to access network resources.

19. The computing system of claim 17 , wherein the software representation comprises a source code representation or an executable compiled from the source code representation and represents a plurality of states and transitions between states.

20. The computing system of claim 17 , wherein the software representation comprises a source code representation or an executable compiled from the source code representation and encapsulates a bitmap representing a plurality of states and transitions between states.

21. The computing system of claim 17 , wherein analyzing the software representation to identify possible attack paths in the computer network comprises stimulating the software representation using a plurality of inputs to identify sets of one or more state changes that reach a target state from a starting state, and an attack path comprises at least a sequence of state changes.

22. The computing system of claim 17 , wherein respective crash statements are associated with a corresponding state that represents a protected resource and the respective crash statements are executed when the corresponding state that represents the protected resource is reached.

23. The computing system of claim 17 , wherein a detection signature comprises one or more atomic rules that detect an occurrence that satisfies the one or more atomic rules on the computing network.

24. The computing system of claim 17 , wherein monitoring the computer network using detection signatures that detect traversal of at least a subset of one or more attack paths comprises processing a triggering event received in response to a detection signature detecting an occurrence that satisfies one or more atomic rules by applying a second set of rules to the triggering event to determine whether to generate an alert.

Assignments (2)
SECURITY INTEREST Recorded Oct 29, 2024
From: VECTRA AI, INC.
To: AB PRIVATE CREDIT INVESTORS LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 069061/0588 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2022
From: BEAUCHESNE, NICOLAS; KAZEROUNIAN, SOHROB; FINLAYSON IV, WILLIAM STOW; LYNN, KARL MATTHEW
To: VECTRA AI, INC.
Reel/Frame 059477/0207 →
Continuity (1)
Related Publication 20230319067A1 · Oct 5, 2023
References Cited (78)
US 6321338B1 · Porras et al. · 2001 [cited by applicant]
US 6651099B1 · Dietz et al. · 2003 [cited by applicant]
US 7305383B1 · Kubesh et al. · 2007 [cited by applicant]
US 8272061B1 · Lotem et al. · 2012 [cited by applicant]
US 9432394B1 · Lahiri et al. · 2016 [cited by applicant]
US 10148685B2 · Hassanzadeh · 2018 [cited by examiner]
US 10528868B2 · Gillespie et al. · 2020 [cited by applicant]
US 11922712B2 · Tsibulevskiy et al. · 2024 [cited by applicant]
US 20030051026A1 · Carter et al. · 2003 [cited by applicant]
US 20030188189A1 · Desai et al. · 2003 [cited by applicant]
US 20080044018A1 · Scrimsher et al. · 2008 [cited by applicant]
US 20130097125A1 · Marvasti et al. · 2013 [cited by applicant]
US 20130283360A1 · Hui · 2013 [cited by examiner]
US 20130340083A1 · Petrica · 2013 [cited by examiner]
US 20140279808A1 · Strassner · 2014 [cited by applicant]
US 20150033340A1 · Giokas · 2015 [cited by applicant]
US 20160301704A1 · Hassanzadeh et al. · 2016 [cited by applicant]
US 20170161498A1 · Yavo · 2017 [cited by applicant]
US 20180232523A1 · Copty et al. · 2018 [cited by applicant]
US 20190109872A1 · Dhakshinamoorthy et al. · 2019 [cited by applicant]
US 20190228098A1 · Daly et al. · 2019 [cited by applicant]
US 20190266071A1 · Copty et al. · 2019 [cited by applicant]
US 20200022003A1 · Bizzarri et al. · 2020 [cited by applicant]
US 20200028861A1 · Pritzkau et al. · 2020 [cited by applicant]
US 20200073783A1 · Hortala et al. · 2020 [cited by applicant]
US 20200177618A1 · Hassanzadeh · 2020 [cited by examiner]
US 20200193031A1 · Avraham · 2020 [cited by examiner]
US 20200304534A1 · Rakesh et al. · 2020 [cited by applicant]
US 20210194924A1 · Heinemeyer et al. · 2021 [cited by applicant]
US 20210243208A1 · Rubin et al. · 2021 [cited by applicant]
US 20210243226A1 · El Gamal et al. · 2021 [cited by applicant]
US 20210248443A1 · Shu · 2021 [cited by examiner]
US 20210336971A1 · Robbins · 2021 [cited by examiner]
US 20210352100A1 · Barai · 2021 [cited by examiner]
US 20220014561A1 · Caceres et al. · 2022 [cited by applicant]
US 20220269591A1 · Mcshane et al. · 2022 [cited by applicant]
US 20220319219A1 · Tsibulevskiy et al. · 2022 [cited by applicant]
US 20220368702A1 · Robbins et al. · 2022 [cited by applicant]
US 20230050691A1 · Gu et al. · 2023 [cited by applicant]
US 20230262073A1 · Sheu et al. · 2023 [cited by applicant]
CA 2926579 · 2016 [cited by applicant]
CN 105262771 · 2016 [cited by applicant]
CN 107277039 · 2017 [cited by applicant]
CN 111049827 · 2020 [cited by applicant]
EP 3726803 · 2020 [cited by applicant]
EP 4254865A1 · 2023 [cited by applicant]
EP 4254866A1 · 2023 [cited by applicant]
EP 4254867A2 · 2023 [cited by applicant]
EP 4254869A2 · 2023 [cited by applicant]
EP 4254868A3 · 2023 [cited by applicant]
WO WO2015013376A2 · 2015 [cited by applicant]
WO 2020046981 · 2020 [cited by applicant]
Moser et al., “Exploring Multiple Execution Paths for Malware Analysis”, 2007 IEEE Symposium on Security and Privacy (SP '07), Date of Conference: May 20-23 (Year: 2007). [cited by examiner]
Jeon et al., “Automated Crash Filtering Using Interprocedural Static Analysis for Binary Codes”, 2017 IEEE 41st Annual Computer Software and Applications Conference (COMPSAC), Date of Conference: Jul. 4-8 (Year: 2017). [cited by examiner]
Extended European Search Report for EP Patent Appln. No. 22191317.1 dated Aug. 3, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191319.7 dated Aug. 17, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191320.5 dated Sep. 28, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191322.1 dated Oct. 2, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191321.3 dated Oct. 2, 2023. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,884 dated Feb. 2, 2024. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,903 dated Jan. 8, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,868 dated Mar. 18, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,868 dated Mar. 15, 2024. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 23199257.9 dated Mar. 6, 2024. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,850 dated Mar. 27, 2024. [cited by applicant]
D. Kreutz, F. M. V. Ramos, P. E. Verfssimo, C. E. Rothenberg, S. Azodolmolky and S. Uhlig, “Software-Defined Networking: A Comprehensive Survey,” in Proceedings of the IEEE, vol. 103, No. 1, pp. 14-76 (Jan. 2015) (Year:… [cited by applicant]
Final Office Action for U.S. Appl. No. 17/711,903 dated May 7, 2024. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/711,884 dated May 23, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,868 dated Aug. 23, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,903 dated Sep. 26, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,868 dated Oct. 28, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,884 dated Nov. 1, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,850 dated Mar. 12, 2025. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,884 dated Apr. 4, 2025. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/128,549 dated Mar. 17, 2025. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,850 dated Apr. 9, 2025. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 18/108,383 dated Apr. 17, 2025. [cited by applicant]
L. Zhao, P. Cao, Y. Duan, H. Yin and J. Xuan, “Probabilistic Path Prioritization for Hybrid Fuzzing,” in IEEE Transactions on Dependable and Secure Computing, vol. 19, No. 3, pp. 1955-1973, May 1-Jun. 2022. [cited by applicant]