IP Library Granted Patent US 12,219,070
Granted Patent B2
US 12,219,070 · App. 17/711,903 · Granted Feb 4, 2025

Method, product, and system for generating detection signatures based on attack paths in a computer network identified using a software representation that embodies network configuration and policy data for security management using detection signature templates

Inventors: Nicolas Beauchesne (Honolulu, HI); Sohrob Kazerounian (Brookline, MA); William Stow Finlayson, IV (Cherry Hill, NJ); Karl Matthew Lynn (San Jose, CA)
Assignee: Vectra AI, Inc.
H04L9/3247H04L47/762H04L47/827H04L47/828
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,219,070
App. No.
17/711,903
Granted
Feb 4, 2025
Kind
B2
Abstract

Disclosed is an approach for generating detection signatures based on analysis of a software representation of what is possible in a computer network based on network configuration data and network policy data. In some embodiments, the process includes maintaining a plurality of detection signature templates, generation of detection signatures (detection signature instances) using respective detection signature templates that are selected based on the analysis of the software representation. In some embodiments, detection signatures templates are of different type and may be deployed at different locations based on their respective type(s), such as at source, destination.

Claims (44)

1. A method comprising:

identifying a plurality of candidate triggers selected for implementation as detection signatures, wherein the plurality of candidate triggers correspond to state-to-state transitions identified by analyzing a software representation of a computer network, the software representation represents actions that can be taken on the computer network, and the software representation of the computer network was generated based on network configuration data and network policy data that specify access rights; and

processing one or more candidate triggers of the plurality of candidate triggers to generate detection signature instances, wherein each of the one or more candidate triggers are processed by:

selecting a respective candidate trigger of the one or more candidate triggers;

identifying a corresponding detection signature template;

duplicating the corresponding detection signature template; and

modifying the duplicate detection signature template to form a respective detection signature.

2. The method of claim 1 , wherein the network configuration data specifies access rights allocated to respective groups and the network policy data specifies comprises a set of access rights for group members to access network resources.

3. The method of claim 1 , wherein the software representation comprises a source code representation or an executable compiled from the source code representation and represents a plurality of states and transitions between states.

4. The method of claim 1 , wherein at least one detection signature corresponding to an individual candidate trigger comprises a first detection signature instance for deployment at a first location, a second detection signature instance corresponding to the same individual candidate trigger comprises a second detection signature instance for deployment at a second location, and the first detection signature instance is different from the second detection signature instance.

5. The method of claim 1 , wherein the respective detection signature corresponding to an individual candidate trigger comprises a first set of conditions and a second set of conditions, wherein satisfaction of either the first set of conditions or the second set of conditions triggers output of a corresponding message.

6. The method of claim 5 , wherein the corresponding message for the first set of conditions is different from the corresponding message for the second set of conditions.

7. The method of claim 5 , wherein the first set of conditions are to be evaluated at a first location and the second set of conditions are to be evaluated at a second location different from the first location.

8. The method of claim 7 , wherein the first and second locations comprise two or more of on a network, at a source, at a destination or endpoint, or at an authentication service.

9. A non-transitory computer readable medium having stored thereon a set of instructions, the set of instructions, when executed by a processor, causing a set of acts comprising:

identifying a plurality of candidate triggers selected for implementation as detection signatures, wherein the plurality of candidate triggers correspond to state-to-state transitions identified by analyzing a software representation of a computer network, the software representation represents actions that can be taken on the computer network, and the software representation of the computer network was generated based on network configuration data and network policy data that specify access rights; and

processing one or more candidate triggers of the plurality of candidate triggers to generate detection signature instances, wherein each of the one or more candidate triggers are processed by:

selecting a respective candidate trigger of the one or more candidate triggers;

identifying a corresponding detection signature template;

duplicating the corresponding detection signature template; and

modifying the duplicate detection signature template to form a respective detection signature.

10. The computer readable medium of claim 9 , wherein the network configuration data specifies access rights allocated to respective groups and the network policy data specifies comprises a set of access rights for group members to access network resources.

11. The computer readable medium of claim 9 , wherein the software representation comprises a source code representation or an executable compiled from the source code representation and represents a plurality of states and transitions between states.

12. The computer readable medium of claim 9 , wherein at least one detection signature corresponding to an individual candidate trigger comprises a first detection signature instance for deployment at a first location, a second detection signature instance corresponding to the same individual candidate trigger comprises a second detection signature instance for deployment at a second location, and the first detection signature instance is different from the second detection signature instance.

13. The computer readable medium of claim 9 , wherein the respective detection signature corresponding to an individual candidate trigger comprises a first set of conditions and a second set of conditions, wherein satisfaction of either the first set of conditions or the second set of conditions triggers output of a corresponding message.

14. The computer readable medium of claim 13 , wherein the corresponding message for the first set of conditions is different from the corresponding message for the second set of conditions.

15. The computer readable medium of claim 13 , wherein the first set of conditions are to be evaluated at a first location and the second set of conditions are to be evaluated at a second location different from the first location.

16. The computer readable medium of claim 15 , wherein the first and second locations comprise two or more of on a network, at a source, at a destination or endpoint, or at an authentication service.

17. A computing system comprising:

a memory storing a set of instructions; and

a processor to execute the set of instructions to perform a set of acts comprising:

identifying a plurality of candidate triggers selected for implementation as detection signatures, wherein the plurality of candidate triggers correspond to state-to-state transitions identified by analyzing a software representation of a computer network, the software representation represents actions that can be taken on the computer network, and the software representation of the computer network was generated based on network configuration data and network policy data that specify access rights; and

processing one or more candidate triggers of the plurality of candidate triggers to generate detection signature instances, wherein each of the one or more candidate triggers are processed by:

selecting a respective candidate trigger of the one or more candidate triggers;

identifying a corresponding detection signature template;

duplicating the corresponding detection signature template; and

modifying the duplicate detection signature template to form a respective detection signature.

18. The computing system of claim 17 , wherein the network configuration data specifies access rights allocated to respective groups and the network policy data specifies comprises a set of access rights for group members to access network resources.

19. The computing system of claim 17 , wherein the software representation comprises a source code representation or an executable compiled from the source code representation and represents a plurality of states and transitions between states.

20. The computing system of claim 17 , wherein at least one detection signature corresponding to an individual candidate trigger comprises a first detection signature instance for deployment at a first location, a second detection signature instance corresponding to the same individual candidate trigger comprises a second detection signature instance for deployment at a second location, and the first detection signature instance is different from the second detection signature instance.

21. The computing system of claim 17 , wherein the respective detection signature corresponding to an individual candidate trigger comprises a first set of conditions and a second set of conditions, wherein satisfaction of either the first set of conditions or the second set of conditions triggers output of a corresponding message.

22. The computing system of claim 21 , wherein the corresponding message for the first set of conditions is different from the corresponding message for the second set of conditions.

23. The computing system of claim 21 , wherein the first set of conditions are to be evaluated at a first location and the second set of conditions are to be evaluated at a second location different from the first location.

24. The computing system of claim 23 , wherein the first and second locations comprise two or more of on a network, at a source, at a destination or endpoint, or at an authentication service.

Assignments (2)
SECURITY INTEREST Recorded Oct 29, 2024
From: VECTRA AI, INC.
To: AB PRIVATE CREDIT INVESTORS LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 069061/0588 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 1, 2022
From: BEAUCHESNE, NICOLAS; KAZEROUNIAN, SOHROB; FINLAYSON IV, WILLIAM STOW; LYNN, KARL MATTHEW
To: VECTRA AI, INC.
Reel/Frame 059478/0072 →
Continuity (1)
Related Publication 20230318845A1 · Oct 5, 2023
References Cited (62)
US 6651099B1 · Dietz et al. · 2003 [cited by applicant]
US 7305383B1 · Kubesh et al. · 2007 [cited by applicant]
US 8272061B1 · Lotem et al. · 2012 [cited by applicant]
US 9432394B1 · Lahiri et al. · 2016 [cited by applicant]
US 10148685B2 · Hassanzadeh et al. · 2018 [cited by applicant]
US 20030051026A1 · Carter et al. · 2003 [cited by applicant]
US 20030188189A1 · Desai · 2003 [cited by examiner]
US 20080044018A1 · Scrimsher et al. · 2008 [cited by applicant]
US 20130097125A1 · Marvasti et al. · 2013 [cited by applicant]
US 20130283360A1 · Hui et al. · 2013 [cited by applicant]
US 20130340083A1 · Petrica et al. · 2013 [cited by applicant]
US 20140279808A1 · Strassner · 2014 [cited by applicant]
US 20150033340A1 · Giokas · 2015 [cited by applicant]
US 20160301704A1 · Hassanzadeh et al. · 2016 [cited by applicant]
US 20170161498A1 · Yavo · 2017 [cited by applicant]
US 20190109872A1 · Dhakshinamoorthy et al. · 2019 [cited by applicant]
US 20200022003A1 · Bizzarri et al. · 2020 [cited by applicant]
US 20200028861A1 · Pritzkau et al. · 2020 [cited by applicant]
US 20200177618A1 · Hassanzadeh et al. · 2020 [cited by applicant]
US 20200193031A1 · Avraham et al. · 2020 [cited by applicant]
US 20200304534A1 · Rakesh et al. · 2020 [cited by applicant]
US 20210194924A1 · Heinemeyer · 2021 [cited by examiner]
US 20210243208A1 · Rubin et al. · 2021 [cited by applicant]
US 20210243226A1 · El Gamal · 2021 [cited by examiner]
US 20210248443A1 · Shu et al. · 2021 [cited by applicant]
US 20210336971A1 · Robbins et al. · 2021 [cited by applicant]
US 20210352100A1 · Barai et al. · 2021 [cited by applicant]
US 20220014561A1 · Caceres et al. · 2022 [cited by applicant]
US 20220269591A1 · Mcshane et al. · 2022 [cited by applicant]
US 20220368702A1 · Robbins et al. · 2022 [cited by applicant]
US 20230050691A1 · Gu et al. · 2023 [cited by applicant]
US 20230262073A1 · Sheu · 2023 [cited by examiner]
CA 2926579 · 2016 [cited by applicant]
CN 105262771A · 2016 [cited by examiner]
CN 107277039 · 2017 [cited by applicant]
CN 111049827 · 2020 [cited by applicant]
EP 3726803 · 2020 [cited by applicant]
EP 4254865A1 · 2023 [cited by applicant]
EP 4254866A1 · 2023 [cited by applicant]
EP 4254867A2 · 2023 [cited by applicant]
EP 4254869A2 · 2023 [cited by applicant]
EP 4254868A3 · 2023 [cited by applicant]
WO WO2015013376A2 · 2015 [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191320.5 dated Sep. 28, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191322.1 dated Oct. 2, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191321.3 dated Oct. 2, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191317.1 dated Aug. 3, 2023. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 22191319.7 dated Aug. 17, 2023. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,884 dated Feb. 2, 2024. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,811 dated Feb. 15, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,868 dated Mar. 18, 2024. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,850 dated Mar. 27, 2024. [cited by applicant]
D. Kreutz, F. M. V. Ramos, P. E. Verfssimo, C. E. Rothenberg, S. Azodolmolky and S. Uhlig, “Software-Defined Networking: A Comprehensive Survey,” in Proceedings of the IEEE, vol. 103, No. 1, pp. 14-76 (Jan. 2015) (Year:… [cited by applicant]
Final Office Action for U.S. Appl. No. 17/711,884 dated May 23, 2024. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/711,811 dated Jul. 11, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,868 dated Aug. 23, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,868 dated Mar. 15, 2024. [cited by applicant]
Extended European Search Report for EP Patent Appln. No. 23199257.9 dated Mar. 6, 2024. [cited by applicant]
Final Office Action for U.S. Appl. No. 17/711,850 dated Oct. 24, 2024. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 17/711,811 dated Oct. 28, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,868 dated Oct. 28, 2024. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/711,884 dated Nov. 1, 2024. [cited by applicant]