IP Library Granted Patent US 11,831,668
Granted Patent B1
US 11,831,668 · App. 17/965,617 · Granted Nov 28, 2023

Using a logical graph to model activity in a network environment

Inventors: Harish Kumar Bharat Singh (Pleasanton, CA); Vikram Kapoor (Cupertino, CA)
Assignee: Lacework Inc.
H04L63/1425G06F9/45558G06N3/006H04L63/1416G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,831,668
App. No.
17/965,617
Granted
Nov 28, 2023
Kind
B1
Abstract

A data platform receives data associated with activities in an environment, generates a logical graph using at least a portion of the received data, at least in part by clustering multiple nodes into a node of the logical graph based at least in part on behaviors in the network environment, and provides data representing a portion of the logical graph to a computer, the data representing the portion of the logical graph configured to be processed by the computer to display a visualization of the portion of the logical graph. The data platform may provide the data to the computer in response to receiving a query from the computer. The data platform may use the logical graph to detect an anomaly in the environment.

Claims (35)

1. A method, comprising:

receiving, by a data platform executed by at least one processor, data associated with a network environment;

generating, by the data platform, a logical graph using at least a portion of the received data, at least in part by clustering multiple nodes into a single node of the logical graph based at least in part on behaviors in the network environment; and

providing, by the data platform, data representing a portion of the logical graph to a computer, the data representing the portion of the logical graph configured to be processed by the computer to display a visualization of the portion of the logical graph.

2. The method of claim 1 , wherein the single node represents the multiple nodes in the logical graph.

3. The method of claim 1 , wherein the generated logical graph comprises a plurality of vertical tiers of clusters.

4. The method of claim 1 , wherein the generated logical graph comprises a plurality of horizontal tiers.

5. The method of claim 1 , wherein generating the logical graph includes clustering multiple nodes representing a plurality of namespaces into a single node based on launching behaviors of the namespaces.

6. The method of claim 1 , wherein generating the logical graph includes clustering multiple nodes representing a plurality of pods into a single node based at least in part on launching behaviors of the pods.

7. The method of claim 1 , wherein generating the logical graph includes clustering multiple nodes representing a plurality of pods into a single node based at least in part on which namespaces launch the pods.

8. The method of claim 1 , further comprising:

receiving, by the data platform, a query from the computer; and

identifying, by the data platform, the portion of the logical graph based on the query;

wherein providing the data representing the portion of the logical graph to the computer is performed in response to the query.

9. The method of claim 1 , further comprising:

detecting, by the data platform and based on the logical graph, an anomaly in the network environment.

10. A computer program product embodied in a non-transitory tangible computer readable storage medium and comprising computer instructions for:

receiving data associated with a container environment;

generating a logical graph using at least a portion of the received data, at least in part by clustering multiple items into a single node of the logical graph based at least in part on behaviors in the container environment; and

providing data representing a portion of the logical graph to a computer, the data representing the portion of the logical graph configured to be processed by the computer to display a visualization of the portion of the logical graph.

11. The computer program product of claim 10 , wherein the single node represents the multiple items in the logical graph.

12. The computer program product of claim 10 , wherein the generated logical graph comprises a plurality of vertical tiers of clusters.

13. The computer program product of claim 10 , wherein the generated logical graph comprises a plurality of horizontal tiers.

14. The computer program product of claim 10 , wherein generating the logical graph includes clustering multiple nodes representing a plurality of namespaces into a single node based on launching behaviors of the namespaces.

15. The computer program product of claim 10 , wherein generating the logical graph includes clustering multiple nodes representing a plurality of pods into a single node based at least in part on launching behaviors of the pods.

16. The computer program product of claim 10 , wherein generating the logical graph includes clustering multiple nodes representing a plurality of pods into a single node based at least in part on which namespaces launch the pods.

17. A system, comprising:

a memory storing instructions; and

a processor coupled to the memory and configured to execute the instructions to:

receive data associated with activities in a network environment;

generate a logical graph using at least a portion of the received data, at least in part by clustering multiple items into a node of the logical graph based at least in part on behaviors in the network environment; and

provide data representing a portion of the logical graph to a computer, the data representing the portion of the logical graph configured to be processed by the computer to display a visualization of the portion of the logical graph.

18. The system of claim 17 , wherein the node represents the multiple items in the logical graph.

19. The system of claim 17 , wherein the generated logical graph comprises a plurality of vertical tiers of clusters.

20. The system of claim 17 , wherein the generated logical graph comprises a plurality of horizontal tiers.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069113/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 13, 2022
From: SINGH, HARISH KUMAR BHARAT; KAPOOR, VIKRAM
To: LACEWORK, INC.
Reel/Frame 061417/0872 →