IP Library Granted Patent US 11,818,156
Granted Patent B1
US 11,818,156 · App. 18/066,724 · Granted Nov 14, 2023

Data lake-enabled security platform

Inventors: Jay Parikh (Redwood City, CA); Úlfar Erlingsson (Palo Alto, CA); Yijou Chen (Cupertino, CA)
Assignee: LACEWORK, INC.
H04L63/1425G06F9/455G06F9/545G06F16/9024G06F16/9038G06F16/9535G06F16/9537G06F21/57H04L43/045H04L43/06H04L63/10H04L67/306H04L67/535G06F16/2456
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,818,156
App. No.
18/066,724
Granted
Nov 14, 2023
Kind
B1
Abstract

Providing a data lake-enabled security platform, including: storing security data associated with a customer in a data lake comprising a plurality of storage environments implemented in different cloud environments of a plurality of cloud environments; generating, based on a plurality of records in the security data, an abstracted security record describing one or more derived insights of the security data; and providing access to the abstracted security record to one or more users associated with the customer.

Claims (26)

1. A method of providing a data lake-enabled security platform, the method comprising:

storing security data associated with a customer in a data lake comprising a plurality of storage environments implemented in different cloud environments;

generating, based on a plurality of records in the security data, an abstracted security record describing one or more insights derived from the security data, wherein generating the abstracted security record comprises processing, by a processing engine, portions of the security data to generate abstracted security records, wherein the processing engine generates the abstracted security records based on one or more customer-selected modules for generating abstracted security records, wherein the one or more customer-selected modules control how the plurality of records are generated into the abstracted security record; and

providing access to the abstracted security record in the data lake to one or more users associated with the customer.

2. The method of claim 1 , wherein the security data comprises a plurality of raw security records stored in a lower storage tier relative to the abstracted security record.

3. The method of claim 1 , wherein the security data comprises a plurality of raw security records stored across the plurality of storage environments.

4. The method of claim 1 , wherein the security data comprises a plurality of processed security records stored across the plurality of storage environments.

5. The method of claim 1 , wherein the abstracted security record is included in a plurality of abstracted security records stored across the plurality of storage environments.

6. The method of claim 1 , further comprising storing data associating the abstracted security record with the plurality of records.

7. The method of claim 1 , wherein generating the abstracted security record comprises allocating processing of at least a portion of the security data across the plurality of cloud environments.

8. The method of claim 7 , wherein allocating processing of the portion of the security data is based on one or more processing costs for the plurality of records.

9. The method of claim 7 , wherein allocating processing of the portion of the security data is based on current resource utilizations for the plurality of cloud environments.

10. The method of claim 1 , wherein the data lake provides a unified view of data stored across the plurality of cloud environments.

11. The method of claim 1 , wherein the plurality of records correspond to a plurality of instances of detected activity associated with the customer and wherein the abstracted security record describes the detected activity.

12. The method of claim 1 , wherein the plurality of records is associated with a particular event and wherein the abstracted security record describes the particular event.

13. The method of claim 12 , wherein the particular event comprises a detected anomaly.

14. The method of claim 12 , wherein the particular event comprises a detected security threat.

15. The method of claim 1 , wherein the plurality of records is associated with a particular event and wherein the abstracted security record comprises one or more suggested actions associated with the particular event occurring.

16. The method of claim 1 , wherein access to the abstracted security record is provided via one or more of a query language or an application program interface (API).

17. The method of claim 16 further comprising generating a polygraph.

18. A computer program product for a data lake-enabled security platform, the computer program product disposed on a non-transitory computer readable medium, the computer program product including computer program instructions configurable to carry out the steps of:

storing security data associated with a customer in a data lake comprising a plurality of storage environments implemented in different cloud environments of a plurality of cloud environments;

generating, based on a plurality of records in the security data, an abstracted security record describing one or more derived insights of the security data, wherein generating the abstracted security record comprises processing, by a processing engine, portions of the security data to generate abstracted security records, wherein the processing engine generates the abstracted security records based on one or more customer-selected modules for generating abstracted security records, wherein the one or more customer-selected modules control how the plurality of records are generated into the abstracted security record; and

providing access to the abstracted security record in the data lake to one or more users associated with the customer.

19. The computer program product of claim 18 , wherein the security data comprises a plurality of raw security records stored in a lower storage tier relative to the abstracted security record.

20. The computer program product of claim 18 , wherein the security data comprises a plurality of raw security records stored across the plurality of storage environments.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069113/0745 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2022
From: PARIKH, JAY; ERLINGSSON, ÚLFAR; CHEN, YIJOU
To: LACEWORK, INC.
Reel/Frame 062109/0065 →
Continuity (8)
Continuation In Part 17671056 · Feb 14, 2022
Continuation In Part 17504311 · Oct 18, 2021
Continuation 16665961 · Oct 28, 2019
Continuation 16134794 · Sep 18, 2018
Provisional Application 63424405 · Nov 10, 2022
Provisional Application 63243013 · Sep 10, 2021
Provisional Application 62650971 · Mar 30, 2018
Provisional Application 62590986 · Nov 27, 2017
Cited By (27)
US 12,190,161 US 12,192,235 US 12,200,137 US 12,212,543 US 12,231,510 US 12,255,929 US 12,271,757 US 12,278,875 US 12,292,991 US 12,301,683 US 12,309,237 US 12,411,974 US 12,417,822 US 12,423,150 US 12,432,218 US 12,489,799 US 12,505,409 US 12,519,867 US 12,530,661 US 12,531,934 US 12,596,814 US 12,598,204 US 12,608,732 US 12,645,794 US 12,665,803 US 12,675,773 US 12,689,549