IP Library Granted Patent US 12,206,696
Granted Patent B1
US 12,206,696 · App. 18/140,394 · Granted Jan 21, 2025

Detecting anomalies in a network environment

Inventors: Vikram Kapoor (Cupertino, CA); Samuel Joseph Pullara, III (Los Altos, CA); Murat Bog (Fremont, CA); Yijou Chen (Cupertino, CA); Sanjay Kalra (San Jose, CA)
Assignee: Fortinet, Inc.
H04L63/1425G06F9/455G06F9/545G06F16/2456G06F16/9024G06F16/9038G06F16/9535G06F16/9537G06F21/57H04L43/045H04L43/06H04L63/10H04L67/306H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,206,696
App. No.
18/140,394
Filed
Apr 27, 2023
Granted
Jan 21, 2025
Kind
B1
Art Unit
2442
USPC
709/224
Abstract

Activities within a network environment are monitored (e.g., using agents). At least a portion of the monitored activities are used to generate a logical graph model. The generated logical graph model is used to determine an anomaly. The detected anomaly is recorded and can be used to generate an alert.

Claims (43)

1. A method comprising:

monitoring activities within a network environment;

generating a logical graph model using at least a portion of the monitored activities, the logical graph model comprising a set of nodes representative of logical entities in the network environment and a set of edges representative of behavioral relationships between nodes interconnected by the edges;

identifying a new process with a process identifier; and

using the generated logical graph model to detect an anomaly in the network environment, wherein the anomaly is detected based on a change to the set of nodes of the logical graph model, the change to the set of nodes comprising an addition of a new node to the set of nodes, wherein the new node represents the new process that is identified with the process identifier and is executing in the network environment.

2. The method of claim 1 , further comprising generating an alert based on the detected anomaly.

3. The method of claim 1 , further comprising:

determining whether the new process in a current time period is a descendant of a login process; and

creating a record to be stored in a login descendant table if the new process is the descendant of the login process.

4. The method of claim 1 , wherein the new node represents a new type of process including at least one of a client process, a server process, a child process, or a login process executing in the network environment.

5. The method of claim 1 , wherein the change to the set of nodes further comprises a change to an attribute of a node in the set of nodes.

6. The method of claim 5 , wherein the change to the attribute of the node represents a change in type of a process executing in the network environment.

7. The method of claim 1 , wherein the logical graph model is a cumulative model of how processes in the network environment behave over time.

8. A computer program product embodied in a non-transitory computer-readable storage medium and comprising computer instructions for:

monitoring activities within a network environment;

generating a logical graph model using at least a portion of the monitored activities, the logical graph model comprising a set of nodes representative of logical entities in the network environment and a set of edges representative of behavioral relationships between nodes interconnected by the edges;

identifying a new process with a process identifier; and

using the generated logical graph model to detect an anomaly in the network environment, wherein the anomaly is detected based on a change to the set of nodes of the logical graph model, the change to the set of nodes comprising an addition of a new node to the set of nodes, wherein the new node represents the new process that is identified with the process identifier and is executing in the network environment.

9. The computer program product of claim 8 , further comprising computer instructions for generating an alert based on the detected anomaly.

10. The computer program product of claim 8 , further comprising:

determining whether the new process in a current time period is a descendant of a login process; and

creating a record to be stored in a login descendant table if the new process is the descendant of the login process.

11. The computer program product of claim 8 , wherein the new node represents a new type of process executing in the network environment.

12. The computer program product of claim 8 , wherein the change to the set of nodes further comprises a change to an attribute of a node in the set of nodes.

13. The computer program product of claim 12 , wherein the change to the attribute of the node represents a change in type of a process executing in the network environment.

14. The computer program product of claim 8 , wherein the logical graph model is a cumulative model of how processes in the network environment behave over time.

15. A method comprising:

monitoring activities within a network environment;

generating a logical graph model using at least a portion of the monitored activities, the logical graph model comprising a set of nodes and a set of edges representative of user connections to resources of the network environment, wherein the set of nodes comprises a node representative of a user identity;

identifying a new process with a process identifier; and

using the generated logical graph model to detect an anomaly in the network environment, wherein the anomaly is detected based on a change to the set of nodes of the logical graph model, the change to the set of nodes comprising an addition of a new node to the set of nodes, wherein the new node represents the new process that is identified with the process identifier and is executing in the network environment.

16. The method of claim 15 , further comprising generating an alert based on the detected anomaly.

17. The method of claim 15 , wherein the anomaly is detected based on an addition of an edge to the set of edges of the logical graph model.

18. The method of claim 15 , wherein the anomaly is detected based on a change to the logical graph model indicative of at least one of:

a user login from a new Internet Protocol (IP) address;

the user login to a new machine class;

the user launch of a process not previously launched by the user; or

the user connection to a server to which the user has not previously connected.

19. The method of claim 15 , wherein the logical graph model represents a chain of connections of a user to different types of computing resources of the network environment.

20. A computer program product embodied in a non-transitory computer-readable storage medium and comprising computer instructions for:

monitoring activities within a network environment;

generating a logical graph model using at least a portion of the monitored activities, the logical graph model comprising a set of nodes and a set of edges representative of user connections to resources of the network environment, wherein the set of nodes comprises a node representative of a user identity; and

using the generated logical graph model to detect an anomaly in the network environment, wherein the anomaly is detected based on a change to the set of nodes of the logical graph model, the change to the set of nodes comprising an addition of a new node to the set of nodes, wherein the new node represents a new process that is identified with a process identifier and is executing in the network environment.

Assignments (2)
MERGER Recorded Oct 7, 2024
From: LACEWORK, INC.
To: FORTINET, INC.
Reel/Frame 069269/0377 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 27, 2023
From: KAPOOR, VIKRAM; PULLARA, SAMUEL JOSEPH, III; BOG, MURAT; CHEN, YIJOU; KALRA, SANJAY
To: LACEWORK, INC.
Reel/Frame 063467/0479 →