IP Library Granted Patent US 12,401,671
Granted Patent B1
US 12,401,671 · App. 18/159,484 · Granted Aug 26, 2025

Managing analytic results in a cybersecurity system

Inventor: Alan D. Ross (Hingham, MA)
Assignee: Cisco Technology, Inc.
H04L63/1425H04L63/1416H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,671
App. No.
18/159,484
Filed
Jan 25, 2023
Granted
Aug 26, 2025
Kind
B1
Art Unit
2408
USPC
726/23
Abstract

In a computer-implemented method for managing analytic results in a cybersecurity system, data representing a plurality of events are accessed, where the plurality of events include machine data generated by entities that are part of or that interact with a computer network. A cybersecurity analytic of a cybersecurity application is applied to the data to produce analytic results, wherein the cybersecurity analytic is to detect a cybersecurity-related anomaly or threat. A performance of the cybersecurity analytic is then evaluated by applying the analytic results to a specified performance criterion. A corrective action for the cybersecurity analytic is then determined, based on a result of evaluating the performance of the cybersecurity analytic. Zero or more anomaly or threat detections by the cybersecurity analytic are then incorporated into an output of the cybersecurity application, based on the determined corrective action.

Claims (49)

1. A computer-implemented method comprising:

accessing, by a first computer system, data representing a plurality of events, the plurality of events including machine data generated by a plurality of entities that are part of or that interact with a computer network;

applying, by the first computer system, a cybersecurity analytic of a cybersecurity application to the data to produce a plurality of analytic results, wherein the cybersecurity analytic is to detect a cybersecurity-related anomaly or threat;

evaluating, by the first computer system, a performance of the cybersecurity analytic by at least determining whether a number of anomaly or threat detections produced by the cybersecurity analytic for a specified time interval exceeds a first threshold or falls below a second threshold different from the first threshold;

determining, by the first computer system, a corrective action for the cybersecurity analytic, based on a result of the evaluating the performance of the cybersecurity analytic;

incorporating, by the first computer system, zero or more anomaly or threat detections by the cybersecurity analytic into an output of the cybersecurity application, based on the determined corrective action, wherein the output is to be sent to an external user computer system; and

providing the output of the cybersecurity application to the external user computer system.

2. The method as recited in claim 1 , wherein the corrective action comprises throttling operability of the cybersecurity analytic by a prescribed factor to prevent some of the anomaly or threat detections produced by the cybersecurity analytic from being included in the output of the cybersecurity application when the number of anomaly or threat detections exceeds the second threshold and falls below the first threshold.

3. The method as recited in claim 1 , wherein the corrective action comprises preventing a specified percentage or portion of all anomaly or threat detections produced by the cybersecurity analytic for a particular time interval from being included in the output of the cybersecurity application when the number of anomaly or threat detections exceeds the second threshold and falls below the first threshold.

4. The method as recited in claim 1 , wherein the corrective action comprises disabling the cybersecurity analytic when the number of anomaly or threat detections exceeds the first threshold.

5. The method as recited in claim 1 , wherein the corrective action comprises throttling operability of the cybersecurity analytic by (i) a first prescribed factor to reduce the number of anomaly or threat detections produced by the cybersecurity analytic from being included in the output of the cybersecurity application when the number of anomaly or threat detections exceeds a third threshold greater than the second threshold and less than the first threshold and (ii) a second prescribed factor less than the first prescribed factor to reduce, by a lesser amount, the number of anomaly or threat detections produced by the cybersecurity analytic when the number of anomaly or threat detections falls below the third threshold and is greater than the second threshold.

6. The method as recited in claim 1 , wherein the evaluating comprises applying the number of anomaly or threat detections output by the cybersecurity analytic for a specified time interval to a range of thresholds including the first threshold to denote a number of anomaly or threat detections beyond a normal or expected range that could make the cybersecurity analytics unreliable and the second threshold to denote a number of anomaly or threat detections below the normal or expected range in which the cybersecurity analytics is ineffective.

7. The method as recited in claim 1 , wherein the evaluating comprises:

applying the number of anomaly or threat detections output by the cybersecurity analytic for a specified time interval to the first threshold; and

determining that the cybersecurity analytic is overfiring if the number of anomaly or threat detections output by the cybersecurity analytic for the specified time interval is above the first threshold.

8. The method as recited in claim 1 , wherein the evaluating comprises:

applying a number of anomaly or threat detections output by the cybersecurity analytic for a specified time interval to the second threshold; and

determining that the cybersecurity analytic is underperforming if the number of anomaly or threat detections output by the cybersecurity analytic for the specified time interval is below the second threshold.

9. The method as recited in claim 1 , wherein the evaluating comprises:

applying the number of anomaly or threat detections output by the cybersecurity analytic for a specified time interval to the first threshold and the second threshold; and

determining that the cybersecurity analytic is overfiring if the number of anomaly or threat detections output by the cybersecurity analytic for the specified time interval is above the first threshold, or that the cybersecurity analytic is underperforming if the number of anomaly or threat detections output by the cybersecurity analytic for the specified time interval is below the second threshold.

10. The method as recited in claim 1 , wherein the data representing the plurality of events are received by the first computer system from the external user computer system prior to the accessing of the data representing the plurality of events, and wherein the first computer system is a cloud-based computer system and the user computer system is an on-premises computer system.

11. The method as recited in claim 1 , wherein the evaluating comprises applying a random sampling of analytic results produced by the cybersecurity analytic to the first threshold and the second threshold.

12. The method as recited in claim 1 , wherein the evaluating is performed by a machine learning runtime.

13. The method as recited in claim 1 , further comprising:

executing the applying, the evaluating, the determining and the incorporating, for each of a plurality of cybersecurity analytics, including determining a separate corrective action for each of the plurality of cybersecurity analytics, wherein each of the plurality of cybersecurity analytics is to detect a different type of cybersecurity-related anomaly or threat.

14. A computer system comprising:

a processor; and

a non-transitory computer-readable medium having stored thereon instructions, execution of which by the processor causes the computer system to perform operations including:

accessing data representing a plurality of events, the plurality of events including machine data generated by a plurality of entities that are part of or that interact with a computer network;

applying a cybersecurity analytic of a cybersecurity application to the data to produce a plurality of analytic results, wherein the cybersecurity analytic is to detect a cybersecurity-related anomaly or threat;

evaluating a performance of the cybersecurity analytic by at least determining whether a number of anomaly or threat detections produced by the cybersecurity analytic for a specified time interval exceeds a first threshold or falls below a second threshold different from the first threshold;

determining a corrective action for the cybersecurity analytic, based on a result of the evaluating the performance of the cybersecurity analytic;

incorporating zero or more anomaly or threat detections by the cybersecurity analytic into an output of the cybersecurity application, based on the determined corrective action, wherein the output is to be sent to an external user computer system; and

providing the output of the cybersecurity application to the external user computer system.

15. The computer system as recited in claim 14 , wherein the corrective action comprises throttling operability of the cybersecurity analytic by a prescribed factor to prevent some of the anomaly or threat detections produced by the cybersecurity analytic from being included in the output of the cybersecurity application when the number of anomaly or threat detections exceeds the second threshold and falls below the first threshold.

16. The computer system as recited in claim 14 , wherein the corrective action comprises disabling the cybersecurity analytic when the number of anomaly or threat detections exceeds the first threshold.

17. The computer system as recited in claim 14 , wherein the corrective action comprises throttling operability of the cybersecurity analytic by (i) a first prescribed factor to reduce the number of anomaly or threat detections produced by the cybersecurity analytic from being included in the output of the cybersecurity application when the number of anomaly or threat detections exceeds a third threshold greater than the second threshold and less than the first threshold and (ii) a second prescribed factor less than the first prescribed factor to reduce, by a lesser amount, the number of anomaly or threat detections produced by the cybersecurity analytic when the number of anomaly or threat detections falls below the third threshold and is greater than the second threshold.

18. A non-transitory computer-readable medium having stored therein instructions, execution of which by one or more processors causes the one or more processors to perform operations including:

accessing data representing a plurality of events, the plurality of events including machine data generated by a plurality of entities that are part of or that interact with a computer network;

applying a cybersecurity analytic of a cybersecurity application to the data to produce a plurality of analytic results, wherein the cybersecurity analytic is to detect a cybersecurity-related anomaly or threat;

evaluating a performance of the cybersecurity analytic by at least determining whether a number of anomaly or threat detections produced by the cybersecurity analytic for a specified time interval exceeds a first threshold or falls below a second threshold different from the first threshold;

determining a corrective action for the cybersecurity analytic, based on a result of the evaluating the performance of the cybersecurity analytic;

incorporating zero or more anomaly or threat detections by the cybersecurity analytic into an output of the cybersecurity application, based on the determined corrective action, wherein the output is to be sent to an external user computer system; and

providing the output of the cybersecurity application to the external user computer system.

19. The non-transitory computer-readable medium as recited in claim 18 , wherein the corrective action comprises at least one of:

preventing some anomaly or threat detections produced by the cybersecurity analytic from being included in the output of the cybersecurity application when the number of anomaly or threat detections exceeds the second threshold and falls below the first threshold; or

disabling the cybersecurity analytic when the number of anomaly or threat detections exceeds the first threshold.

20. The non-transitory computer-readable medium as recited in claim 19 , wherein the evaluating comprises applying the number of anomaly or threat detections output by the cybersecurity analytic for the specified time interval to the second threshold and determining that the cybersecurity analytic is underperforming if the number of anomaly or threat detections output by the cybersecurity falls below the second threshold.

Assignments (3)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2023
From: ROSS, ALAN D.
To: SPLUNK INC.
Reel/Frame 062486/0900 →
References Cited (25)
US 7937344B2 · Baum et al. · 2011 [cited by applicant]
US 8112425B2 · Baum et al. · 2012 [cited by applicant]
US 8751529B2 · Zhang et al. · 2014 [cited by applicant]
US 8788525B2 · Neels et al. · 2014 [cited by applicant]
US 9215240B2 · Merza et al. · 2015 [cited by applicant]
US 9286413B1 · Coates et al. · 2016 [cited by applicant]
US 10127258B2 · Lamas et al. · 2018 [cited by applicant]
US 10158653B1 · Magcale · 2018 [cited by examiner]
US 11150976B1 · Marwah · 2021 [cited by examiner]
US 20130326620A1 · Merza · 2013 [cited by examiner]
US 20190098106A1 · Mungel et al. · 2019 [cited by applicant]
US 20200382547A1 · Basballe Sorensen · 2020 [cited by examiner]
US 20210026961A1 · Underwood · 2021 [cited by examiner]
US 20210329089A1 · Yellin · 2021 [cited by examiner]
US 20220086179A1 · Levin · 2022 [cited by examiner]
US 20220201010A1 · Tarsauliya · 2022 [cited by examiner]
US 20220224711A1 · Singh · 2022 [cited by examiner]
US 20230068946A1 · McCarthy · 2023 [cited by examiner]
US 20230262077A1 · Palmer · 2023 [cited by examiner]
US 20240080344A1 · Francesco · 2024 [cited by examiner]
Splunk Enterprise 8.0.0 Overview, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Cloud 8.0.2004 User Manual, available online, retrieved May 20, 2020 from docs.splunk.com. [cited by applicant]
Splunk Quick Reference Guide, updated 2019, available online at https://www.splunk.com/pdfs/solution-guides/splunk-quick-reference-guide.pdf, retrieved May 20, 2020. [cited by applicant]
Carraso, David, “Exploring Splunk,” published by CITO Research, New York, NY, Apr. 2012. [cited by applicant]
Bitincka, Ledion et al., “Optimizing Data Analysis with a Semi-structured Time Series Database,” self-published, first presented at “Workshop on Managing Systems via Log Analysis and Machine Learning Techniques (SLAML)”… [cited by applicant]
Cited By (1)
US 12,568,111