IP Library Granted Patent US 12,657,302
Granted Patent B2
US 12,657,302 · App. 18/183,783 · Granted Jun 16, 2026

Latent-context alert correlation engine in a security management system

Inventors: Daniel Davraev (Or Yehuda, IL); Tamer Salman (Haifa, IL); Ram Haim Pliskin (Rishon Lezion, IL)
Assignee: Microsoft Technology Licensing, LLC
G06F21/57G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,657,302
App. No.
18/183,783
Filed
Mar 14, 2023
Granted
Jun 16, 2026
Kind
B2
Examiner
LIU, ZHE
Art Unit
2493
USPC
726/1
Abstract

Methods, systems, and computer storage media for providing security incident management using a latent-context alert correlation engine in a security management system. Security incident management is provided using the latent-context alert correlation engine that is operationally integrated into the security management system. In operation, first security data of a first alert and second security data of a second alert are accessed. The first alert and the second alert do not share a common entity identifiable in a security graph. Using the first security data and the second security data, a determination is made that the first alert is connected to the second alert based on a latent-context connection. The latent-context connection is a known attack path connection that indirectly connects alerts. Based on determining that the first alert is connected to the second alert, a security incident is generated for the alert. A notification comprising the security incident is communicated.

Claims (62)

1 . A computerized system comprising:

one or more computer processors;

computer memory storing computer-useable instructions that, when used by the one or more computer processors, cause the one or more computer processors to perform operations, the operations comprising:

accessing first security data of a first alert and second security data of a second alert, wherein the first alert and the second alert are associated with a computing environment;

determining that the first alert is not connected to the second alert based on the first alert and the second alert not having a common entity identified in a security graph;

using the first security data, the second security data, and a latent-context alert correlation graph model associated with an attack path definitions engine that supports identifying latent-context connections between alerts with correlations in the security graph, determining that the first alert is connected to the second alert based on a latent-context connection,

wherein the latent-context connection is a derived attack-path-based connection that maps security data in a latent-context alert correlation graph associated with the latent-context alert correlation graph model, wherein the derived attack-path-based connection is identified based on a plurality of known attack objects associated with a type of attack on the computing environment,

wherein the latent-context alert correlation graph model graphs security data for alerts without correlations based on the security graph and security graph data,

wherein the latent-context connections are based on latent-context connection types include one or more of: permission, installation, and subscription,

wherein the latent-context connection types are not entity associations in the security graph,

based on determining that the first alert is connected to the second alert, generating a security incident associated with the first alert and the second alert;

receiving a request for a security posture of the computing environment; and

communicating a security posture visualization associated with the computing environment, wherein the security posture visualization comprises the security incident.

2 . The system of claim 1 , wherein the attack path definitions engine is associated with a latent-context alert correlation engine that supports identifying a plurality of latent-context connections based on a plurality of attack path definitions associated with historical alerts, wherein the plurality of latent-context connections are associated with the latent-context alert correlation graph model.

3 . The system of claim 1 , wherein the security posture visualization is associated with a notification, the security posture visualization comprising a first plurality of alerts that are not associated with security incidents and a second plurality of alerts that are associated with security incidents, wherein the first plurality of alerts and the second plurality of alerts are provided in the security posture visualization based on corresponding inference scores.

4 . The system of claim 1 , the operations further comprising accessing latent-context connection data associated with the first alert or the second alert, wherein the latent-context connection data is associated with the latent-context alert correlation graph model, wherein the latent-context alert correlation graph model indicates types of latent-context connection data to be retrieved for the first alert or the second alert.

5 . The system of claim 1 , the operations further comprising generating the latent-context alert correlation graph based on the first security data and the second security data, wherein the latent-context alert correlation graph comprises a first node associated with the first alert and a second node associated with the second alert, the first node is connected to the second node via the latent-context connection.

6 . The system of claim 1 , wherein a security incident management engine comprises a security graph Application Programming Interface (API) that is associated with a plurality of alerts from security providers, wherein a first set of alerts are associated with a first security incident; and wherein a second set of alerts are not associated with a second security incident, the second set of alerts comprising the first alert and the second alert.

7 . The system of claim 1 , further comprising a security incident management engine that supports generating the security posture visualization comprising the security incident, wherein the security incident comprises one or more latent-context connections between the first alert and the second alert.

8 . The system of claim 1 , wherein the security incident is associated with a remediation action, wherein the remediation action is executable to address a security threat associated with the security incident.

9 . The system of claim 1 , the operations further comprising:

communicating, from a security management client, the request for the security posture of the computing environment;

based on the request, receiving the security posture visualization associated with the computing environment, wherein the security posture visualization comprises comprising the security incident; and

causing display of the security posture visualization.

10 . The system of claim 1 , the operations further comprising:

accessing a plurality of attack path definitions;

based on the plurality of attack path definitions, identifying a plurality of latent-context connections for the latent-context alert correlation graph model; and

deploying the latent-context alert correlation graph model to support identifying latent-context connections between a plurality of alerts.

11 . One or more computer-storage media having computer-executable instructions embodied thereon that, when executed by a computing system having a processor and memory, cause the processor to perform operations, the operations comprising:

accessing first security data of a first alert and second security data of a second alert, wherein the first alert and the second alert are not connected based on the first alert and the second alert not having a common entity identified in a security graph;

using the first security data, the second security data, and a latent-context alert correlation graph model associated with an attack definitions engine that supports identifying latent-context connections between alert without correlations in the security graph, determining that the first alert is connected to the second alert based on a latent-context connection, wherein the latent-context connection is a derived attack-path-based connection that maps security data in a latent-context alert correlation graph associated with the latent-context alert correlation graph model,

wherein the derived attack-path-based connection is identified based on a plurality of known attack objects associated with a type of attack on a computing environment,

wherein the latent-context alert correlation graph model graphs security data for alerts without correlations based on the security graph and security graph data,

wherein the latent-context connections are based on latent-context connection types include one or more of: permission, installation, and subscription,

wherein the latent-context connection types are not entity associations in the security graph; and

based on determining that the first alert is connected to the second alert, generating a security incident associated with the first alert and the second alert; and

communicating a notification comprising the security incident.

12 . The media of claim 11 , the operations further comprising accessing latent-context connection data associated with the first alert or the second alert, wherein the latent-context connection data is associated with the latent-context alert correlation graph model, wherein the latent-context alert correlation graph model indicates types of latent-context connection data to be retrieved for the first alert or the second alert.

13 . The media of claim 11 , the operations further comprising generating the latent-context alert correlation graph based on the first security data and the second security data, wherein the latent-context alert correlation graph comprises a first node associated with the first alert and a second node associated with the second alert, the first node is connected to the second node via the latent-context connection.

14 . The media of claim 11 , wherein the notification is associated with a security posture visualization comprising a first plurality of alerts that are not associated with security incidents and a second plurality of alerts that are associated with security incidents, wherein the first plurality of alerts and the second plurality of alerts are provided in the security posture visualization based on corresponding inference scores.

15 . The media of claim 11 , the operations further comprising:

accessing a plurality of attack path definitions;

based on the plurality of attack path definitions, identifying a plurality of latent-context connections for the latent-context alert correlation graph model; and

deploying the latent-context alert correlation graph model to support identifying latent-context connections between a plurality of alerts.

16 . A computer-implemented method, the method comprising:

accessing first security data of a first alert and second security data of a second alert, wherein the first alert and the second alert are not connected based on the first alert and the second alert not having a common entity identified in a security graph, wherein the first alert and the second alert are associated with a computing environment;

using the first security data, the second security data, and a latent-context alert correlation graph model associated with an attack path definitions engine that supports identifying laten-context connections between alerts without correlations in the security graph, determining that the first alert is connected to the second alert based on a latent-context connection,

wherein the latent-context connection is a derived attack-path-based connection that maps security data in a latent-context alert correlation graph associated with the latent-context alert correlation graph model,

wherein the derived attack-path-based connection is identified based on a plurality of known attack objects associated with a type of attack on the computing environment,

wherein the latent-context alert correlation graph model graphs security data for alerts without correlations based on the security graph and security graph data,

wherein the latent-context connections are based on latent-context connection types include one or more of: permission, installation, and subscription,

wherein the latent-context connection types are not entity associations in the security graph; and

based on determining that the first alert is connected to the second alert, generating a security incident associated with the first alert and the second alert.

17 . The method of claim 16 , the method further comprising accessing latent-context connection data associated with the first alert or the second alert, wherein the latent-context connection data is associated with the latent-context alert correlation graph model, wherein the latent-context alert correlation graph model indicates types of latent-context connection data to be retrieved for the first alert or the second alert.

18 . The method of claim 16 , the method further comprising generating the latent-context alert correlation graph based on the first security data and the second security data, wherein the latent-context alert correlation graph comprises a first node associated with the first alert and a second node associated with the second alert, the first node is connected to the second node via the latent-context connection.

19 . The method of claim 16 , the method further comprising:

receiving a request for a security posture of the computing environment; and

communicating a security posture visualization associated with the computing environment, wherein the security posture visualization comprises a first plurality of alerts that are not associated with security incidents and a second plurality of alerts that are associated with security incidents, wherein the first plurality of alerts and the second plurality of alerts are provided in the security posture visualization based on corresponding inference scores.

20 . The method of claim 16 , the method further comprising:

accessing a plurality of attack path definitions;

based on the plurality of attack path definitions, identifying a plurality of latent-context connections for the latent-context alert correlation graph model; and

deploying the latent-context alert correlation graph model to support identifying latent-context connections between a plurality of alerts.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2023
From: DAVRAEV, DANIEL; PLISKIN, RAM HAIM; SALMAN, TAMER
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 063109/0059 →
Continuity (1)
Related Publication 20240311483A1 · Sep 19, 2024
References Cited (16)
US 10530796B2 · Patterson · 2020 [cited by examiner]
US 10742667B1 · Stern · 2020 [cited by examiner]
US 20160301704A1 · Hassanzadeh · 2016 [cited by examiner]
US 20170288974A1 · Yoshihira · 2017 [cited by examiner]
US 20170288979A1 · Yoshihira · 2017 [cited by examiner]
US 20180234310A1 · Ingalls · 2018 [cited by examiner]
US 20190379684A1 · Brown · 2019 [cited by examiner]
US 20200322361A1 · Ravindra · 2020 [cited by examiner]
US 20210081539A1 · Karin · 2021 [cited by applicant]
US 20210352095A1 · Cam · 2021 [cited by examiner]
US 20230017839A1 · Mizushima · 2023 [cited by examiner]
US 20230087267A1 · Shi · 2023 [cited by examiner]
US 20240070291A1 · Lee · 2024 [cited by examiner]
International Search Report and Written Opinion received for PCT Application No. PCT/US2024/018582, Jun. 13, 2024, 18 pages. [cited by applicant]
Johnson, et al., “What is Microsoft Intelligent Security Graph? 1 TechTarget,” Retrieved from the Internet: URL:https://www.techtarget.com/searchenterprisedesktop/opinion/What-is-Microsoft-Intelligent-Security-Graph, Ja… [cited by applicant]
International Preliminary Report on Patentability (Chapter I) received for PCT Application No. PCT/US2024/018582, mailed on Sep. 25, 2025, 12 pages. [cited by applicant]