IP Library › Granted Patent US 12,348,536
Granted Patent B1
US 12,348,536 · App. 18/203,256 · Granted Jul 1, 2025

Cloud integrated network security

Inventors: Sai Krishna Lakshminarayanan (Galway, IE); Gianni Tedesco (Seoul, KR); Morgan Nally (Galway, IE); Luke Coughlan (Galway, IE)
Assignee: Rapid7, Inc.
H04L63/1416H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,536
App. No.
18/203,256
Granted
Jul 1, 2025
Kind
B1
Abstract

Various embodiments include systems and methods pertaining to a security service platform that detects security threats based on a security service that operates on structurally deduplicated network data. The security service may operate within a cloud environment and perform the security analysis that includes compiling a ruleset to generate an executable, where the executable is run over the structurally deduplicated event data. If the executable identifies a rule match for a given portion of structurally deduplicated event data, then the security service platform may reconstruct the structurally deduplicated event data to access all portions of a network event associated with the structurally deduplicated event data that triggered the rule match. The security service platform may use the reconstructed event data to generate and provide an alert that indicates a detected cyberattack.

Claims (59)

1. A method comprising:

accessing, by one or more cloud services, structurally deduplicated data indicative of event data, wherein the deduplicated event data is structured in accordance with a data model comprising one or more fields;

determining, based on the structurally deduplicated data, a plurality of deduplicated field groups associated with one or more fields of the data model, wherein the plurality of deduplicated field groups are associated with a network event;

determining, based on one or more references from the deduplicated field groups to a plurality of deduplicated values, one or more values associated with the deduplicated field groups;

determining, based on a ruleset running on the deduplicated field groups and on the one or more values, whether a rule is indicative of a cyberattack;

determining, based on whether the rule is indicative of a cyberattack, to reconstruct a network event or to not reconstruct the network event; and

generating, based on determining to reconstruct the network event, an alert indicative of the network event.

2. The method of claim 1 , wherein the structurally deduplicated data is indicative of multiple data formats, wherein the multiple data formats are associated with a combination of: TLS events, DNS events, or flow events.

3. The method of claim 1 , wherein the structurally deduplicated data comprises:

a plurality of event references associated with event data, wherein the event data is structured in accordance with a data model comprising one or more fields;

a plurality of deduplicated field groups associated with one or more fields of the data model that include redundant data with other field group of the event data; and

a plurality of deduplicated values associated with one or more values in one or more fields of the event data that are redundant with one or more other values in one or more other fields of the event data.

4. The method of claim 1 , wherein more than one cyberattack attempt is determined based on a single rule matching a single instance of structurally deduplicated data.

5. The method of claim 1 , further comprising:

in response to the determining to reconstruct the network event:

reconstructing, based on the structurally deduplicated data comprising deduplicated event data, an instance of a network event associated with the cyberattack; and

determining, based on the instance of the network event, the one or more remediation operations;

wherein the alert is indicative of the one or more remediation operations.

6. The method of claim 1 , wherein event data included within the structurally deduplicated data comprises: a transport layer security (TLS) event; a domain name system (DNS) event; or a flow event.

7. The method of claim 1 , wherein a quantity of levels of the deduplicated field groups is based on a quantity of nesting levels of a data model representing a network event.

8. A system comprising:

a memory storing executable instructions; and

one or more processors that execute the executable instructions to:

access, by one or more cloud services, structurally deduplicated data indicative of event data, wherein the deduplicated event data is structured in accordance with a data model comprising one or more fields;

determine, based on the structurally deduplicated data, a plurality of deduplicated field groups associated with one or more fields of the data model, wherein the plurality of deduplicated field groups are associated with a network event;

determine, based on one or more references from the deduplicated field groups to a plurality of deduplicated values, one or more values associated with the deduplicated field groups;

determine, based on a ruleset running on the deduplicated field groups and on the one or more values, whether a rule is indicative of a cyberattack;

determine, based on whether the rule is indicative of a cyberattack, to reconstruct a network event or to not reconstruct the network event; and

generate, based on determining to reconstruct the network event, an alert indicative of the network event.

9. The system of claim 8 , wherein a format of the structurally deduplicated data is based on a structure of the data model.

10. The system of claim 9 , wherein a format of the structurally deduplicated data is based on:

determining one or more references from one or more of the plurality of event references to one or more of the deduplicated field groups; and

determining one or more second references from one or more of the deduplicated field groups to one or more of the plurality of deduplicated values.

11. The system of claim 10 , wherein the structurally deduplicated data is indicative of multiple data formats, wherein the multiple data formats are associated with a combination of: TLS events, DNS events, or flow events.

12. The system of claim 8 , wherein the structurally deduplicated data comprises:

a plurality of event references associated with event data, wherein the event data is structured in accordance with a data model comprising one or more fields;

a plurality of deduplicated field groups associated with one or more fields of the data model that include redundant data with other field group of the event data; and

a plurality of deduplicated values associated with one or more values in one or more fields of the event data that are redundant with one or more other values in one or more other fields of the event data.

13. The system of claim 8 , wherein event data included within the structurally deduplicated data comprises: a transport layer security (TLS) event; a domain name system (DNS) event; or a flow event.

14. The system of claim 8 , wherein a quantity of levels of the deduplicated field groups is based on a quantity of nesting levels of a data model representing a network event.

15. One or more non-transitory computer-accessible storage media storing executable instructions that, when executed by one or more processors, cause one or more computer systems to:

access, by one or more cloud services, structurally deduplicated data indicative of event data, wherein the deduplicated event data is structured in accordance with a data model comprising one or more fields;

determine, based on the structurally deduplicated data, a plurality of deduplicated field groups associated with one or more fields of the data model, wherein the plurality of deduplicated field groups are associated with a network event;

determine, based on one or more references from the deduplicated field groups to a plurality of deduplicated values, one or more values associated with the deduplicated field groups;

determine, based on a ruleset running on the deduplicated field groups and on the one or more values, whether a rule is indicative of a cyberattack;

determine, based on whether the rule is indicative of a cyberattack, to reconstruct a network event or to not reconstruct the network event; and

generate, based on determining to reconstruct the network event, an alert indicative of the network event.

16. The one or more non-transitory computer-accessible storage media of claim 15 , wherein the structurally deduplicated data is indicative of multiple data formats, wherein the multiple data formats are associated with a combination of: TLS events, DNS events, or flow events.

17. The one or more non-transitory computer-accessible storage media of claim 16 , wherein the structurally deduplicated data comprises:

a plurality of event references associated with event data, wherein the event data is structured in accordance with a data model comprising one or more fields;

a plurality of deduplicated field groups associated with one or more fields of the data model that include redundant data with other field group of the event data; and

a plurality of deduplicated values associated with one or more values in one or more fields of the event data that are redundant with one or more other values in one or more other fields of the event data.

18. The one or more non-transitory computer-accessible storage media of claim 15 , wherein the one or more processors, further cause one or more computer systems to:

in response to the determining to reconstruct the network event:

reconstruct, based on the structurally deduplicated data comprising deduplicated event data, an instance of a network event associated with the cyberattack; and

determine, based on the instance of the network event, the one or more remediation operations;

wherein the alert is indicative of the one or more remediation operations.

19. The one or more non-transitory computer-accessible storage media of claim 15 , wherein event data included within the structurally deduplicated data comprises: a transport layer security (TLS) event; a domain name system (DNS) event; or a flow event.

20. The one or more non-transitory computer-accessible storage media of claim 15 , wherein a quantity of levels of the deduplicated field groups is based on a quantity of nesting levels of a data model representing a network event.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2024
From: COUGHLAN, LUKE; TEDESCO, GIANNI; NALLY, MORGAN; LAKSHMINARAYANAN, SAI KRISHNA
To: RAPID7, INC.; RAPID7 IRELAND LIMITED; RAPID7 INTERNATIONAL LIMITED
Reel/Frame 068351/0471 →
References Cited (47)
US 7788722B1 · Njemanze · 2010 [cited by examiner]
US 8462781B2 · McGhee et al. · 2013 [cited by applicant]
US 9178902B1 · Zagorsky · 2015 [cited by examiner]
US 9654510B1 · Pillai · 2017 [cited by examiner]
US 9697355B1 · Park · 2017 [cited by examiner]
US 10091075B2 · Hegde et al. · 2018 [cited by applicant]
US 10205733B1 · Park · 2019 [cited by examiner]
US 10778610B2 · Levy et al. · 2020 [cited by applicant]
US 10795578B2 · Floyd et al. · 2020 [cited by applicant]
US 10803201B1 · Nicholls · 2020 [cited by examiner]
US 10868825B1 · Dominessy · 2020 [cited by examiner]
US 11184403B1 · Wu · 2021 [cited by examiner]
US 11336698B1 · Wu · 2022 [cited by examiner]
US 11379607B2 · Swafford · 2022 [cited by applicant]
US 11444871B1 · Nainar · 2022 [cited by examiner]
US 11457024B2 · Bindal · 2022 [cited by examiner]
US 11575712B2 · Kung et al. · 2023 [cited by applicant]
US 11694775B1 · Maier · 2023 [cited by examiner]
US 11818101B2 · Santuka · 2023 [cited by examiner]
US 20070226807A1 · Ginter · 2007 [cited by examiner]
US 20130312101A1 · Lotem · 2013 [cited by examiner]
US 20140046645A1 · White · 2014 [cited by examiner]
US 20170098087A1 · Li · 2017 [cited by examiner]
US 20170099311A1 · Kesin · 2017 [cited by examiner]
US 20170124351A1 · Scaiano · 2017 [cited by examiner]
US 20170195354A1 · Kesin · 2017 [cited by examiner]
US 20170214702A1 · Moscovici · 2017 [cited by examiner]
US 20170324768A1 · Crabtree · 2017 [cited by examiner]
US 20180013771A1 · Crabtree · 2018 [cited by examiner]
US 20180234435A1 · Cohen · 2018 [cited by examiner]
US 20180295154A1 · Crabtree · 2018 [cited by examiner]
US 20190007441A1 · Kesin · 2019 [cited by examiner]
US 20200045064A1 · Bindal · 2020 [cited by examiner]
US 20210105294A1 · Kruse · 2021 [cited by examiner]
US 20210112083A1 · Janakiraman · 2021 [cited by examiner]
US 20210293130A1 · Revheim · 2021 [cited by examiner]
US 20210320941A1 · e Silva · 2021 [cited by examiner]
US 20220078209A1 · V · 2022 [cited by examiner]
US 20220103594A1 · Galloway · 2022 [cited by examiner]
US 20220103597A1 · Gobena · 2022 [cited by examiner]
US 20220108402A1 · Jalal · 2022 [cited by examiner]
US 20220188733A1 · Wang · 2022 [cited by examiner]
US 20230114774A1 · Santuka · 2023 [cited by examiner]
US 20230230126A1 · Habibabadi · 2023 [cited by examiner]
US 20240070287A1 · Cooney · 2024 [cited by examiner]
US 20240095358A1 · Zhang · 2024 [cited by examiner]
US 20240143737A1 · Zamir · 2024 [cited by examiner]
Cited By (1)
US 12,744,836