IP Library Patent Application 18207061
Patent Application
App. No. 18/207,061

Unifying of the network device entity and the user entity for better cyber security modeling along with ingesting firewall rules to determine pathways through a network

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/207,061
Abstract

A device linking service can unify data streams from different sources of access into a network to get a composite picture of a behavior of an individual physical network device that has different device identifiers from the different sources of access into the network via cross-referencing information from the different sources of access into the network. The device linking service creates a unified network device identifier for the different device identifiers from the different sources of access into the network. The device linking service supplies the unified network device identifier and associated information with the different device identifiers from the different sources of access into the network to a prediction engine. The prediction engine runs a simulation of attack paths for the network that a cyber threat may take.

Claims (47)

1 . An apparatus, comprising:

a device linking service configured to unify data streams from different sources of access into a network to get a composite picture of a behavior of an individual physical network device that has different device identifiers from the different sources of access into the network via cross-referencing information from the different sources of access into the network, where the device linking service is configured to create a unified network device identifier for the different device identifiers from the different sources of access into the network, where the device linking service is configured to supply the unified network device identifier and associated information with the different device identifiers from the different sources of access into the network to a prediction engine, where the prediction engine is configured to run a simulation of attack paths for the network that a cyber threat may take, and where any instructions for the device linking service and the prediction engine are stored in an executable format on one or more non-transitory computer readable mediums, which are executable by one or more processors.

2 . The apparatus of claim 1 ,

where the device linking service is configured to create a meta entity identifier from the unified network device identifier and one or more user identifiers associated with the different device identifiers from the different sources of access into the network,

where the device linking service is configured to supply the meta entity identifier and associated information to a cyber security appliance configured to detect the cyber threat in the network, and

where the cyber security appliance is configured to use the meta entity identifier and information associated with the unified network device identifier and the one or more user identifiers associated with the different device identifiers to create multiple models of a pattern of life for the meta entity identifier in order to detect the cyber threat.

3 . The apparatus of claim 2 , where the cyber security appliance is configured to have an autonomous response module to autonomously respond to mitigate the cyber threat as well as to cooperate with the prediction engine in order to determine how to properly autonomously respond to a cyber attack by the cyber threat based upon simulations run in the prediction engine modelling the attack paths into and through the network.

4 . The apparatus of claim 1 ,

where the device linking service is configured to cooperate with a firewall configuration ingester and the prediction engine,

where the prediction engine is configured to monitor traffic into the network in order to map all of the paths into and through the network taken by the monitored traffic,

where the firewall configuration ingester is configured to ingest firewall rules to determine theoretically possible paths through the network in accordance with the firewall rules and a mapping of nodes of the network, and

where the prediction engine is configured to combine all of the paths into and through the network taken by the monitored traffic with the possible paths through the network theoretically possible in accordance with the firewall rules from the firewall configuration ingester in light of the unified network device identifier with a user entity in the network from the device linking service to determine possible attack paths when running the simulation of attack paths for the network that the cyber threat may take.

5 . The apparatus of claim 1 , where the device linking service is configured to passively monitor the data streams from different sources having access into the network as well as to actively query third party platforms to gather and ingest device data, user data, and activity data from multiple third party vendors and then analyze the ingested data, and then pass the ingested data into the prediction engine to perform the simulation of attack paths for the network that the cyber threat may take.

6 . The apparatus of claim 1 , where the device linking service is configured to maintain data from the data streams in their generic format as well as put relevant data into a uniform analysis format in a central data store via translation and mapping and then using the central data store to store the relevant data for the uniform analysis format.

7 . The apparatus of claim 1 , where the device linking service is configured to 1) apply at least one of string matching and fuzzy logic to cross-reference information from the different sources of access into the network as well as 2) use a central data store to store data points organized by how the data points relate to another data point.

8 . The apparatus of claim 1 , where the device linking service is configured to aggregate network presence information about a user of the network and their different user accounts on different third-party applications served from third-party platforms external to the network, who is then also associated with this particular individual physical network device.

9 . The apparatus of claim 1 , further comprising:

a firewall configuration ingester configured to cooperate with the device linking service, where the firewall configuration ingester is configured to examine rules of firewall configurations and their settings to model changes in these rules over time to detect unusual rules over time to the firewall configurations that cause new attack path modelling routes into the network.

10 . The apparatus of claim 1 , further comprising:

a firewall configuration ingester configured to cooperate with the device linking service and the prediction engine, where the firewall configuration ingester is configured to examine firewall rules implemented by a firewall to identify routes into the network allowed by a current firewall rules and supply the prediction engine with a set of possible routes that a cyber attack by the cyber threat may take into the network and permitted reasons into the network.

11 . A non-transitory computer readable medium configured to store instructions in an executable format in the non-transitory computer readable medium, which when executed by one or more processors cause operations, comprising:

providing a device linking service to unify data streams from different sources of access into a network to get a composite picture of a behavior of an individual physical network device that has different device identifiers from the different sources of access into the network via cross-referencing information from the different sources of access into the network,

providing the device linking service to create a unified network device identifier for the different device identifiers from the different sources of access into the network,

providing the device linking service to then link the unified network device identifier with a user in the network, and

providing the device linking service to supply the unified network device identifier and associated information with the different device identifiers from the different sources of access into the network to a prediction engine, where the prediction engine is configured to run a simulation of attack paths for the network that a cyber threat may take.

12 . The non-transitory computer readable medium of claim 11 , further comprising:

providing the device linking service to create a meta entity identifier from the unified network device identifier and one or more user identifiers associated with the different device identifiers from the different sources of access into the network,

providing the device linking service to supply the meta entity identifier and associated information to a cyber security appliance configured to detect the cyber threat in the network, and

providing the cyber security appliance to use the meta entity identifier and information associated with the unified network device identifier and the one or more user identifiers associated with the different device identifiers to create multiple models of a pattern of life for the meta entity identifier in order to detect the cyber threat.

13 . The non-transitory computer readable medium of claim 12 , further comprising:

providing the cyber security appliance to have an autonomous response module to autonomously respond to mitigate the cyber threat as well as to cooperate with the prediction engine in order to determine how to properly autonomously respond to a cyber attack by the cyber threat based upon simulations run in the prediction engine modelling the attack paths into and through the network.

14 . The non-transitory computer readable medium of claim 11 , further comprising:

providing the prediction engine to monitor traffic into the network in order to map all of the paths into and through the network taken by the monitored traffic,

providing a firewall configuration ingester to ingest firewall rules to determine theoretically possible paths through the network in accordance with the firewall rules and a mapping of nodes of the network, and

providing the prediction engine to combine all of the paths into and through the network taken by the monitored traffic with the possible paths through the network theoretically possible in accordance with the firewall rules from the firewall configuration ingester in light of the unified network device identifier with a user entity in the network from the device linking service to determine possible attack paths when running the simulation of attack paths for the network that the cyber threat may take.

15 . The non-transitory computer readable medium of claim 11 , further comprising:

providing the device linking service to passively monitor the data streams from different sources having access into the network as well as to actively query third party platforms to gather and ingest device data, user data, and activity data from multiple third party vendors and then analyze the ingested data, and then pass the ingested data into the prediction engine to perform the simulation of attack paths for the network that the cyber threat may take.

16 . The non-transitory computer readable medium of claim 11 , further comprising:

providing the device linking service to maintain data from the data streams in their generic format as well as put relevant data into a uniform analysis format in a central data store via translation and mapping and then using the central data store to store the relevant data for the uniform analysis format.

17 . The non-transitory computer readable medium of claim 11 , further comprising:

providing the device linking service to 1) apply at least one of string matching and fuzzy logic to cross-reference information from the different sources of access into the network as well as 2) use a central data store to store data points organized by how the data points relate to another data point.

18 . The non-transitory computer readable medium of claim 11 , further comprising:

providing the device linking service to aggregate network presence information about the user of the network and their different user accounts on different third-party applications served from third-party platforms external to the network, who is then also associated with this particular individual physical network device.

19 . The non-transitory computer readable medium of claim 11 , further comprising:

providing a firewall configuration ingester to examine rules of firewall configurations and their settings to model changes in these rules over time to detect unusual rules over time to the firewall configurations that cause new attack path modelling routes into the network.

20 . The non-transitory computer readable medium of claim 11 , further comprising:

providing a firewall configuration ingester to examine firewall rules implemented by a firewall to identify routes into the network allowed by a current firewall rules and supply the prediction engine with a set of possible routes that a cyber attack by the cyber threat may take into the network and permitted reasons into the network.

Assignments (4)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2024
From: LAL, JAKE; HOWLETT, GUY; THOMSON, ALEXANDER FOX; WINGAR, JAMES REES; WOODFORD, ANDREW
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 066563/0551 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2023
From: THOMSON, ALEXANDER FOX; WINGAR, JAMES REES
To: DARKTRACE HOLDINGS LIMITED
Reel/Frame 063887/0825 →