IP Library Granted Patent US 12,047,407
Granted Patent B2
US 12,047,407 · App. 18/228,982 · Granted Jul 23, 2024

Managing security actions in a computing environment based on movement of a security threat

Inventors: Sourabh Satish (Fremont, CA); Oliver Friedrichs (Woodside, CA); Atif Mahadik (Fremont, CA); Govind Salinas (Sunnyvale, CA)
Assignee: Splunk Inc.
H04L63/1441G06F16/285G06F21/554H04L63/0236H04L63/1416H04L63/1425H04L63/1433H04L63/20H04L47/2425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,047,407
App. No.
18/228,982
Granted
Jul 23, 2024
Kind
B2
Abstract

Systems, methods, and software described herein provide security actions based on the current state of a security threat. In one example, a method of operating an advisement system in a computing environment with a plurality of computing assets includes identifying a security threat within the computing environment. The method further includes, in response to identifying the security threat, obtaining state information for the security threat within the computing environment, and determining a current state for the security threat within the computing environment. The method also provides obtaining enrichment information for the security threat and determining one or more security actions for the security threat based on the enrichment information and the current state for the security threat.

Claims (46)

1. A computer-implemented method performed by an advisement system coupled to a computing environment, the computing environment comprising computing assets, the method comprising:

identifying a security threat involving the computing environment;

obtaining state information for the security threat;

determining, based on the state information, that the security threat comprises a malicious process in a lateral movement state in which the malicious process is attempting to move to other computing assets within the computing environment;

identifying a security action for responding to the security threat based on determining that the security threat comprises a malicious process in a lateral movement state;

translating the security action into a process to be implemented at a computing asset of the computing assets; and

initiating implementation of the security action at the computing asset.

2. The method of claim 1 , wherein determining, based on the state information, that the security threat comprises a malicious process in a lateral movement state comprises monitoring a number of connections between the computing assets in the computing environment.

3. The method of claim 1 , wherein determining, based on the state information, that the security threat comprises a malicious process in a lateral movement state comprises monitoring types of the computing assets that are communicating in the computing environment.

4. The method of claim 1 , wherein determining, based on the state information, that the security threat comprises a malicious process in a lateral movement state comprises monitoring a relation of internal connections to external connections by the security threat.

5. The method of claim 1 , further comprising obtaining enrichment information for the security threat from at least one internal or external database.

6. The method of claim 5 , wherein identifying the security action for responding to the security threat comprises:

identifying a rule set based on the enrichment information obtained for the security threat; and

identifying the security action associated with the rule set.

7. The method of claim 1 , wherein the security threat includes at least one of a virus or a malware attack.

8. A non-transitory computer-readable storage medium storing instructions that, when executed by one or more processors, cause performance of operations comprising:

identifying a security threat involving a computing environment, the computing environment comprising computing assets;

obtaining state information for the security threat;

determining, based on the state information, that the security threat comprises a malicious process in a lateral movement state in which the malicious process is attempting to move to other computing assets within the computing environment;

identifying a security action for responding to the security threat based on determining that the security threat comprises a malicious process in a lateral movement state;

translating the security action into a process to be implemented at a computing asset of the computing assets; and

initiating implementation of the security action at the computing asset.

9. The non-transitory computer-readable storage medium of claim 8 , wherein determining, based on the state information, that the security threat comprises a malicious process in a lateral movement state comprises monitoring a number of connections between the computing assets in the computing environment.

10. The non-transitory computer-readable storage medium of claim 8 , wherein determining, based on the state information, that the security threat comprises a malicious process in a lateral movement state comprises monitoring types of the computing assets that are communicating in the computing environment.

11. The non-transitory computer-readable storage medium of claim 8 , wherein determining, based on the state information, that the security threat comprises a malicious process in a lateral movement state comprises monitoring a relation of internal connections to external connections by the security threat.

12. The non-transitory computer-readable storage medium of claim 8 storing further instructions that, when executed by one or more processors, cause performance of further operations comprising obtaining enrichment information for the security threat from at least one internal or external database.

13. The non-transitory computer-readable storage medium of claim 12 , wherein identifying the security action for responding to the security threat comprises:

identifying a rule set based on the enrichment information obtained for the security threat; and

identifying the security action associated with the rule set.

14. The non-transitory computer-readable storage medium of claim 8 , wherein the security threat includes at least one of a virus or a malware attack.

15. A computing device, comprising:

one or more processors; and

a non-transitory computer-readable storage medium storing instructions that, when executed by the one or more processors, cause the computing device to:

identify a security threat involving a computing environment, the computing environment comprising computing assets;

obtain state information for the security threat;

determine, based on the state information, that the security threat comprises a malicious process in a lateral movement state in which the malicious process is attempting to move to other computing assets within the computing environment;

identify a security action for responding to the security threat based on determining that the security threat comprises a malicious process in a lateral movement state;

translate the security action into a process to be implemented at a computing asset of the computing assets; and

initiate implementation of the security action at the computing asset.

16. The computing device of claim 15 , wherein determining, based on the state information, that the security threat comprises a malicious process in a lateral movement state comprises monitoring a number of connections between the computing assets in the computing environment.

17. The computing device of claim 15 , wherein determining, based on the state information, that the security threat comprises a malicious process in a lateral movement state comprises monitoring types of the computing assets that are communicating in the computing environment.

18. The computing device of claim 15 , wherein determining, based on the state information, that the security threat comprises a malicious process in a lateral movement state comprises monitoring a relation of internal connections to external connections by the security threat.

19. The computing device of claim 15 , the non-transitory computer-readable storage medium storing further instructions that, when executed by the one or more processors, further cause the computing device to obtain enrichment information for the security threat from at least one internal or external database.

20. The computing device of claim 19 , wherein identifying the security action for responding to the security threat comprises:

identifying a rule set based on the enrichment information obtained for the security threat; and

identifying the security action associated with the rule set.

Assignments (4)
CHANGE OF NAME Recorded Jul 22, 2025
From: SPLUNK INC.
To: SPLUNK LLC
Reel/Frame 072170/0599 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 22, 2025
From: SPLUNK LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 072173/0058 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2023
From: SATISH, SOURABH; FRIEDRICHS, OLIVER; MAHADIK, ATIF; SALINAS, GOVIND
To: PHANTOM CYBER CORPORATION
Reel/Frame 064455/0282 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 1, 2023
From: PHANTOM CYBER CORPORATION
To: SPLUNK INC.
Reel/Frame 064455/0352 →
Continuity (9)
Continuation 17242165 · Apr 27, 2021
Continuation 16736120 · Jan 7, 2020
Continuation 16107979 · Aug 21, 2018
Continuation 15886183 · Feb 1, 2018
Continuation 14824262 · Aug 12, 2015
Provisional Application 62106830 · Jan 23, 2015
Provisional Application 62106837 · Jan 23, 2015
Provisional Application 62087025 · Dec 3, 2014
Related Publication 20230388338A1 · Nov 30, 2023
Cited By (1)
US 12,536,280