IP Library › Granted Patent US 12,235,901
Granted Patent B2
US 12,235,901 · App. 18/649,017 · Granted Feb 25, 2025

Cyberattack detection using probabilistic graphical models

Inventors: Nitzan Niv (Nesher, IL); Gad Naor (Tel-Aviv, IL)
Assignee: Rapid7 Israel Technologies Ltd.
G06F16/9024G06F9/546G06N20/00G06Q30/0271H04L41/142H04L41/145H04L43/062H04L63/102H04L63/104H04L63/1416H04L63/1425H04L63/1441H04L67/30H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,235,901
App. No.
18/649,017
Granted
Feb 25, 2025
Kind
B2
Abstract

Various embodiments include systems and methods to implement a security platform providing cyberattack detection. The security platform may, with respect to a cloud compute environment, use audit log data that is associated with a particular domain of operational activity within the cloud compute environment. Based on multiple baseline profiles associated with the operational activity, the security platform may use a probabilistic graph to determine a behavioral anomaly. The security platform may, based on the behavioral anomaly, identify a cyberattack.

Claims (33)

1. A method for detecting cyberattacks using audit logs, the method comprising:

at least one processor to perform:

creating, using first audit log data, a probabilistic model of baseline operational activity within a cloud compute environment, the probabilistic model comprising a probabilistic graph having nodes and edges, the nodes representing factors associated with respective probability distributions and the edges representing probabilistic dependencies among the factors represented by the nodes;

updating the probabilistic model using second audit log data to obtain an updated probabilistic model;

determining, using third audit log data and the updated probabilistic model, a number of deviations of operational activity from the baseline operational activity; and

generating an alert indicative of the cyberattack when the number of deviations of operational activity is greater than a threshold value.

2. The method of claim 1 , wherein the probabilistic model comprises a Bayesian Belief Network.

3. The method of claim 1 , further comprising determining, using the third audit log data, one or more resources associated with the cyberattack.

4. The method of claim 1 , further comprising identifying credential data that has been compromised by the cyberattack.

5. The method of claim 1 , further comprising determining, using additional audit log data, one or more updates to the probabilistic graph.

6. The method of claim 1 , wherein the cyberattack comprises port scanning, endpoint scanning and/or DNS tunneling.

7. A system for detecting cyberattacks using audit logs, the system comprising:

one or more processors; and

a memory storing executable instructions that, when executed, cause the one or more processors to perform:

creating, using first audit log data, a probabilistic model of baseline operational activity within a cloud compute environment, the probabilistic model comprising a probabilistic graph having nodes and edges, the nodes representing factors associated with respective probability distributions and the edges representing probabilistic dependencies among the factors represented by the nodes;

updating the probabilistic model using second audit log data to obtain an updated probabilistic model;

determining, using third audit log data and the updated probabilistic model, a number of deviations of operational activity from the baseline operational activity; and

generating an alert indicative of the cyberattack when the number of deviations of operational activity is greater than a threshold value.

8. The system of claim 7 , wherein the probabilistic model comprises a Bayesian Belief Network.

9. The system of claim 7 , wherein the executable instructions, when executed, cause the one or more processors to perform determining, using the third audit log data, one or more resources associated with the cyberattack.

10. The system of claim 7 , wherein the executable instructions, when executed, cause the one or more processors to perform identifying credential data that has been compromised by the cyberattack.

11. The system of claim 7 , wherein the executable instructions, when executed, cause the one or more processors to perform determining, using additional audit log data, one or more updates to the probabilistic graph.

12. The system of claim 7 , wherein the cyberattack comprises port scanning, endpoint scanning and/or DNS tunneling.

13. A memory storing executable instructions that, when executed, cause at least one processor to perform a method for detecting cyberattacks using audit logs, the method comprising:

creating, using first audit log data, a probabilistic model of baseline operational activity within a cloud compute environment, the probabilistic model comprising a probabilistic graph having nodes and edges, the nodes representing factors associated with respective probability distributions and the edges representing probabilistic dependencies among the factors represented by the nodes;

updating the probabilistic model using second audit log data to obtain an updated probabilistic model;

determining, using third audit log data and the updated probabilistic model, a number of deviations of operational activity from the baseline operational activity; and

generating an alert indicative of the cyberattack when the number of deviations of operational activity is greater than a threshold value.

14. The memory of claim 13 , wherein the probabilistic model comprises a Bayesian Belief Network.

15. The memory of claim 13 , further comprising determining, using the third audit log data, one or more resources associated with the cyberattack.

16. The memory of claim 13 , further comprising identifying credential data that has been compromised by the cyberattack.

17. The memory of claim 13 , further comprising determining, using additional audit log data, one or more updates to the probabilistic graph.

18. The memory of claim 13 , wherein the cyberattack comprises port scanning, endpoint scanning and/or DNS tunneling.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 26, 2025
From: RAPID7 ISRAEL TECHNOLOGIES LTD.
To: INTSIGHTS CYBER INTELLIGENCE LTD.
Reel/Frame 072392/0183 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2025
From: NIV, NITZAN; NAOR, GAD
To: RAPID7, INC.
Reel/Frame 069806/0634 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 9, 2025
From: RAPID7, INC.
To: RAPID7 ISRAEL TECHNOLOGIES LTD.
Reel/Frame 069806/0796 →
Continuity (4)
Continuation 17979132 · Nov 2, 2022
Continuation In Part 17590221 · Feb 1, 2022
Continuation 16263322 · Jan 31, 2019
Related Publication 20240323202A1 · Sep 26, 2024
References Cited (17)
US 9516053B1 · Muddu · 2016 [cited by examiner]
US 11425149B2 · Niv et al. · 2022 [cited by applicant]
US 11818014B2 · Niv et al. · 2023 [cited by applicant]
US 20130305357A1 · Ayyagari et al. · 2013 [cited by applicant]
US 20160078365A1 · Baumard · 2016 [cited by applicant]
US 20160125304A1 · Pizurica et al. · 2016 [cited by applicant]
US 20170262325A1 · Liisberg · 2017 [cited by applicant]
US 20180047065A1 · Wildberger · 2018 [cited by applicant]
US 20190132344A1 · Lem · 2019 [cited by examiner]
US 20200057956A1 · Phan et al. · 2020 [cited by applicant]
US 20200195670A1 · Deardorff et al. · 2020 [cited by applicant]
US 20200252416A1 · Niv et al. · 2020 [cited by applicant]
US 20220159025A1 · Niv et al. · 2022 [cited by applicant]
US 20230388195A1 · Niv et al. · 2023 [cited by applicant]
Rienstra, Ranked Programming. Ranking Theory. Aug. 2018. 7 pages. [cited by applicant]
Scarfone et al., Guide to intrusion detection and prevention systems (idps). NIST special publication. Feb. 20, 2007;800(2007):94:1-127. [cited by applicant]
SPOHN et.al., A Survey of Ranking Theory. KOPS—Konstanzer Online Publications, 2009:185-228. [cited by applicant]