IP Library Granted Patent US 12,712,893
Granted Patent B2
US 12,712,893 · App. 18/755,297 · Granted Aug 18, 2026

Cybersecurity investigation tools utilizing information graphs

Inventors: Gabriel G. Infante-Lopez (Cordoba, AR); Hemang Satish Nadkarni (Cupertino, CA); Pablo Andres Michelis (San Jose, CA); Francisco Matias Cuenca-Acuna (Cordoba, AR); Matias L. Marenchino (Cordoba, AR); Maria Torino (Cordoba, AR)
Assignee: Musaruba US LLC
H04L63/1416G06F16/9024H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,712,893
App. No.
18/755,297
Filed
Jun 26, 2024
Granted
Aug 18, 2026
Kind
B2
Art Unit
2426
USPC
726/23
Abstract

Example apparatus disclosed herein iteratively link data from one or more cybersecurity tools based on a graph schema to generate an information graph. Disclosed example apparatus also cause presentation of a first pattern detected in the information graph. Disclosed example apparatus further update the information graph based on data from at least one of the cybersecurity tools, the at least one of the cybersecurity tools selected based on a second pattern, the second pattern associated with a known cyberattack technique.

Claims (50)

1 . An apparatus comprising:

interface circuitry;

computer readable instructions stored on a non-transitory computer readable medium; and

at least one processor circuit to be programmed by the computer readable instructions to:

iteratively link data from one or more cybersecurity tools based on a graph schema to generate an information graph;

cause presentation of a first pattern comprising of a first path detected in the information graph;

expand the first path detected in the information graph based on data from at least one of the cybersecurity tools, the at least one of the cybersecurity tools selected based on a second pattern comprising of a second path in the graph schema that corresponds to the first path detected in the information graph, the second pattern associated with a previously known cyberattack technique stored in a knowledge base; and

cause presentation of the expanded first path in the information graph.

2 . The apparatus of claim 1 , wherein the second pattern is a reference pattern associated with the known cyberattack technique, and the first pattern corresponds to at least a portion of the reference pattern.

3 . The apparatus of claim 2 , wherein one or more of the at least one processor circuit is to:

annotate the information graph based on user input; and

search the annotated information graph for an additional reference pattern, the additional reference pattern associated with an additional known cyberattack technique.

4 . The apparatus of claim 1 , wherein one or more of the at least one processor circuit is to select the at least one of the cybersecurity tools based on user input obtained after the presentation of the first pattern.

5 . The apparatus of claim 1 , wherein one or more of the at least one processor circuit is to output an inference corresponding to the first pattern, the inference associated with a confidence score.

6 . The apparatus of claim 5 , wherein one or more of the at least one processor circuit is to adjust the confidence score based on user input.

7 . The apparatus of claim 1 , wherein the graph schema is to specify relationships among the one or more cybersecurity tools, respective ones of the cybersecurity tools having respective input-output data relationships, the respective ones of the cybersecurity tools to specify respective procedures to obtain respective data that satisfies the respective input-output data relationships, and one or more of the at least one processor circuit is to:

detect an event associated with a computing device; and

initiate generation of the information graph based on a selected one of the cybersecurity tools that has an input-output relationship associated with the event.

8 . At least one non-transitory computer readable medium comprising computer readable instructions to cause at least one processor circuit to at least:

iteratively generate an information graph based on a graph schema and data from one or more of a plurality of cybersecurity tools;

after detection of a first pattern comprising of a first path in the information graph, select a cybersecurity tool from the plurality of cybersecurity tools based on a second pattern comprising of a second path in the graph schema that corresponds to the first path detected in the information graph, the second pattern associated with a previously known cyberattack technique stored in a knowledge base;

expand the first path detected in the information graph based on data from the selected cybersecurity tool; and

cause presentation of the expanded first path in the information graph.

9 . The at least one non-transitory computer readable medium of claim 8 , wherein the second pattern is a reference pattern associated with the known cyberattack technique, and the first pattern corresponds to at least a portion of the reference pattern.

10 . The at least one non-transitory computer readable medium of claim 9 , wherein the instructions are to cause one or more of the at least one processor circuit to:

annotate the information graph based on user input; and

search the annotated information graph for an additional reference pattern, the additional reference pattern associated respectively with an additional known cyberattack technique.

11 . The at least one non-transitory computer readable medium of claim 8 , wherein the instructions are to cause one or more of the at least one processor circuit to select the cybersecurity tool based on user input obtained after presentation of the first pattern.

12 . The at least one non-transitory computer readable medium of claim 8 , wherein the instructions are to cause one or more of the at least one processor circuit to output an inference corresponding to the first pattern, the inference associated with a confidence score.

13 . The at least one non-transitory computer readable medium of claim 12 , wherein the instructions are to cause one or more of the at least one processor circuit to adjust the confidence score based on user input.

14 . The at least one non-transitory computer readable medium of claim 8 , wherein the selected cybersecurity tool is a first cybersecurity tool, the graph schema is to specify relationships among the plurality of cybersecurity tools, respective ones of the cybersecurity tools having respective input-output data relationships, the respective ones of the cybersecurity tools to specify respective procedures to obtain respective data that satisfies the respective input-output data relationships, and one or more of the at least one processor circuit is to:

detect an event associated with a computing device;

select a second cybersecurity tool of the plurality of cybersecurity tools that has an input-output relationship associated with the event; and

initiate generation of the information graph based on the second cybersecurity tool.

15 . An apparatus comprising:

interface circuitry;

computer readable instructions stored on a non-transitory computer readable medium; and

at least one processor circuit to be programmed by the computer readable instructions to:

iteratively link data from one or more cybersecurity tools based on a graph schema to generate an information graph;

detect a first pattern comprising of a first path in the information graph;

detect a first one of the cybersecurity tools based on a second pattern comprising of a second path in the graph schema that corresponds to the first path detected in the information graph, the second pattern associated with a previously known cyberattack technique stored in a knowledge base;

expand the first path detected in the information graph based on data from the selected first one of the cybersecurity tools; and

cause presentation of the expanded first path in the information graph.

16 . The apparatus of claim 15 , wherein the second pattern is a reference pattern associated with the known cyberattack technique, and the first pattern corresponds to at least a portion of the reference pattern.

17 . The apparatus of claim 16 , wherein one or more of the at least one processor circuit is to:

annotate the information graph based on user input; and

search the annotated information graph for an additional reference pattern, the additional reference pattern associated with an additional known cyberattack technique.

18 . The apparatus of claim 15 , wherein one or more of the at least one processor circuit is to select the first one of the cybersecurity tools based on user input obtained after presentation of the first pattern.

19 . The apparatus of claim 15 , wherein one or more of the at least one processor circuit is to output an inference corresponding to the first pattern, the inference associated with a confidence score.

20 . The apparatus of claim 19 , wherein one or more of the at least one processor circuit is to adjust the confidence score based on user input.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2024
From: INFANTE-LOPEZ, GABRIEL G.; NADKARNI, HEMANG SATISH; MICHELIS, PABLO ANDRES; CUENCA-ACUNA, FRANCISCO MATIAS; MARENCHINO, MATIAS; TORINO, MARIA
To: MCAFEE, LLC
Reel/Frame 068349/0825 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 21, 2024
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 068730/0593 →
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
Continuity (3)
Continuation 17493364 · Oct 4, 2021
Continuation 16232296 · Dec 26, 2018
Related Publication 20240348628A1 · Oct 17, 2024
References Cited (20)
US 9117079B1 · Huang et al. · 2015 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9928365B1 · Anderson et al. · 2018 [cited by applicant]
US 10673880B1 · Pratt et al. · 2020 [cited by applicant]
US 11140179B1 · Infante-Lopez et al. · 2021 [cited by applicant]
US 12047395B2 · Infante-Lopez et al. · 2024 [cited by applicant]
US 20070209074A1 · Coffman · 2007 [cited by examiner]
US 20160285914A1 · Singh et al. · 2016 [cited by applicant]
US 20180046928A1 · Jang et al. · 2018 [cited by applicant]
US 20180219894A1 · Crabtree et al. · 2018 [cited by applicant]
US 20180329958A1 · Choudhury · 2018 [cited by examiner]
US 20200201989A1 · Shu et al. · 2020 [cited by applicant]
McAfee, “McAfee Investigator Product Guide,” 2018, 17 pages. [cited by applicant]
United States Patent and Trademark Office, “Non-Final Office Action” issued in connection with U.S. Appl. No. 16/232,296 on Jan. 25, 2021 (8 pages). [cited by applicant]
United States Patent and Trademark Office, “Notice of Allowance,” issued in connection with U.S. Appl. No. 16/232,296 on Jun. 1, 2021 (9 pages). [cited by applicant]
United States Patent and Trademark Office, “Non-Final Office Action,” issued in connection with U.S. Appl. No. 17/493,364, mailed on Sep. 8, 2023, 33 pages. [cited by applicant]
Baeldung, “Connecting to a Specific Schema in JDBC,” last updated Aug. 18, 2023, retrieved from <https://www.baeldung.com/jdbc-connect-to-schema> on Dec. 19, 2023. [cited by applicant]
IBM, “What is JDBC?,” IBM documentation, last updated on Sep. 3, 2021, retrieved from <https://www.ibm.com/docs/en/informix-servers/12.10?topic=started-what-is-jdbc> on Dec. 19, 2023. [cited by applicant]
United States Patent and Trademark Office, “Notice of Allowance and Fee(s) Due,” issued in connection with U.S. Appl. No. 17/493,364, dated Mar. 8, 2024, 10 pages. [cited by applicant]
McAfee,“McAfee Investigator: Transform Analysis into Expert Investigators,” May 2018, 4 pages. [cited by applicant]