SECURITY GRAPH FOR MONITORING A COMPUTE ENVIRONMENT
A method is disclosed. The method comprises receiving data from a plurality of entities within a compute environment, generating a security graph including a plurality of nodes representing the entities and a plurality of edges interconnecting the nodes to represent relationships between the entities and displaying the security graph via a user interface.
1 . A method comprising:
receiving data from a plurality of entities within a compute environment;
generating a security graph including a plurality of nodes representing the entities and a plurality of edges interconnecting the nodes to represent relationships between the entities; and
displaying the security graph via a user interface.
2 . The method of claim 1 , further comprising:
executing a query on the received data;
generating query results; and
displaying the query results.
3 . The method of claim 2 , further comprising:
generating a second security graph based on the received data; and
displaying the second security graph.
4 . The method of claim 3 , wherein the second security graph provides a graphical context of the query results.
5 . The method of claim 1 , further comprising:
determining critical asset resources based on the received data;
filtering the critical asset resources from other asset resources; and
displaying the critical asset resources within the security graph.
6 . The method of claim 5 , further comprising applying one or more filters to elements of the security graph.
7 . The method of claim 2 , further comprising generating a list of sample queries to query the received data.
8 . The method of claim 7 , wherein the list of sample queries is generated based on at least one of the following: cross-customer data, trending queries, or security issues.
9 . A system comprising:
at least one physical memory device; and
one or more processors coupled with the at least one physical memory device to execute one or more instructions to:
receive data from a plurality of entities within a compute environment;
generate a security graph including a plurality of nodes representing the entities and a plurality of edges interconnecting the nodes to represent relationships between the entities; and
display the security graph via a user interface.
10 . The system of claim 9 , wherein the one or more processors further execute the one or more instructions to:
execute a query on the received data;
generate query results; and
display the query results.
11 . The system of claim 10 , wherein the one or more processors further execute the one or more instructions to:
generate a second security graph based on the collected data; and
display the second security graph.
12 . The system of claim 11 , wherein the second security graph provides a graphical context of the query results.
13 . The system of claim 9 , wherein the one or more processors further execute the one or more instructions to:
determine critical asset resources based on the received data;
filter the critical asset resources from other asset resources; and
display the critical asset resources within the security graph.
14 . The system of claim 13 , wherein the one or more processors further execute the one or more instructions to apply one or more filters to elements of the security graph.
15 . The system of claim 10 , wherein the one or more processors further execute the one or more instructions to generate a list of sample queries to query the received data.
16 . At least one non-transitory computer readable medium having instructions stored thereon, which when executed by one or more processors, cause the processors to:
receive data from a plurality of entities within a compute environment;
generate a security graph including a plurality of nodes representing the entities and a plurality of edges interconnecting the nodes to represent relationships between the entities; and
display the security graph via a user interface.
17 . The computer readable medium of claim 16 , having instructions stored thereon, which when executed by the one or more processors, further cause the processors to:
execute a query on the received data;
generate query results; and
display the query results.
18 . The computer readable medium of claim 17 , having instructions stored thereon, which when executed by the one or more processors, further cause the processors to:
generate a second security graph based on the collected data; and
display the second security graph.
19 . The computer readable medium of claim 18 , wherein the second security graph provides a graphical context of the query results.
20 . The computer readable medium of claim 16 , having instructions stored thereon, which when executed by the one or more processors, further cause the processors to:
determine critical asset resources based on the received data;
filter the critical asset resources from other asset resources; and
display the critical asset resources within the security graph.