IP Library Granted Patent US 9,736,173
Granted Patent B2
US 9,736,173 · App. 14/879,876 · Granted Aug 15, 2017

Differential dependency tracking for attack forensics

Inventors: Zhichun Li (Princeton, NJ); Zhenyu Wu (Plainsboro, NJ); Zhiyun Qian (Franklin Park, NJ); Guofei Jiang (Princeton, NJ); Masoud Akhoondi (Princeton, NJ); Markus Kusano (Princeton, NJ)
Assignee: NEC Corporation
H04L63/1416G06F17/30958H04L63/1425H04L63/1441H04L2463/146
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,736,173
App. No.
14/879,876
Filed
Oct 9, 2015
Granted
Aug 15, 2017
Kind
B2
Art Unit
2438
USPC
726/23
Abstract

Methods and systems for intrusion attack recovery include monitoring two or more hosts in a network to generate audit logs of system events. One or more dependency graphs (DGraphs) is generated based on the audit logs. A relevancy score for each edge of the DGraphs is determined. Irrelevant events from the DGraphs are pruned to generate a condensed backtracking graph. An origin is located by backtracking from an attack detection point in the condensed backtracking graph.

Claims (24)

1. A computer-implemented method for intrusion attack recovery, comprising:

monitoring two or more hosts in a network to generate audit logs of system events;

generating one or more dependency graphs (DGraphs) based on the audit logs;

building a reference model, and determining a relevancy score for each of a plurality of edges of the DGraphs based on the reference model;

pruning irrelevant events from the DGraphs to generate a condensed backtracking graph based on the relevance score, the pruning comprising:

removing events from the DGraphs that are in paths exceeding a threshold length from an attack detection point, and

removing resources determined to be unrelated to an attack; and

backtracking from the attack detection point in the condensed backtracking graph to locate an origin.

2. The method of claim 1 , wherein pruning irrelevant events further comprises removing events from the DGraphs that do not lead to a relevant event in a path from the attack detection point.

3. The method of claim 1 , wherein pruning irrelevant events further comprises comparing events to a relevancy threshold.

4. The method of claim 3 , wherein pruning irrelevant events further comprises removing paths having no event that exceeds a relevancy threshold.

5. The method of claim 1 , wherein pruning irrelevant events further comprises removing events having an associated time that occurred after the attack detection point.

6. The method of claim 1 , wherein determining the relevancy score for each of a plurality of edges comprises performing a depth-limited search.

7. A system for intrusion attack recovery, comprising:

a remote host monitor configured to monitoring two or more hosts in a network to generate audit logs of system events and to generate one or more dependency graphs (DGraphs) based on the audit logs;

a relevance determiner comprising a memory coupled to a processor, the processor being configured to build a reference model, to determine a relevancy score for each of a plurality of edges of the DGraphs based on the reference model, and to for pruning irrelevant events from the DGraphs to generate a condensed backtracking graph based on the relevancy score, the pruning comprising:

removing events from the DGraphs that are in paths exceeding a threshold length from an attack detection point; and

removing resources determined to be unrelated to an attack; and

a backtracker configured to backtrack from the attack detection point in the condensed backtracking graph to locate an origin.

8. The system of claim 7 , wherein the relevance determiner is further configured to remove events from the DGraphs that do not lead to a relevant event in a path from the attack detection point.

9. The system of claim 7 , wherein the relevance determiner is further configured to compare events to a relevancy threshold.

10. The system of claim 9 , wherein the relevance determiner is further configured to remove paths having no event that exceeds a relevancy threshold.

11. The system of claim 7 , wherein the relevance determiner is further configured to remove events having an associated time that occurred after the attack detection point.

12. The system of claim 7 , wherein the relevance determiner is further configured to perform a depth-limited search.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2017
From: NEC LABORATORIES AMERICA, INC.
To: NEC CORPORATION
Reel/Frame 042864/0459 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 3, 2015
From: LI, ZHICHUN; WU, ZHENYU; QIAN, ZHIYUN; JIANG, GUOFEI; AKHOONDI, MASOUD; KUSANO, MARKUS
To: NEC LABORATORIES AMERICA, INC.
Reel/Frame 036948/0439 →
Continuity (2)
Provisional Application 62062298 · Oct 10, 2014
Related Publication 20160105454A1 · Apr 14, 2016