IP Library Granted Patent US 10,050,985
Granted Patent B2
US 10,050,985 · App. 14/930,368 · Granted Aug 14, 2018

System for implementing threat detection using threat and risk assessment of asset-actor interactions

Inventors: Himanshu Mhatre (Mountain View, CA); David Lopes Pegna (San Carlos, CA); Oliver Brdiczka (Mountain View, CA)
Assignee: Vectra Networks, Inc.
H04L63/1425G06F11/00G06F12/14G06F21/552H04L63/1416G06F21/566G06F21/6245H04L67/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,050,985
App. No.
14/930,368
Granted
Aug 14, 2018
Kind
B2
Abstract

Disclosed is an approach to detect insider threats, by tracking unusual access activity for a specific user or computer with regard to accessing key assets over time. In this way, malicious activity and the different preparation phases of attacks can be identified.

Claims (42)

1. A method for performing threat detection in a network comprising:

monitoring, by a network security device, communications traffic in the network; and

implementing a threat detection system on the network security device, wherein the threat detection system performs the steps of:

constructing a predictive model using metadata extracted from the communications traffic, wherein the predictive model is constructed by identifying data for a key asset, generating a dataspace representation for the key asset relative to an actor in the network, and clustering data within the dataspace representation, wherein the predictive model is constructed using at least one of ensemble-based estimation over k-means, Gaussian mixture models, or other statistic estimators;

analyzing behaviors in the network relative to the predictive model; and

reporting a threat if abnormal behavior is identified.

2. The method of claim 1 , wherein the predictive model corresponds to a given time period.

3. The method of claim 1 , wherein a threshold threat level is established relative to the predictive model, and activity that falls outside the threshold threat level is identifiable as the threat.

4. The method of claim 3 , in which the threshold threat level corresponds to a radius surrounding a centroid of a cluster formed within a dataspace representation.

5. The method of claim 1 , wherein evaluation metrics are employed to analyze the behaviors in the network, and the evaluation metrics corresponds to at least one of z-scores based on variances estimated from mixture models, mean absolute deviation, and distance from centroids of clusters.

6. The method of claim 1 , further comprising analysis of relative risks and impacts of possible threats.

7. The method of claim 6 , wherein a plurality of threshold threat levels are established relative to different predictive models.

8. The method of claim 1 , wherein (near) real time monitoring is performed to check for the abnormal behavior.

9. A computer program product embodied on a non-transitory computer readable medium, the non-transitory computer readable medium having stored thereon a sequence of instructions which, when executed by a processor causes the processor to execute a method for performing a process to perform threat detection in a network, the process comprising:

monitoring, by a network security device, communications traffic in the network;

constructing a predictive model using metadata extracted from the communications traffic, wherein the predictive model is constructed by identifying data for a key asset, generating a dataspace representation for the key asset relative to an actor in the network, and clustering data within the dataspace representation, wherein the predictive model is constructed using at least one of ensemble-based estimation over k-means, Gaussian mixture models, or other statistic estimators;

analyzing behaviors in the network relative to the predictive model; and

reporting a threat if abnormal behavior is identified.

10. The computer program product of claim 9 , wherein the predictive model corresponds to a given time period.

11. The computer program product of claim 9 , wherein a threshold threat level is established relative to the predictive model, and activity that falls outside the threshold threat level is identifiable as the threat.

12. The computer program product of claim 11 , in which the threshold threat level corresponds to a radius surrounding a centroid of a cluster formed within a dataspace plot.

13. The computer program product of claim 9 , wherein evaluation metrics are employed analyze the behaviors in the network, and the evaluation metrics corresponds to at least one of z-scores based on variances estimated from mixture models, mean absolute deviation, and distance from centroids of clusters.

14. The computer program product of claim 9 , further comprising analysis of relative risks and impacts of possible threats.

15. The computer program product of claim 14 , wherein a plurality of threshold threat levels are established relative to different predictive models.

16. The computer program product of claim 9 , wherein (near) real time monitoring is performed to check for the abnormal behavior.

17. A system, comprising:

a computer processor to execute a set of program code instructions;

a memory to hold the program code instructions, in which the program code instructions comprises program code to perform:

monitoring, by a network security device, communications traffic in a network;

constructing a predictive model using metadata extracted from the communications traffic, wherein the predictive model is constructed by identifying data for a key asset, generating a dataspace representation for the key asset relative to an actor in the network, and clustering data within the dataspace representation, wherein the predictive model is constructed using at least one of ensemble-based estimation over k-means, Gaussian mixture models, or other statistic estimators;

analyzing behaviors in the network relative to the predictive model; and

reporting a threat if abnormal behavior is identified.

18. The system of claim 17 , wherein the predictive model corresponds to a given time period.

19. The system of claim 17 , wherein a threshold threat level is established relative to the predictive model, and activity that falls outside the threshold threat level is identifiable as the threat.

20. The system of claim 19 , in which the threshold threat level corresponds to a radius surrounding a centroid of a cluster formed within a dataspace plot.

21. The system of claim 17 , wherein evaluation metrics are employed analyze the behaviors in the network, and the evaluation metrics corresponds to at least one of z-scores based on variances estimated from mixture models, mean absolute deviation, and distance from centroids of clusters.

22. The system of claim 17 , wherein the program code instructions further comprises program code to perform analysis of relative risks and impacts of possible threats.

23. The system of claim 22 , wherein a plurality of threshold threat levels are established relative to different predictive models.

24. The system of claim 17 , wherein the program code instructions further comprises program code to perform (near) real time monitoring to check for the abnormal behavior.

25. The method of claim 1 , wherein the step of monitoring by the network security device further comprises monitoring network packets, the network security device receiving the network packets from a network infrastructure having network equipment.

26. The method of claim 25 , wherein the networking equipment comprises a router or a switch.

27. The method of claim 25 , wherein the network security device is implemented as software on a dedicated hardware device.

Assignments (7)
SECURITY INTEREST Recorded Oct 29, 2024
From: VECTRA AI, INC.
To: AB PRIVATE CREDIT INVESTORS LLC, AS ADMINISTRATIVE AGENT
Reel/Frame 069061/0588 →
CHANGE OF NAME Recorded Sep 23, 2024
From: VECTRA NETWORKS, INC.
To: VECTRA AI, INC.
Reel/Frame 069020/0149 →
RELEASE OF SECURITY INTEREST Recorded Mar 19, 2021
From: SILVER LAKE WATERMAN FUND, L.P., AS AGENT
To: VECTRA AI, INC.
Reel/Frame 055656/0351 →
CHANGE OF NAME Recorded Nov 4, 2019
From: VECTRA NETWORKS, INC.
To: VECTRA AI, INC.
Reel/Frame 050925/0991 →
SECURITY INTEREST Recorded Mar 13, 2019
From: VECTRA AI, INC.
To: SILVER LAKE WATERMAN FUND, L.P., AS AGENT
Reel/Frame 048591/0071 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2017
From: BRDICZKA, OLIVER
To: VECTRA NETWORKS, INC.
Reel/Frame 043772/0161 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 12, 2017
From: MHATRE, HIMANSHU; PEGNA, DAVID LOPES
To: VECTRA NETWORKS, INC.
Reel/Frame 040970/0226 →
Continuity (2)
Provisional Application 62074602 · Nov 3, 2014
Related Publication 20160191559A1 · Jun 30, 2016
Cited By (1)
US 12,652,300