IP Library Granted Patent US 10,262,133
Granted Patent B1
US 10,262,133 · App. 15/001,865 · Granted Apr 16, 2019

System and method for contextually analyzing potential cyber security threats

Inventors: Alon Cohen (Even Yehuda, IL); Amos Stern (Hod Hasharon, IL); Garry Fatakhov (Holon, IL)
Assignee: Cyarx Technologies Ltd.
G06F21/552H04L41/065H04L63/14G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,262,133
App. No.
15/001,865
Granted
Apr 16, 2019
Kind
B1
Abstract

A system and method for contextually analyzing potential cyber security threats. The method comprises receiving at least one event, wherein the at least one event is associated with at least one entity; parsing the at least one event; modeling, based on at least one modeling rule, the at least one parsed event to determine the at least one characteristic; and generating a graph based on the determined at least one characteristic, wherein the graph represents the relationships among the at least one entity.

Claims (48)

1. A method implemented by a computer for contextually analyzing potential cyber security threats in a computer network, comprising:

receiving at least one security event for the computer network, wherein the at least one security event is associated with at least one entity, wherein an entity is a computing arrangement coupled to the network and associated with an organization;

parsing the at least one security event;

modeling, based on at least one modeling rule selected from a set of a plurality of modeling rules, the at least one parsed security event, the modeling being such as to identify each of the at least one entity involved in an event, and to determine at least one characteristic of the at least one security event, the at least one characteristic including at least one relationship characteristic of relationships among each of the at least one entity identified as being involved in the event;

retrieving, based on the modeled events and by interfacing with external systems, enrichment information respective of the at least one characteristic;

enriching the determined at least one characteristic using the enrichment information;

unifying the at least one characteristic and the enrichment information into a data set having a single unified format; and

generating a graph based on the unified format data set, wherein the graph represents the relationships among the at least one entity.

2. The method of claim 1 , further comprising:

upon receiving a new event, gradually updating the generated graph based on the received new security event.

3. The method of claim 1 , further comprising:

generating an analysis report based on the graph.

4. The method of claim 2 , further comprising:

causing a display of the generated graph; and

causing a display of a drilled-down portion of the graph, wherein drilled-down portion includes at least one entity of interest.

5. The method of claim 1 , further comprising:

receiving a plurality of cases; and

grouping the plurality of cases, the grouping being based on the generated graph.

6. The method of claim 1 , wherein the at least one relationship characteristic includes at least one relationship type, wherein each relationship type is any of: user to user, user to host, host to host, and self event.

7. The method of claim 6 , wherein the modeling includes determining the at least one relationship type based on a connection type between primary entities involved in each event.

8. A non-transitory computer readable medium having stored thereon instructions for causing one or more processing units to execute a process for contextually analyzing potential cyber security threats in a computer network, the process comprising:

receiving at least one security event for the computer network, wherein the at least one security event is associated with at least one entity, wherein an entity is a computing arrangement coupled to the network and associated with an organization;

parsing the at least one security event;

modeling, based on at least one modeling rule selected from a set of a plurality of modeling rules, the at least one parsed security event, the modeling being such as to identify each of the at least one entity involved in an event, and to determine at least one characteristic of the at least one security event, the at least one characteristic including at least one relationship characteristic of relationships among each of the at least one entity identified as being involved in the event;

retrieving, based on the modeled events and by interfacing with external systems, enrichment information respective of the at least one characteristic;

enriching the determined at least one characteristic using the enrichment information;

unifying the at least one characteristic and the enrichment information into a data set having a single unified format; and

generating a graph based on the unified format data set, wherein the graph represents the relationships among the at least one entity.

9. A system for contextually analyzing potential security threats in a computer network, comprising:

a hardware processing unit; and

a memory, the memory containing instructions that, when executed by the processing unit, configure the system to:

receiving at least one security event for the computer network, wherein the at least one security event is associated with at least one entity, wherein an entity is a computing arrangement coupled to the network and associated with an organization;

parsing the at least one security event;

modeling, based on at least one modeling rule selected from a set of a plurality of modeling rules, the at least one parsed security event, the modeling being such as to identify each of the at least one entity involved in an event, and to determine at least one characteristic of the at least one security event, the at least one characteristic including at least one relationship characteristic of relationships among each of the at least one entity identified as being involved in the event;

retrieving, based on the modeled events and by interfacing with external systems, enrichment information respective of the at least one characteristic;

enriching the determined at least one characteristic using the enrichment information;

unifying the at least one characteristic and the enrichment information into a data set having a single unified format; and

generating a graph based on the unified format data set, wherein the graph represents the relationships among the at least one entity.

10. The system of claim 9 , wherein the system is further configured to:

upon receiving a new security event, gradually update the generated graph based on the received new event.

11. The system of claim 9 , wherein the system is further configured to:

generate an analysis report based on the graph.

12. The system of claim 10 , wherein the system is further configured to:

cause a display of the generated graph; and

cause a display of a drilled-down portion of the graph, wherein drilled-down portion includes at least one entity of interest.

13. The system of claim 9 , wherein the system is further configured to:

receive a plurality of cases; and

group the plurality of cases using the generated graph.

Assignments (6)
CONFIRMATORY ASSIGNMENT Recorded Feb 23, 2023
From: CYARX TECHNOLOGIES LTD.
To: GOOGLE LLC
Reel/Frame 062839/0589 →
RELEASE OF PATENT SECURITY INTEREST Recorded Feb 22, 2023
From: SILICON VALLEY BANK
To: CYARX TECHNOLOGIES LTD.
Reel/Frame 062821/0538 →
CHANGE OF ASSIGNEE ADDRESS Recorded Oct 28, 2021
From: CYARX TECHNOLOGIES LTD.
To: CYARX TECHNOLOGIES LTD.
Reel/Frame 057968/0683 →
SECURITY INTEREST Recorded Dec 11, 2020
From: CYARX TECHNOLOGIES LTD.
To: SILICON VALLEY BANK
Reel/Frame 054616/0691 →
SECURITY INTEREST Recorded Aug 14, 2018
From: CYARX TECHNOLOGIES LTD
To: SILICON VALLEY BANK
Reel/Frame 046789/0138 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 20, 2016
From: COHEN, ALON; STERN, AMOS; FATAKHOV, GARRY
To: CYARX TECHNOLOGIES LTD.
Reel/Frame 037536/0174 →