IP Library › Granted Patent US 10,681,064
Granted Patent B2
US 10,681,064 · App. 15/847,450 · Granted Jun 9, 2020

Analysis of complex relationships among information technology security-relevant entities using a network graph

Inventors: Wei-Guo Peng (Dallau, DE); Lin Luo (Wiesloch, DE); Eugen Pritzkau (Wiesloch, DE); Hartwig Seifert (Elchesheim-Illingen, DE); Harish Mehta (Wiesenbach, DE); Nan Zhang (Schriesheim, DE); Thorsten Menke (Bad Iburg, DE); Jona Hassforther (Heidelberg, DE); Rita Merkel (Ilvesheim, DE); Florian Chrosziel (St. Leon-Rot, DE); Kathrin Nos (Nussloch, DE); Marco Rodeck (Maikammer, DE); Thomas Kunz (Lobbach/Lobenfeld, DE)
Assignee: SAP SE
H04L63/1416H04L41/0604H04L41/069H04L41/22H04L43/045H04L63/1425G06F16/9024G06T11/203H04L63/0236H04L63/0263
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,681,064
App. No.
15/847,450
Granted
Jun 9, 2020
Kind
B2
Abstract

A filter is selected from one or more filters defined for an ETD Network Graph. Events are fetched from the selected log files based on the selected filter and entities identified based on the fetched Events. Relationships are determined between the identified entities, and the determined relationships and identified entities are displayed in the ETD Network Graph. An identified entity is selected to filter data in an ETD Event Series Chart. An Event is selected in the ETD Event Series Chart to display Event Attributes in an Event Attribute Dialog. An Event Attribute is selected in the Event Attribute Dialog to filter Events in the ETD Event Series Chart.

Claims (47)

1. A computer-implemented method, comprising:

selecting one or more log files containing Events associated with one or more entities for Enterprise Threat Detection (ETD) analysis;

selecting a filter from one or more filters defined for an ETD Network Graph;

fetching Events from the selected one or more log files based on the selected filter;

identifying entities based on the fetched Events;

determining relationships between the identified entities;

enabling tooltip functionality for Attribute values associated with one or more Events displayed in an ETD Event Series Chart and one or more displayed graphical elements in the ETD Network Graph;

displaying the determined relationships and identified entities in the ETD Network Graph;

selecting an identified entity to filter data in the ETD Event Series Chart;

selecting an Event in the ETD Event Series Chart to display Event Attributes in an Event Attribute Dialog; and

selecting an Event Attribute in the Event Attribute Dialog to filter Events in the ETD Event Series Chart.

2. The computer-implemented method of claim 1 , comprising generating a case file for later ETD analysis based on a selected event in the ETD Event Series Chart.

3. The computer-implemented method of claim 1 , wherein the one or more defined filters include a timeframe, Alert, or an ETD Pattern.

4. The computer-implemented method of claim 1 , wherein the Event Series Chart comprises two identical time axes.

5. The computer-implemented method of claim 1 , comprising enabling zooming and panning functionality for the ETD Event Series Chart.

6. A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations comprising:

selecting one or more log files containing Events associated with one or more entities for Enterprise Threat Detection (ETD) analysis;

selecting a filter from one or more filters defined for an ETD Network Graph;

fetching Events from the selected one or more log files based on the selected filter;

identifying entities based on the fetched Events;

determining relationships between the identified entities;

enabling tooltip functionality for Attribute values associated with one or more Events displayed in an ETD Event Series Chart and one or more displayed graphical elements in the ETD Network Graph;

displaying the determined relationships and identified entities in the ETD NetworkGraph;

selecting an identified entity to filter data in the ETD Event Series Chart;

selecting an Event in the ETD Event Series Chart to display Event Attributes in an Event Attribute Dialog; and

selecting an Event Attribute in the Event Attribute Dialog to filter Events in the ETD Event Series Chart.

7. The non-transitory, computer-readable medium of claim 6 , comprising one or more instructions to generate a case file for later ETD analysis based on a selected event in the ETD Event Series Chart.

8. The non-transitory, computer-readable medium of claim 6 , wherein the one or more defined filters include a timeframe, Alert, or an ETD Pattern.

9. The non-transitory, computer-readable medium of claim 6 , wherein the Event Series Chart comprises two identical time axes.

10. The non-transitory, computer-readable medium of claim 6 , comprising one or more instructions to enable zooming and panning functionality for the ETD Event Series Chart.

11. A computer-implemented system, comprising:

one or more computers; and

one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising:

selecting one or more log files containing Events associated with one or more entities for Enterprise Threat Detection (ETD) analysis;

selecting a filter from one or more filters defined for an ETD Network Graph;

fetching Events from the selected one or more log files based on the selected filter;

identifying entities based on the fetched Events;

determining relationships between the identified entities;

enabling tooltip functionality for Attribute values associated with one or more Events displayed in an ETD Event Series Chart and one or more displayed graphical elements in the ETD Network Graph;

displaying the determined relationships and identified entities in the ETD Network Graph;

selecting an identified entity to filter data in the ETD Event Series Chart;

selecting an Event in the ETD Event Series Chart to display Event Attributes in an Event Attribute Dialog; and

selecting an Event Attribute in the Event Attribute Dialog to filter Events in the ETD Event Series Chart.

12. The computer-implemented system of claim 11 , comprising one or more operations to generate a case file for later ETD analysis based on a selected event in the ETD Event Series Chart.

13. The computer-implemented system of claim 11 , wherein the one or more defined filters include a timeframe, Alert, or an ETD Pattern.

14. The computer-implemented system of claim 11 , wherein the Event Series Chart comprises two identical time axes.

15. The computer-implemented system of claim 11 , comprising one or more operations to enable zooming and panning functionality for the ETD Event Series Chart.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2018
From: PENG, WEI-GUO; LUO, LIN; PRITZKAU, EUGEN; SEIFERT, HARTWIG; MEHTA, HARISH; ZHANG, NAN; MENKE, THORSTEN; HASSFORTHER, JONA; MERKEL, RITA; CHROSZIEL, FLORIAN; NOS, KATHRIN; RODECK, MARCO; KUNZ, THOMAS
To: SAP SE
Reel/Frame 044739/0666 →
Continuity (1)
Related Publication 20190190927A1 · Jun 20, 2019