IP Library Granted Patent US 10,778,708
Granted Patent B1
US 10,778,708 · App. 15/872,527 · Granted Sep 15, 2020

Method and apparatus for detecting effectiveness of security controls

Inventors: Brandon Hoffman (Cocoa Beach, FL); Namrata Patel (Raritan, NJ); George Budd (Randolph, NJ); Bill Robinson (Flemington, NJ)
Assignee: Lumeta Corporation
H04L63/1425H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,778,708
App. No.
15/872,527
Granted
Sep 15, 2020
Kind
B1
Abstract

An index of network data is received, the index including network infrastructure data, network connection topology data and network devices data, collected in real time. Data describing one or more cybersecurity threat sources is received. Data describing communications occurring with devices within the network is received. The data describing the one or more cybersecurity threat sources and the data describing the communications occurring with devices within the network are analyzed to identify data describing possible security threats. The data describing the possible security threats is correlated with the index of network data to identify security threats to devices within the network.

Claims (21)

1. A computer-implemented method comprising:

receiving an index of network data, comprising network infrastructure data, network connection topology data and network devices data including the IP addresses of network devices, collected in real time;

receiving data describing one or more cybersecurity threat sources;

receiving data describing communications occurring with devices within the network;

analyzing the data describing the one or more cybersecurity threat sources and the data describing the communications occurring with devices within the network to identify data describing one or more possible security threats, wherein the data describing one or more possible security threats includes netflow cache data identifying a source IP address and a destination IP address for network communications associated with possible security threats; and

while receiving the data describing communications occurring with devices within the network, collected in real time, correlating the data describing the one or more possible security threats including the netflow cache data identifying the source IP address and the destination IP address for network communications associated with possible security threats with the index of network data including the IP addresses of network devices by matching the IP addresses in the netflow cache data to the IP addresses in the index of network data to identify one or more security threats to devices within the network.

2. The computer-implemented method of claim 1 , wherein the indexing of network data is collected based on control plane data.

3. A system comprising:

memory operable to store at least one program;

at least one processor communicatively coupled to the memory, in which the at least one program, when executed by the at least one processor, causes the at least one processor to perform a method comprising:

receiving an index of network data, comprising network infrastructure data, network connection topology data and network devices data including IP addresses of network devices, collected in real time;

receiving data describing one or more cybersecurity threat sources;

receiving data describing communications occurring with devices within the network;

analyzing the data describing the one or more cybersecurity threat sources and the data describing the communications occurring with devices within the network to identify data describing one or more possible security threats, wherein the data describing one or more possible security threats includes netflow cache data identifying a source IP address and a destination IP address for network communications associated with possible security threats; and

while receiving the data describing communications occurring with devices within the network, collected in real time, correlating the data describing the one or more possible security threats including the netflow cache data identifying the source IP address and the destination IP address for network communications associated with possible security threats with the index of network data including the IP addresses of network devices by matching the IP addresses in the netflow cache data to the IP addresses in the index of network data to identify one or more security threats to devices within the network.

4. A non-transitory computer readable storage medium having stored thereon computer-executable instructions which, when executed by a processor, perform a method comprising:

receiving an index of network data, comprising network infrastructure data, network connection topology data and network devices data including IP addresses of network devices, collected in real time;

receiving data describing one or more cybersecurity threat sources;

receiving data describing communications occurring with devices within the network, collected in real time;

analyzing the data describing the one or more cybersecurity threat sources and the data describing the communications occurring with devices within the network to identify data describing one or more possible security threats, wherein the data describing one or more possible security threats includes netflow cache data identifying a source IP address and a destination IP address for each network communication; and

while receiving the data describing communications occurring with devices within the network, collected in real time, correlating the data describing the one or more possible security threats including the netflow cache data identifying the source IP address and the destination IP address for network communications associated with possible security threats with the index of network data including the IP addresses of network devices by matching the IP addresses in the netflow cache data to the IP addresses in the index of network data to identify one or more security threats to devices within the network.

Assignments (4)
RELEASE OF SECURITY INTEREST Recorded Sep 17, 2020
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: LUMETA CORPORATION
Reel/Frame 053803/0299 →
PATENT SECURITY AGREEMENT Recorded Aug 18, 2020
From: FIREMON, LLC; IMMEDIATE INSIGHT, INC.; LUMETA CORPORATION
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 053532/0428 →
SECURITY INTEREST Recorded Jun 7, 2018
From: LUMETA CORPORATION
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS AGENT
Reel/Frame 046019/0044 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2018
From: HOFFMAN, BRANDON; PATEL, NAMRATA; BUDD, GEORGE; ROBINSON, BILL
To: LUMETA CORPORATION
Reel/Frame 044994/0184 →